Meta shipped Muse on 8 September 2026. OpenAI shipped Dots on 29 September, 21 days later. Both are always-on personal agents with a cloud computer and a browser, both have a nameable mascot, and both promise to keep working while you do something else. Underneath, the two companies made opposite decisions about where trust lives. Meta built a new, closed runtime: one virtual machine per user, a gatekeeper process the agent cannot override, and a connector directory it reviews itself. OpenAI attached an agent to what ChatGPT accounts already had: more than 4,000 plugins, the permissions already granted to them, and the user's own identity. This is part two of our Dots series. Part one covered what a dot is. Here the two products go side by side, with the question a security owner actually has to answer: when the agent gets something wrong, how far does the damage travel?
The comparison in one table
Everything below is taken from the vendors' own launch posts, help centres and security write-ups, checked on 3 October 2026. Where a cell says "not published", we looked and did not find it.
| Dimension | OpenAI Dots | Meta Muse |
|---|---|---|
| Launched | 29 September 2026 | 8 September 2026 |
| Model | GPT-6 Astra | Muse Spark |
| Runtime | Own cloud computer and browser per dot, kept separate from the user's machine unless connected | Dedicated Secure VM per user; agent in an unprivileged container inside it |
| Action gatekeeper | Auto-review plus four-level Custom Rules | Sentinel, a separate process: allow, deny or ask |
| Connectors | 4,000+ existing ChatGPT plugins, permissions inherited | Meta-reviewed directory, plus unreviewed custom connectors and a browser fallback |
| Credentials | Saved passwords used for sign-in "without exposing them"; plugin grants reused | Surrogate tokens; real secret inserted at the network boundary |
| Memory control | Pause or wipe everything; no per-item view or edit | "Forget" for specific learned information |
| Buyer | Pro, Business Premium, Enterprise beta | Consumers: free tier, $20 and $100 plans |
| Reachable from Sweden | Business Premium yes, Enterprise if an admin enables it, Pro no | No. US and Canada only |
Where the agent runs
On the surface the runtimes look alike. A dot gets its own cloud computer and browser, hosted by OpenAI, and you can watch it work. A Muse agent gets a virtual machine with a browser and enough compute to compile code and run sub-agents. In both cases the machine is in the vendor's cloud and your laptop is out of the picture unless you opt in. Dots keep local computer access off until the user confirms it in the desktop app. Muse added Mac desktop control at Connect on 23 September.
The difference is how much each vendor has told you about the inside of that machine. Meta published an engineering post on launch day that goes down to the process level. The agent harness runs in a systemd-nspawn container where root inside the container maps to an unprivileged user on the host. Connector code runs in separate privilege-separated workers. A credential daemon holds the secrets, and the agent never sees them. Meta also wrote down the limits: the current design "does not prevent Meta from accessing data when necessary to support, secure or operate the service", and the Confidential VM that would change that, encrypted with a key only the user holds, is promised for later this year and is with a small group of testers today.
OpenAI's public material on Dots describes behaviour and controls. It says the dot's computer is separate from yours and that saved passwords are used without being exposed. As of 3 October we have not found an OpenAI document for Dots that describes the isolation model at the level Meta's does. That is a gap in what is published, and it should be read as exactly that. It says nothing about which runtime is stronger. It does mean a security reviewer can check Meta's claims against a design and can only check OpenAI's against a help article.
Who approves an action
This is where the two designs part most clearly.
Muse puts a second process between the agent and the world. Meta calls it Sentinel and describes it as "the sole permission authority" for connector actions and for all network egress. Every outbound request ends in one of three states: allowed, denied, or ask the user. Sentinel sits outside the agent's container, so an instruction injected into the agent's context cannot tell Sentinel to stand down. Meta adds kernel-level data-flow tracking that it calls tainted egress. A process that has touched untrusted content loses its auto-allow status and falls back to the normal approval flow. The gate is architectural: it exists whether or not the user configured anything.
Dots put policy in front of the action. Auto-review checks a planned action against the user's instructions, the user's Custom Rules and OpenAI's safety requirements before anything that could affect an account or share information goes out. Custom Rules then set one of four behaviours per action type: take action without asking, take action if pre-approved, ask before taking action, or hand off to you. Below those sits a fixed floor. Password changes and money transfers always return to the human. Permanent deletion and installing unrecognised software need approval each time.
The practical trade-off is configurability against independence. A dot's rules are far more expressive than Sentinel's three outcomes, and an organisation can write its usage policy directly into them. But OpenAI's help text carries a sentence that Meta's architecture is designed to make less relevant: "A dot can make mistakes, including when following your rules." A rule the agent itself is asked to follow is a weaker control than a gate the agent cannot reach. Meta, for its part, does not claim the gate is sufficient. Its security post says plainly that "Muse isn't immune to attack. Prompt injection remains an open problem in the industry." It backs that with a bounty of up to $130,000 for a prompt injection that affects one user.
Connectors: inherited reach against curated reach
A dot connects to more than 4,000 applications on its first day because it has no connector directory of its own. It uses ChatGPT's plugins, and plugin permissions are shared across dots, ChatGPT, ChatGPT Work and Codex. Whatever an employee connected to ChatGPT in the past is what their dot can reach now, with no new consent step.
Muse started from zero. Meta opened connectors to developers on 18 September and reported more than 1,500 applications within a week. Directory connectors go through a functional, security and legal review by Meta before listing. Launch partners named at Connect include Walmart, Expedia and Instacart on the consumer side and GitHub and Notion on the work side.
"Curated" needs a qualifier, though. Muse has two other connector classes. A user can ask Muse to write a custom connector from an API or a command-line tool, and Meta's Help Center says it does not review those. And when no connector exists, Muse falls back to driving the website in its browser. Amazon blocked that route on 22 September, as Fortune reported. So the reviewed directory is the front door, with two side doors that carry less assurance. We went through all three in the Muse connectors post.
Credential handling follows the same split. Muse gives the agent a surrogate token with no access rights of its own. After Sentinel authorises a specific request, the real secret is swapped in at the network boundary, so a model that never held the credential cannot be talked into leaking it. OpenAI states that dots sign in to supported websites with saved passwords "without exposing them". For plugins, the dot rides on the OAuth grants the user already made, with the scopes the user already accepted.
Identity and memory
Muse is a consumer product. It acts for a private person inside that person's accounts, and it has its own email address since Connect. There is no enterprise identity story because there is no enterprise product.
Dots are sold into workspaces, which is where identity starts to matter. A standard dot runs on the user's own account. Its emails come from that person, and the downstream systems log that person's name. The German consultancy innFactory put the consequence in one line in its 30 September analysis: a standard dot is "indistinguishable from that employee in an audit". Specialist dots, in enterprise preview, get their own identity, credentials and system access, and OpenAI has said it is working with Microsoft to bring them under Agent 365, which is where an Entra agent identity would apply. Tomorrow's part three is about that distinction.
On memory, Meta has the more granular control today. Users can tell Muse to forget specific things it has learned. A dot's memory can be paused or wiped as a whole, and individual memories cannot currently be viewed or edited. On training, Meta's position is opt-out: its security post says agent trajectories are sanitised of key personal identifiers and then used for training unless the user opts out.
Blast radius: what a bad day looks like
Take the standard failure for this product class. The agent reads a web page or an email containing hidden instructions, and those instructions tell it to send data somewhere or act in a connected account.
For a Muse user, the damage is bounded by three things: the connectors that one person enabled, Sentinel's decision on each outbound request, and the taint tracking that should push a compromised process back to asking. The agent holds no real credentials to exfiltrate. The exposure is one consumer's accounts, including payment, where Muse checks out through Stripe's Link with a single-use virtual card.
For a standard dot in a company, the bound is different in kind. The reach is every plugin the employee ever connected, possibly a shared drive, a mailbox and Slack. The gate is auto-review and whichever rule level applies to that action type. If the action was set to run without asking, the remaining defence is auto-review alone. And whatever happens is recorded downstream as the employee's own action. The fixed floor does remove the worst outcomes, since no rule lets a dot move money or change a password. Sending a document to the wrong recipient is not on that floor.
None of this makes Dots the unsafe choice and Muse the safe one. Muse's consumer reach includes shopping and payments, which a dot will not complete without approval. Meta's own text concedes that it can read the VM today. The fair summary is that Muse limits blast radius by construction and narrow reach, while Dots limit it by policy across a very wide reach. Policy can be written well. It has to be written, though, and the defaults were not chosen by your security team.
Price and scale
Muse is free up to a weekly token allowance, with Power at $20 and Max at $100 per month above that, and Meta has said it expects to take a small fee on transactions. The first dot is included in Pro and Business Premium plans, conversations with it do not count against ChatGPT limits, and work it starts in Codex or ChatGPT Work does. OpenAI has not published permanent allowances or the price of a second dot.
Only one of the two has adoption numbers. Sensor Tower put Muse at 5 million downloads on 30 September, 22 days after launch, and The Information reported 3 million weekly users, as relayed by The Next Web on 2 October. OpenAI has published no usage figures for Dots, which is four days into a gradual rollout.
The Swedish and EU angle
For a reader in Sweden, the comparison is lopsided before it starts. Muse is available in the United States and Canada. Meta has announced no European date, and the reasons that is unlikely to change quickly are in our post on Muse and the EU. Dots are split: ChatGPT Pro subscribers in the EEA, Switzerland and the UK are excluded with no date, while Business Premium rolls out "across all supported ChatGPT regions" and Enterprise workspaces have a beta that stays off until an admin enables it.
So the agent a Swedish company can actually switch on this month is the one whose trust model depends most on configuration, and the one with the more inspectable architecture is not on offer. That shapes the work. A Swedish pilot of Dots is mostly a rules-and-inventory exercise: which plugins are connected, which action types run unattended, and how the company will tell a dot's actions from an employee's when someone asks. The Muse design is still worth studying as a reference, because a separate gatekeeper and surrogate credentials are patterns you can require from any agent, including one you build.
For teams that need the audit log and the data location under their own control, the third option remains a self-built agent in the Azure tenant on the same model family, with an Entra agent identity and connectors chosen on purpose. We covered the open-source runtimes for that route in Muse vs Hermes Agent vs OpenClaw, and our Azure OpenAI integration service covers the build.
Who should pilot which
- Swedish company on ChatGPT Business Premium: pilot Dots with a small named group. Audit their existing plugin connections first, and set outbound messages and file edits to "ask before taking action".
- Swedish company on ChatGPT Enterprise: leave the beta off until you have decided how standard dots will be distinguished in your logs, or wait for specialist dots with their own identity.
- Anyone in the EU hoping to trial Muse: there is nothing to trial. Do not route around the geography with a US account for company data.
- Teams with US or Canadian staff who use Muse privately: treat it as a personal consumer app. Keep company accounts out of its connectors, including custom ones Meta does not review.
- Regulated workloads: neither product. Build the agent in your own tenant and borrow Meta's two patterns, an out-of-process gatekeeper and credentials the model never holds.
- Security reviewers: ask OpenAI, through your account team, for a runtime isolation description comparable to Meta's published one, and record the answer.
subscribe # the AI news that matters, minus the noise
Sources
- OpenAI: Introducing dots (29 September 2026)
- OpenAI Help Center: Dots privacy, security and safety FAQs
- OpenAI Help Center: Getting started with your dot
- Meta: Introducing Muse, a personal AI agent (8 September 2026)
- Meta AI Research: Security and safety for AI agents, our approach with Muse
- TechCrunch: Everything new coming to Meta's AI agent Muse (23 September 2026)
- The Next Web: OpenAI launches dots, always-on AI agents with their own cloud computers
- The Next Web: Meta's Muse reportedly passes 3 million weekly users and 5m downloads (2 October 2026)
- innFactory: OpenAI dots, what always-on agents mean for your company (30 September 2026)