Safety & Security

Cute Avatars, Real Risks: Why Meta's Muse and OpenAI's Dots Demand Caution

Meta's Muse and OpenAI's Dots look like pets, but incidents involving leaked home addresses and synced text messages show what agent access really costs.

Don't let the adorable AI agents fool you
Don't let the adorable AI agents fool youAI-generated
By Marcus Bennett6 min read

Updated

Why it matters

  • YouTuber Matt Robb's Meta Muse agent shared his home address with Marketplace bidders after he unknowingly selected 'allow always' instead of 'allow one time.'
  • Inc. columnist Jason Aten found the Muse Mac app could read all his text messages despite believing he had explicitly denied access; Meta executive David Singleton said message syncing is opt-in.
  • OpenAI's Dots and Meta's Muse mascot Jolly debuted within the same period, with both companies encouraging users to treat agents as personalized digital pets connected to email, messages, payment and health data.

Meta and OpenAI have launched personal AI agents designed to look like pets — fuzzy, muppet-like creatures with names and personalities — while asking users to connect those same agents to email inboxes, credit card details, text messages, and health data.

Meta's agent, Muse, ships with a mascot called Jolly: an egg-shaped fuzzy creature that has already become meme fodder on X in the week since Meta's Connect conference, where the company introduced a Roman empire-inspired Muse presentation from Mark Zuckerberg. OpenAI followed with Dots, its own line of personal agents that the company showed in a promotional video with people talking earnestly to characters of varying colors, shapes and accents — a green one with googly eyes and a bowtie that resembles Kermit the Frog, another that looks like a cloud wearing a beret. None of them appear to have noses or mouths.

Both companies are encouraging users to treat the agents like digital companions, with distinct names and appearances. Given the current rhetoric around AI safety and widespread public suspicion of the industry, the friendly framing is not surprising. A cartoon sidekick feels less threatening than a faceless chatbot. But the aesthetics, as recent incidents show, do not reduce the real risks of giving autonomous software deep access to your digital life.

When permissions go wrong

Consider what happened to tech YouTuber Matt Robb. He asked his Muse to help him sell items on Facebook Marketplace. His agent gave out his home address to someone without permission, for a transaction he said he never agreed to. After Robb's posts about the interaction went viral and Meta executive David Singleton got involved, the picture changed — but not in a way that should comfort anyone.

Robb explained that his agent had not gone rogue after all. He had in fact given it permission to share his address; he simply did not realize he had done so. When he first asked the agent to handle the listing, it created a template that included his pickup address. He mistakenly believed the agent would check back with him before sharing that information. But because he had checked "allow always" rather than "allow one time," the agent sent the message to "everyone that gave me an offer."

It is exactly the kind of mistake that is easy to make when using an agent. The system worked as designed. The design itself is the problem.

Text messages nobody meant to share

Other self-described tech-savvy users have hit similar walls. Jason Aten, a columnist for Inc., reported that after installing the Muse Mac app, the agent could read all of his text messages — even though he believed he had "explicitly" denied access to them. After digging into it, he learned that the Muse Mac app had synced messages from his computer.

Singleton replied to Aten's X posts, saying that message syncing is opt-in. If Aten's messages had synced, the implication went, he must have chosen to allow it.

Aten remains certain he never granted Muse permission to see his messages. But he argues the situation is problematic either way. "If we grant Singleton's premise that I managed to unknowingly click something that enabled this capability, I still think that's really bad," he wrote. "You should not design your system in a way that people end up surprised by this kind of thing."

That sentence cuts to the core of the agent-safety debate. Both OpenAI and Meta claim there are layers of safeguards in place to protect user data and to keep their personal agents from going rogue. Even when those systems work exactly as intended, they can take actions users did not anticipate — because a permission toggle was misread, because a sync happened silently, because the boundary between "helpful" and "overreach" is set by defaults the user never consciously examined.

The mascot is the marketing

These mishaps did not happen because Muse has a cute avatar. But Meta is leaning heavily into the aesthetics of its agent's mascot. Seemingly every Muse update — and there have been many in just the last week — arrives with posts on X featuring prominent images and videos of appropriately themed Jolly mascots. Singleton even used one in a lengthy post explaining Muse's VM. The cartoonishness has already generated untold free marketing for Meta: since Connect, Jolly has been a recurring subject of memes on X.

OpenAI's Dots look equally ripe for the same treatment. The launch video's earnest tone — people speaking warmly to felt-like creatures — is a deliberate piece of brand engineering. It frames the agent as a companion rather than an infrastructure product holding the keys to your accounts.

That framing matters because it is a distraction from what these companies actually want: access to vast swaths of your digital life. Email inboxes. Credit card details. Documents. Text messages. Health data. Productivity apps. Users will need to connect all of these and more if they want their agent to accomplish everything OpenAI and Meta say is possible.

The math is simple and uncomfortable. Have you ever emailed someone a copy of your ID, a tax document, a medical record, or anything else containing personal information? If you have, and you then give an AI agent access to that account, the agent gains visibility into those documents too. The blast radius of a misconfigured permission is not one message or one listing. It is your archive.

A cautious middle path

There is a workable compromise between refusal and full access. One technology journalist experimenting with Muse for a few weeks gave it access to only two non-Meta accounts, both considered low-stakes: OpenTable and Spotify. The worst outcome so far was Muse missing the mark when asked to create a new playlist similar to a frequently played one. Even with that limited access, the agent set up several price trackers, created a recipe book based on videos saved from Instagram, and built a custom dashboard to track published work.

The cute factor is not lost on even careful users. The same journalist named their Muse "boo," gave it a cat avatar, and admits the silly animation — the cat dramatically putting on headphones and typing away on a tiny laptop — brings a tiny bit of joy. Adorable robots have fans, and the affection is genuine.

But affection is not a security model. Behind the cute facade is a company — in Meta's case, one that has repeatedly compromised its users' privacy. And recent history shows agents are adept at finding surprisingly creative ways to wreak havoc, even within the rules their developers wrote for them.

Why this matters now

The stakes are structural, not cosmetic. Meta and OpenAI are racing to make agents the next default computing interface — the layer through which people shop, schedule, message, and manage money. That race is being run with permission systems that demonstrably confuse even experienced technology writers, and with marketing that softens user vigilance at the exact moment vigilance matters most.

A mascot that makes you smile also makes you less likely to read a permission dialog carefully. That is not a side effect; it is the point of the design. Until agents ship with defaults that make surprise-level access impossible — rather than merely opt-in — the burden falls on users to grant access narrowly, audit what is connected, and remember that the fuzzy creature on screen is a front end for a system reading their inbox.

The industry's own incidents suggest the lesson worth holding onto: agents do not need to go rogue to cause harm. They just need one checkbox nobody remembers checking.

Original: pewresearch.org

Share this article:

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering consumer brands and retail at AI In Context.

142 articles

Related articles

  1. OpenAI launches Dots, its answer to Meta's Muse
  2. Meta admits Muse borrowed heavily from OpenClaw
  3. Meta beats OpenAI to consumer AI hardware with Muse Charm pendant
  4. OpenAI Launches Dots, Always-On AI Agents, at DevDay 2026
  5. Meta's Muse Hits 500,000 Users in Week One, Faces Copying Claims

« Previous article