Muse and OpenAI's Dots push AI agents deeper into email and apps
The agent race is moving from answering questions to acting inside inboxes, browsers, and connected apps — both Meta and OpenAI are betting on always-on cloud computers while gating the riskiest actions behind user approval.
In this brief: 3 sections 2 min read
Both run dedicated cloud computers with their own browsers and connected-app access, continuing tasks after the user leaves.
Muse sends email, books travel, completes forms, and makes purchases; it is free for most uses with paid tiers for heavier use.
Dots conduct background research through connected apps in read-only mode — those tools cannot send messages, change app content, or control a browser or computer.
Users can create rules for Dots; individual memories cannot currently be viewed, deleted, or directly modified.
Muse requests approval before actions such as sending email or making a purchase.
Dots require the user to take over for password changes and money transfers.
Deleting data or installing software may require approval; read-only background tools are the default for research.
Muse maintains an audit trail covering completed and planned actions.
Conversations, tool calls, and subagent exchanges may be sanitized and used to train future models by default, with an opt-out in Muse settings.
Muse interactions and VM data are not shared directly with Meta's ad systems, though agent browsing can influence advertising indirectly.
Meta's security program pays up to $300,000 for valid bug reports including prompt injection; a Confidential VM encrypting the machine with a user-held key is planned for later in 2026.
OpenAI says human review may occur in limited situations, including safety cases, even when model improvement is disabled.