Back

Muse Secure VM vs OpenAI dots: two privacy stacks for personal agents

Meta Muse Secure VM and Sentinel safety diagram

With OpenAI dots shipping Sept. 29, Meta's Muse company and research materials lock a contrasting privacy and safety stack. Muse runs in an isolated Secure VM with a Sentinel that alone approves outside actions and keeps credentials from the agent. OpenAI says each dot works on its own cloud computer, with read-only proactive research, Custom Rules, and auto-review.

Two personal-agent stacks just drew a clear privacy line. After OpenAI shipped dots on Sept. 29, Meta's Muse company launch and safety research set a different architecture: an isolated Secure VM, a Sentinel that alone approves outside actions, and credentials the agent never sees.

Meta says Muse is a personal AI agent that runs on Muse Secure VM, a dedicated virtual machine that houses both the agent and a person's data. Each person stays in control of how much access Muse gets. A separate Sentinel agent on the same machine is the sole permission authority for connector actions and network egress. Muse proposes actions. Only Sentinel can grant them. Meta says Muse has no visibility into passwords or payment methods, and credentials go into secure storage so the agent can use them without seeing them.

Meta AI Research frames the design as assuming the agent may be under attack. The harness runs in an isolated cell. Every outside-world interaction runs through Sentinel, which the agent cannot override. Meta says it is opening a Muse bug bounty that awards up to $300,000 for valid reports, including up to $130,000 for successful prompt-injection attempts that affect one user. Later in 2026, Meta says it plans Muse Confidential VM, intended so the whole VM, including a person's data and conversations, is encrypted with a key only the person holds.

OpenAI's Sept. 29 introducing-dots post describes a different safety surface. Each dot works on its own cloud computer, while the user's computer stays separate unless the user connects it. OpenAI says dots can use saved passwords for supported sites without exposing them to the model. Proactive research uses connected apps with tools restricted to read-only, so those tools cannot send messages, change app content, or control the browser or computer. Custom Rules set when to act, require approval, or block. Auto-review checks actions that could affect accounts or share information. Sensitive tasks such as changing a password always stay with the user. Monitoring can pause or stop a dot on a safety concern.

The story here is the privacy and safety architecture contrast after dots shipped. It is not a Ray-Ban glasses Muse product tip, not a DevDay wrap, and not a shopping-block or downloads scoreboard. What remains open is how Secure VM and Confidential VM hold up outside Meta's described design, and how dots' auto-review and read-only proactive research behave once users connect real work apps at scale.