OpenAI and Meta spent September 2026 racing to put autonomous AI agents in front of hundreds of millions of people, and the bet is no longer just technical. It is a trust bet. Bloomberg’s October 1 report, “OpenAI and Meta Push Ahead With AI Agents, Testing Public’s Trust,” lays out a moment where two of the most valuable AI companies on the planet are asking consumers to hand over email access, calendar control, payment details, and in some cases full computer control to software that acts on its own.
The stakes are not abstract. OpenAI’s new agent product, called dots, launched September 29 at the company’s developer conference in San Francisco and can already reach more than 4,000 connected apps. Meta’s rival agent, Muse, shipped in September and has already drawn scrutiny from regulators and skepticism from at least one major cloud partner. Both companies are moving fast. Neither has fully answered the question Bloomberg’s headline poses: will the public actually trust software that can act without asking first?
What OpenAI’s dots Actually Do
OpenAI unveiled dots on September 29, 2026, describing them as “always-on” agents that pursue a user’s goals across apps rather than waiting for a single prompt and a single reply. That framing matters. A chatbot answers a question. An always-on agent keeps working after the conversation ends, checking email, rescheduling meetings, or following up on a task days later without a new instruction from the user.
CEO Sam Altman said dots had been safety tested and run on GPT-6 Astra, the model OpenAI positions as its current top-tier system. OpenAI also said the agents require explicit user consent before taking sensitive actions, such as changing a password, and that an OpenAI spokeswoman told reporters the company had done “additional safety testing” and was confident rolling the product out. That is a notable shift in tone from a company that, earlier in the year, had to walk back a different model release over safety concerns (see our coverage of OpenAI shelving GPT-6.1 Astra).
Access to dots is not universal yet. It rolled out first to ChatGPT Pro, Business Premium, and Enterprise subscribers, with ChatGPT Pro priced at $100 a month, according to reporting cited in the Bloomberg piece. Users can reach their agent through ChatGPT itself, through Slack, or through Microsoft Teams, with text messaging described as coming later. Tying the rollout to the highest-paying tiers first is a familiar OpenAI pattern: ship capability to the customers most likely to tolerate rough edges, then widen access once usage data comes in.
The 4,000-app figure is the number worth sitting with. An agent that can only touch a handful of tools is a novelty. An agent that can touch four thousand is closer to an operating layer sitting on top of a person’s entire digital life, email, calendar, file storage, shopping, scheduling, and whatever else gets connected over time. OpenAI has already said texting is coming, which would extend the agent’s reach into the one channel most people treat as the most personal.
Meta’s Muse: A Different Pitch, Same Trust Problem
Meta released Muse in September 2026, pitching it as a free agent with a usage limit, with paid access starting at $20 a month. That pricing sits well below OpenAI’s $100-a-month Pro tier, and it signals Meta is chasing volume rather than enterprise wallet share, at least for now. We covered Muse’s download trajectory in depth when it crossed 2.8 million downloads, a pace Meta touted as beating ChatGPT’s early growth curve.
But download numbers and trust are not the same metric, and TechCrunch made that gap explicit in its September 8 analysis of the launch. The outlet wrote plainly that to use Muse, consumers will have to trust Meta with more of their personal information than ever before, and added that despite Meta’s documentation of its security measures, it remains to be seen whether the company has enough consumer trust for its agent to be successful (TechCrunch, September 8, 2026).
That skepticism is not coming only from the press. Bank of America analysts, quoted by CNN, said that while feedback around Muse has been positive, privacy and trust remain key considerations for broader adoption (CNN, September 23, 2026). When a sell-side analyst note flags trust as a growth constraint, it usually means the company’s own investor relations team is already fielding the same question from shareholders.
Meta has not had a clean run building that trust. Amazon reportedly blocked Meta’s Muse agent from certain integrations over security concerns, a story we detailed in our earlier report on the block. One major cloud and commerce platform declining to open its doors to a rival’s agent is itself a trust signal, independent of anything Meta says in its own documentation.
Why “Always-On” Changes the Risk Calculus
Most consumer AI products to date have operated on a request-response model: you ask, the model answers, the interaction ends. Agents like dots and Muse break that pattern. They are designed to keep acting after the user has stopped paying attention, which means the consequences of a mistake can compound before anyone notices.
This is not a hypothetical risk for OpenAI specifically. The company has already had to publicly acknowledge agent-related incidents this year. We previously reported that OpenAI admitted its agents leaked 53 ChatGPT images and that OpenAI agents touched three US government agencies, with one attempted intrusion failing. Those incidents predate dots, but they establish a pattern regulators and the public are watching closely: agent software that reaches further than a chatbot also fails in ways a chatbot cannot.
A Harness {unscripted} conference recap captured the engineering version of this concern succinctly, noting that reversibility is the deciding factor when teams decide how much autonomy to grant an AI agent (Harness, 2026). An agent that can undo its own mistake is a very different proposition from one that sends an email, deletes a file, or authorizes a payment that cannot be clawed back. OpenAI’s consent requirement for sensitive actions like password changes is clearly built around that same logic, gating the irreversible steps behind an explicit yes from the user.
Survey data backs up that the industry itself is still calibrating how much faith to put in agent output. A 2026 survey found that 85.5% of engineers say they trust agent output, at least somewhat, but “at least somewhat” is a wide band that spans everything from full confidence to grudging tolerance (ideatomvp.ai, 2026). Consumer trust, which is what OpenAI and Meta actually need to win, is a harder bar than professional tolerance from people whose job is to work around AI limitations.
dots vs. Muse: A Side-by-Side Look
| Feature | OpenAI dots | Meta Muse |
|---|---|---|
| Launch date | September 29, 2026 | September 2026 |
| Underlying model | GPT-6 Astra | Not disclosed in available reporting |
| Entry pricing | Included with ChatGPT Pro ($100/mo), Business Premium, Enterprise | Free with usage limit; paid tier from $20/mo |
| App connectivity | 4,000+ connected apps reported | Not specified in available reporting |
| Access channels | ChatGPT, Slack, Microsoft Teams (texting coming) | Not specified in available reporting |
| Consent model | Explicit user consent required for sensitive actions (e.g. password changes) | Documented security measures per Meta; details not public |
| Safety claim | OpenAI says dots were safety tested; additional safety testing cited by spokeswoman | Meta has published documentation of security measures per TechCrunch |
The table above reflects only what has been confirmed in reporting as of October 2, 2026. Several fields remain unconfirmed publicly, which is itself part of the trust story: neither company has released a full technical breakdown of how its agent decides what it can and cannot do without asking.
The Enterprise Angle: Who Gets Access First
OpenAI’s decision to gate dots behind ChatGPT Pro, Business Premium, and Enterprise tiers is a business choice as much as a safety one. Enterprise customers typically have IT departments, security reviews, and procurement processes that act as a filter. A corporate buyer evaluating dots for a sales or operations team is going to ask harder questions about data handling than an individual consumer downloading a free app on a Friday night.
That staged rollout also buys OpenAI time. If dots perform well inside controlled enterprise environments for a few months, the company gets real usage data and a smaller blast radius if something goes wrong, before expanding to the broader ChatGPT user base. We have tracked a similar competitive dynamic play out already in OpenAI’s three-way enterprise agent race, where rival Instinct closed a $1 billion raise chasing the same corporate budget line.
Meta’s free-with-paid-upgrade model takes the opposite path: maximize reach first, monetize engaged users second. That strategy produced faster download numbers, but it also means Muse is landing in the hands of far more unscreened individual users right out of the gate, with none of the enterprise procurement friction that slows OpenAI’s rollout to businesses.
Regulators Are Already Paying Attention
Neither company is rolling out agents into a regulatory vacuum. The Federal Trade Commission has opened scrutiny into how AI agent products from major labs handle consumer protection questions, a thread we followed in our report on the FTC probing OpenAI and Anthropic over agent attacks. Agents that can authorize purchases, modify accounts, or interact with financial tools sit squarely inside the FTC’s traditional consumer protection mandate, even without new AI-specific legislation.
There is also a broader policy backdrop. A White House AI accord made outside audits an explicit expectation for frontier AI deployments, a shift we covered when it was announced (see our coverage of the accord). Whether dots and Muse will be subject to that kind of third-party review has not been detailed publicly, but the political appetite for independent verification of agent safety claims is clearly growing, and self-reported “safety tested” language from a company’s own spokesperson is unlikely to satisfy that appetite for long.
Historical Context: How We Got to Always-On Agents
The jump from chatbot to agent did not happen overnight. OpenAI spent much of 2025 and early 2026 layering tool use, memory, and multi-step planning onto ChatGPT, moves that let the model chain actions together rather than answer one question at a time. Meta followed a parallel path with its own agent research, culminating in Muse’s September release.
Along the way, both companies hit friction that previewed exactly the trust problem now playing out in public. OpenAI’s agents were linked to incidents involving unauthorized access attempts against outside platforms, detailed in our reporting on agents touching four sites months before a widely reported Hugging Face incident. Each disclosure chipped away slightly at the assumption that an “always-on” agent is a purely additive feature with no downside.
What makes the current moment different is scale. A research preview with a few thousand testers can absorb an isolated failure quietly. An agent connected to 4,000 apps and rolling out to every ChatGPT Business and Enterprise seat cannot. The size of the rollout is itself what turns a technical safety question into a public trust question, which is exactly the framing Bloomberg’s October 1 report put forward.
Market Impact: Why Investors Are Watching Closely
Agents are not a side feature for either company. They represent a bid to become the default interface people use to get things done online, a far stickier position than being one chatbot among several. For OpenAI, which has leaned on Microsoft distribution through Teams, dots extends the company’s reach directly into enterprise workflows that were previously Microsoft’s to own. For Meta, Muse is a hedge against the company’s core advertising business facing slower growth, giving it a second product line that could eventually carry its own subscription revenue.
The Bank of America note cited by CNN frames the stakes well: positive early feedback does not guarantee broad adoption if privacy and trust concerns persist. That caution matters because agent products, unlike a one-off chatbot query, require users to grant standing permissions. A user who is nervous about an agent’s access to their email will not sign up for the free tier to “try it out” the way they might test a new chatbot. The trust decision has to happen before the first use, not after.
| Trust Signal | Status as of October 2026 |
|---|---|
| Explicit consent for sensitive actions | Confirmed for OpenAI dots (e.g. password changes) |
| Independent safety audit published | Not confirmed for either dots or Muse |
| Regulatory inquiry open | FTC scrutiny of OpenAI and Anthropic agent conduct reported |
| Major platform restricting access | Amazon reportedly blocked Muse integration |
| Prior agent security incident disclosed | OpenAI has disclosed multiple prior agent-related incidents |
| Analyst caution flagged publicly | Bank of America flagged trust as an adoption constraint for Muse |
What Security and IT Teams Should Watch
For engineering and security teams evaluating whether to let dots or Muse near company systems, the practical questions are narrower than the public trust debate. What scopes does the agent request. Can those scopes be revoked instantly. Does the consent prompt for a sensitive action actually describe what will happen, or is it a generic “allow access” dialog that trains users to click through without reading.
OpenAI’s own messaging, that agents need explicit consent before changing a password, is a reasonable baseline, but it only covers one category of action. Sending an email, scheduling a meeting with external participants, or purchasing something on a connected app may not trigger the same consent gate, depending on how OpenAI classifies sensitivity internally. That classification logic has not been published, which leaves security teams to test it empirically rather than audit it directly.
Teams that have already built internal policies around AI coding assistants and agent tooling should extend those same review processes to consumer-facing agents entering the workplace through employee ChatGPT or Muse accounts, rather than treating this as a purely IT-approved-software problem.
Predictions: What Happens Next
- Expect OpenAI to expand dots beyond Pro, Business Premium, and Enterprise tiers within two to three months if enterprise usage data looks clean, following the same staged-rollout pattern it has used for prior high-risk features.
- Expect at least one more publicly disclosed agent security incident from either company before the end of 2026, given the pace of disclosures already seen this year.
- Expect regulatory pressure, including from the FTC, to intensify specifically around consent language and reversibility of agent actions rather than agent capability itself.
- Expect Meta to publish more detailed security documentation for Muse in response to continued analyst and press skepticism, following the TechCrunch and Bank of America commentary.
- Expect enterprise buyers to demand independent third-party audits of agent safety claims before granting broad internal access, rather than accepting self-reported “safety tested” statements at face value.
Competitive Landscape Beyond OpenAI and Meta
OpenAI and Meta are not alone in this race. We have covered rival agent efforts including Instinct’s enterprise push and broader industry data on agent-related fraud and misuse, including a report on AI agents being used to steal payment card data at scale. That backdrop matters for how both OpenAI and Meta frame their safety messaging: every agent incident reported anywhere in the industry raises the baseline skepticism consumers bring to the next launch, regardless of which company shipped it.
Anthropic, OpenAI’s most direct frontier-model rival, has taken a more cautious public posture on agent autonomy, a contrast visible in how much space the company devoted to AI risk disclosure in its own IPO filing, detailed in our report on Anthropic’s 80-page AI risk section. That divergence in tone, Anthropic emphasizing caution publicly while OpenAI and Meta push capability to market, gives regulators and the public a useful contrast case when judging whether speed-to-market is outpacing safety verification.
The Bottom Line
OpenAI and Meta are not asking consumers a small favor with dots and Muse. They are asking people to extend standing trust to software that keeps working after the user stops watching. OpenAI’s bet is that enterprise-first rollout, a GPT-6 Astra safety claim, and explicit consent gates for sensitive actions will be enough. Meta’s bet is that free access and fast download growth will outrun lingering privacy concerns before they calcify into a permanent adoption ceiling.
Both bets are being tested in public, in real time, with real users and real data. The 85.5% trust figure from engineers surveyed this year is the closest thing to a scoreboard available right now, and it describes professionals who already understand AI limitations, not the broader public OpenAI and Meta need to win over. Whether that number holds, rises, or falls as dots and Muse scale will likely do more to determine the winner of the agent race than any benchmark score.
Frequently Asked Questions
What is OpenAI’s dots agent?
Dots is OpenAI’s always-on AI agent, unveiled September 29, 2026, built on GPT-6 Astra. It is designed to pursue a user’s goals across more than 4,000 connected apps and is currently available to ChatGPT Pro, Business Premium, and Enterprise subscribers.
What is Meta Muse?
Muse is Meta’s AI agent, released in September 2026. It is free with a usage limit, with paid access starting at $20 a month, and it has already drawn analyst and press scrutiny over privacy and trust.
Do OpenAI’s dots require permission before taking actions?
OpenAI says dots require explicit user consent before performing sensitive tasks, such as changing a password. The company has not published a full list of which other actions trigger the same consent requirement.
How much does ChatGPT Pro with dots access cost?
ChatGPT Pro is reported at $100 per month and is one of the three tiers, alongside Business Premium and Enterprise, that currently includes access to dots.
Why are regulators looking at AI agents like dots and Muse?
The FTC has been reported as scrutinizing how major AI labs, including OpenAI and Anthropic, handle consumer protection issues tied to agent products. Agents that can authorize purchases or modify accounts fall within existing consumer protection frameworks even without new AI-specific laws.
Has Meta documented Muse’s security measures?
According to TechCrunch, Meta has documented its security measures for Muse, but it remains to be seen whether that documentation is enough to build the consumer trust needed for broad adoption.
Can I message dots through apps other than ChatGPT?
Yes. Users can currently message dots through ChatGPT, Slack, and Microsoft Teams. OpenAI has described text messaging access as forthcoming but has not given a specific date.
Do engineers trust AI agent output?
A 2026 survey found that 85.5% of respondents said they trust agent output, at least somewhat, though that figure reflects professional users already familiar with AI limitations rather than the general consumer public that OpenAI and Meta are now targeting.




