OpenAI Dots and Meta Muse: always-on personal AI agents
TECH

OpenAI Dots and Meta Muse: always-on personal AI agents

54+
Signals

Strategic Overview

  • 01.
    OpenAI launched "dots," always-on AI agents, at DevDay 2026 on September 29, 2026, calling them remarkably capable, always-on agents built to handle everything, with users starting from a primary dot they name and customize.
  • 02.
    Each dot runs on GPT-6 Astra with its own cloud computer and browser, learns from feedback over time, can work toward user goals around the clock, and connects to more than 4,000 apps through plugins while working on several projects at once.
  • 03.
    Dots are rolling out to ChatGPT Pro and Business Premium subscribers, with Pro tiers at $100, $200 and $500 per month each including a first dot at no extra cost; the Pro rollout excludes the European Economic Area, Switzerland and the UK, while Business Premium covers all supported ChatGPT regions.
  • 04.
    Users govern a dot's autonomy through Custom Rules, deciding what it may do on its own, what it must ask about first, and what it may never do such as changing a password, on top of defaults for which actions need approval each time.
  • 05.
    Meta launched Muse, a personal AI agent pitched as software that does the work rather than answering questions, on September 8, 2026 in the US across iOS, Android and the web, with a Mac app following shortly after.
  • 06.
    Muse's default avatar is a cream-colored character named Jolly with beady black eyes and an upward smile, and users can customize names, appearances and attire; Mark Zuckerberg's own avatar is called Agrippa and styled as a Roman general.
  • 07.
    Muse hit number one on the US App Store by September 18, a position it held since, and topped Google Play the following day, with third-party download estimates spanning 2.3 million (Appfigures) to 4.3 million (Apptopia) and roughly 3.4 million from Sensor Tower.
  • 08.
    Muse reached 2.5 million downloads in 13 days, surpassing ChatGPT's own download record at launch.
  • 09.
    Muse runs on a dedicated Muse Secure VM with isolated infrastructure, a Sentinel agent that controls internet access and permission requests, and credential storage that Meta says keeps passwords out of its own view, with a future Muse Confidential VM promising user-only decryption.
  • 010.
    Amazon blocked Muse from its platform citing policies against shopping automation tools, and Meta discontinued a planned human concierge feature over data-leak concerns.

Deep Analysis

The Agent Market Split in Three Weeks, Not Three Years

The Agent Market Split in Three Weeks, Not Three Years
OpenAI's Dots interface, unveiled at DevDay 2026, pairs an always-on agent with a customizable avatar and per-action permission rules.

Meta shipped Muse free on iOS, Android and the web on September 8 [6][7]and handed users 100 million free tokens a week [11]. OpenAI answered on September 29 with Dots [1]at $100, $200 and $500 per month across its Pro 100/200/500 tiers, plus Business Premium at $125 per user per month [5], with Bloomberg billing the new $500 tier alongside the agent itself [9]. Each dot runs GPT-6 Astra on its own cloud computer and browser with plugin reach into more than 4,000 apps [2], while the Pro rollout skips the European Economic Area, Switzerland and the UK and Business Premium ships across all supported ChatGPT regions [4]. CNBC and Yahoo Finance read the sequencing identically: OpenAI followed Meta into a market Meta had already validated [15][16]. The fork is unusually clean for a category this young. Meta is buying consumer habit at zero marginal price to the user and betting distribution compounds. OpenAI is selling governed autonomy at a price only a company expense line absorbs. Nobody is competing on the same axis, which means the first real test is not which agent is smarter but which business model survives the support burden of acting on someone's live accounts.

The Permission Layer Is the Actual Product

Strip away the mascots and both products are permission engines. Dots ship Custom Rules in which the user declares what the agent may do alone, what it must ask about first, and what it may never do, with changing a password cited as the canonical never [3][4]. Muse answers with infrastructure instead of policy: a dedicated Muse Secure VM with isolated infrastructure, a Sentinel agent that gates internet access and permission requests, credential storage designed so the assistant cannot read passwords, and a promised Confidential VM where only the user holds the decryption key [6]. Meta went further in press comments, insisting that "even Meta won't be able to see that information" [12]. What is striking is that builder communities arrived at the same shortlist independently. A gap analysis of self-hosted agents versus the commercial ones named persistent responsibilities that survive sessions, a proactive mode that monitors permitted sources while the user is away, per-action AUTO/ASK/BLOCK rules, agent-to-agent handoffs and an inspectable workspace the human can take over. Model quality never appears on that list. Muse power users have meanwhile invented a guardrail no vendor gave them, draft-then-approve for outbound texting, and Meta's own retreat points the same way: it killed a planned human-concierge feature over data-leak concerns [11].

Three Days From Chart Topper to Account-Level Backdoor

Muse topped the App Store on September 18. Three days later a proof-of-concept for the flaw nicknamed not-a-mused was on GitHub [14]. The mechanism was mundane and devastating: an undocumented setting, endo_voyager_dictation_endpoint, could be rewritten by any unprivileged local process to hijack voice-dictation traffic and capture the agent's authentication token, handing an attacker account-level control over every service the agent had been granted [13][14]. Meta shipped a hotfix removing the setting the next day [14], but the two sides never agreed on what had happened. Patrick Wardle called it "the ultimate backdoor," while Meta's David Singleton framed it as "a local privilege escalation" [14]. Both readings are technically defensible, which is precisely the problem with always-on agents: a low-severity local bug inherits the blast radius of everything the agent can touch. The quieter finding in the same disclosure is arguably worse for companies - no enterprise controls, no SIEM exports, no admin console and no documentation for monitoring which employee accounts had been connected to Muse [14]. Investor Jason Calacanis responded with a demand that doubles as the category's missing standard: "tight defenses and 3rd party testing" [12].

Downloads Measure Curiosity, Not Reliability

The adoption numbers are real and also nearly uninterpretable. Muse hit number one on the US App Store on September 18 and topped Google Play the next day [8][10], reached 2.5 million downloads in 13 days and beat ChatGPT's own launch record [11], yet trackers could not agree on the total: 2.3 million from Appfigures, roughly 3.4 million from Sensor Tower, 4.3 million from Apptopia [10][11]. A two-million-spread estimate is a measure of interest, not of whether the agent works. Hands-on verdicts are more useful and more hedged: Yahoo Finance's technology editor found Muse "generally a solid AI agent for the average person" while explicitly noting it makes mistakes [15]. Financial video coverage circulated a viral story of a user who got a delayed flight refunded in about two minutes, then immediately asked the unanswered question - who is liable when the agent botches the refund instead. Community reaction splits along exactly that line. Builder forums treat Dots and Muse as a spec to reverse-engineer and catalog use cases for, from read-only financial monitoring to watch-only wallet alerts. Mainstream AI forums were skeptical to dismissive, with the sharpest pushback aimed at over-broad permission requests, including one account of Muse asking for Shopify write plus full Gmail access and being refused outright. Amazon made the institutional version of that refusal, blocking Muse under policies against shopping automation [11]. Bloomberg's framing is the fair one: both companies are testing public trust ahead of settled oversight [18].

The Market Priced the Mascot Before the Margins

Meta shares went from $613.48 on September 8 to $777.59 on September 24, a 26.8% run including an 11.43% single-day surge on September 21 [11], capping roughly 27% to 36% for the month and Meta's strongest monthly performance in over a decade [17]. Wells Fargo lifted its target from $640 to $796 [11], and in financial video commentary an Evercore analyst reaffirmed an outperform with an $860 target on the thesis that Muse could become Meta's first meaningful consumer AI revenue stream outside advertising. Set against that, the cash picture inverts: Meta is projected to post negative free cash flow of $6.4 billion in 2026 and negative $29.2 billion in 2027, after $46 billion positive the prior year [17]. The rally is therefore a bet that a free agent with 100 million weekly free tokens [11]converts into something billable before the buildout bill lands. The surrounding theater reinforces how early this is - Zuckerberg's Roman-general avatar Agrippa [12], life-size Jolly cutouts at Connect and a Tamagotchi-style Muse charm keychain [10]. On X, independent commentary framed Dots not as a breakthrough but as OpenAI's reactive answer to Muse and rival assistants, with a recurring question about whether Dots will ever be free. That is the real competitive pressure: Meta has set the consumer price at zero while burning cash, and OpenAI has to justify $100 a month against it.

Historical Context

2026-09-08
Meta launched Muse, its personal AI agent app, in the US on iOS, Android and the web.
2026-09-18
Muse reached number one on the US Apple App Store, a position it held for days afterward.
2026-09-21
Published a proof-of-concept on GitHub for the Muse not-a-mused privilege-escalation vulnerability.
2026-09-22
Issued a hotfix removing the vulnerable undocumented setting from production builds of Muse.
2026-09-24
Zuckerberg promoted the Jolly mascot with life-size cutouts and announced expansions to smart glasses plus a Tamagotchi-style Muse charm keychain.
2026-09-29
Unveiled Dots, its always-on agent product, at DevDay 2026 in San Francisco alongside a new $500 paid tier, directly following Meta's Muse momentum.

Power Map

Key Players
Subject

OpenAI Dots and Meta Muse: always-on personal AI agents

OP

OpenAI

Launched Dots as an always-on agentic competitor aimed primarily at paying Pro and Business Premium customers, built on GPT-6 Astra with plugin access to more than 4,000 apps.

ME

Meta Platforms

Launched Muse as a free consumer-facing personal agent embedded in its wider ecosystem, driving a major stock rally and competing directly with OpenAI's paid enterprise push.

MA

Mark Zuckerberg (Meta CEO)

Publicly championed Muse, naming his own customized avatar Agrippa and promoting the Jolly mascot at Meta Connect, framing Muse as central to Meta's consumer AI strategy.

PA

Patrick Wardle (Objective-See Foundation)

Discovered and published a proof-of-concept for the Muse not-a-mused privilege-escalation vulnerability, pressuring Meta into a hotfix within about a day of disclosure.

DA

David Singleton (Meta Superintelligence Labs)

Delivered Meta's official response to the disclosed flaw, characterizing it as a low-risk local privilege escalation while confirming the hotfix.

AM

Amazon

Blocked Muse from its platform citing policy restrictions on shopping-automation tools, illustrating platform-level pushback against autonomous agents.

WA

Wall Street analysts and investors

Repriced Meta on Muse's consumer traction, with Wells Fargo lifting its price target from $640 to $796 as the launch fed broader tech-sector gains across AMD, Intel, ARM, Qualcomm and the Nasdaq.

Fact Check

18 cited
  1. [1] OpenAI launches Dots, its bubbly agentic avatar
  2. [2] OpenAI announces Dots, always-on agents powered by GPT-6 Astra
  3. [3] Dots privacy, security and safety FAQs
  4. [4] OpenAI brings always-on Dots agents to ChatGPT
  5. [5] OpenAI Dots pricing explained
  6. [6] Introducing Muse, a Personal AI Agent
  7. [7] Meta AI launches Muse personal agent, including a new mobile app for iPhone
  8. [8] Meta's New Muse AI App Tops Charts, Draws Strong Early Reviews
  9. [9] OpenAI Unveils Always-On AI Agent Dots, New $500 Paid Tier
  10. [10] Meta Muse App Store Strategy
  11. [11] Meta's Muse AI agent upends industry in US debut
  12. [12] Meta's Muse AI agent and its cute animated avatar draw praise and privacy worries
  13. [13] Meta Muse already has a majorly worrying zero-day security issue
  14. [14] Muse security flaw: Meta AI assistant zero-day
  15. [15] OpenAI debuts Dots AI agents in challenge to Meta's popular Muse agent
  16. [16] OpenAI follows Meta into the red-hot market for personal agents
  17. [17] Meta stock jumps 36% in September after Muse launch
  18. [18] OpenAI and Meta Push Ahead With AI Agents, Testing Public's Trust

Source Articles

Top 5

THE SIGNAL.

Analysts

“Argued the Muse dictation-endpoint flaw effectively turned the assistant into "the ultimate backdoor" at account level once an attacker gained control of the agent's authentication token.”

Patrick Wardle
macOS security researcher, founder of Objective-See Foundation

“Downplayed the severity of the disclosed vulnerability as "a local privilege escalation" rather than a remotely exploitable weakness.”

David Singleton
Meta Superintelligence Labs

“Offered a hands-on verdict after extended use: "while it makes mistakes at times, it's generally a solid AI agent for the average person, especially for tasks like comparing products and getting quick answers to complex questions."”

Daniel Howley
Technology Editor, Yahoo Finance

“Called for stronger security scrutiny of always-on consumer AI agents, specifically "tight defenses and 3rd party testing."”

Jason Calacanis
Entrepreneur and investor
The Crowd

“Dots are here! A new way to use AI that works 24/7 for you; get more of your time and attention back to work at a higher level. https://t.co/Kp4fPSGUTT”

@@sama14707

“NEW: OpenAI announces "Dots" their answer to Grok Bot and Meta Muse AI agents”

@@AutismCapital1904

“The interview with @thsottiaux from OpenAI 0:00 Everything OpenAI launched at DevDay 2:44 Sponsors: Wispr Flow, Hostinger, OpenArt 4:11 What is ChatGPT Dots? 7:52 Will ChatGPT Dots be free? 10:15 GPT-6.1 Sol vs GPT-6 Astra 11:44 Is AI now building AI? 12:53 Ultra Fast”

@@VaibhavSisinty515

“Closing most gaps between Hermes vs Dots and Grok Bots”

@u/MJ_Ali45242
Broadcast
Meta Muse AI Connectors: The App Store for AI?

Meta Muse AI Connectors: The App Store for AI?

Why Meta's Muse AI agent is soaring in popularity

Why Meta's Muse AI agent is soaring in popularity

OpenAI Dots vs. Grok Bot vs. Muse for Business: Who Wins? Plus Best Use Cases

OpenAI Dots vs. Grok Bot vs. Muse for Business: Who Wins? Plus Best Use Cases

OpenAI Dots and Meta Muse: always-on personal AI agents — AI News | Agentic Brew