Meta’s Muse and OpenAI’s Dots Expand AI Agents Into Email, Apps
Muse is rolling out in the United States, while Dots are available to eligible paid ChatGPT users. Both systems can act across browsers and connected services with limits on sensitive actions.

Meta’s Muse and OpenAI’s Dots are extending consumer AI agents beyond chat by allowing them to operate browsers, cloud computers and connected applications, while placing limits on purchases, money transfers and other sensitive actions.
Muse began rolling out in the United States after Meta announced it Sept. 8. The service is available on iOS, Android and muse.ai, and can send email, book travel, complete forms and make purchases. Muse is free for most uses, with subscriptions for heavier use.
OpenAI announced Dots Sept. 29 for eligible ChatGPT Pro and Business Premium users. The first dot is included at no extra cost in those plans. Enterprise, education and health-care users can access a beta when a workspace administrator enables it.
Both products work through cloud computers and can continue tasks after a user leaves the app. That gives them broader access to email, connected applications and sensitive data than conventional chat tools, while raising the risk of unintended or irreversible actions.
Muse operates inside a dedicated virtual machine with its own browser. It requests approval before actions such as sending email or making a purchase and maintains an audit trail covering completed and planned actions.
Muse interactions and virtual-machine data are not shared directly with Meta’s advertising systems. Agent browsing can still influence advertising indirectly because it appears as the user’s activity. Conversations, tool calls and exchanges between subagents may be sanitized and used to train future models by default, with an opt-out available in Muse settings.
Meta’s Muse security program offers up to $300,000 for valid bug reports, including prompt-injection attacks. A planned Confidential VM feature would encrypt the virtual machine with a key held only by the user. The feature was planned for later in 2026.
Dots operate through separate cloud computers and browsers and can use connected applications. Users can inspect a dot’s computer and, in some cases, connect it to their own devices. Dots can also conduct background research through connected apps in read-only mode, but those tools cannot send messages, change app content or control a browser or computer.
Users can create rules for Dots, although some actions remain restricted. Password changes and money transfers require the user to take over, while deleting data or installing software may require approval. Dots can retain conversation and plugin context for as long as the user keeps the dot, but individual memories cannot currently be viewed, deleted or directly modified.
Human review may occur in limited situations, including safety cases, even when model improvement is disabled. OpenAI’s Dots launch continues an earlier comparison of access and workload controls, while the two products now present different priorities: Meta emphasizes a mainstream personal assistant, and OpenAI also positions Dots for organizational work.