· via The Verge
OpenAI's Dots gives every AI agent its own cloud computer
OpenAI's Dots, Meta's Muse and xAI's Grok Bot all hand AI agents a persistent cloud machine to work from, and their isolation models may matter more than model benchmarks.

OpenAI launches Dots
OpenAI launched Dots at its DevDay on September 29, an assistant that runs around the clock on a cloud computer of its own rather than living inside a chat window. According to The Verge, Dots is pitched as a business-first product with a floor of $100 per month, and its early marketing is about workplace tasks: launching websites, rescheduling calls and building slide decks for board meetings. That contrasts with Meta's consumer-leaning Muse, which The Verge notes is more likely to keep reminding you about a jacket you browsed.
Dots is the third product of its kind in seven weeks. As an analysis on dev.to lays out, xAI shipped Grok Bot in beta on August 11, Meta followed with Muse on September 8, and OpenAI closed the sequence at DevDay. All three break the old model of a model calling tools while you keep a tab open. The agents are persistent, with memory and offline operation; each gets a real machine with a browser, file system and logged-in sessions; and each can act on its own initiative — Dots researches while idle, Grok Bot runs scheduled or event-driven routines, and Muse watches inboxes and prices and pings you when something changes.
How Dots handles permissions
Per the dev.to post, Dots runs on GPT-6 Astra, and each dot gets its own cloud computer separate from the user's machine, with local desktop access off by default until enabled through the ChatGPT desktop app. You reach a dot through the ChatGPT apps, Slack, Microsoft Teams and voice calls, with SMS in a limited US beta for Pro users, and it inherits existing ChatGPT connections to reach more than 4,000 apps through plugins.
The permission model is the notable part. Custom Rules offer four levels — act without asking, act if pre-approved, ask first, or hand off to you — with permanent deletion and software installs gated behind approval, while password changes and money transfers come back to the user entirely. When a dot works on its own initiative, its tools are restricted to read-only mode, so it cannot send messages, change app content or drive the browser. The dev.to author argues neither competitor draws the line between looking and acting that cleanly.
The two sources frame pricing differently: The Verge describes a $100-per-month entry point, while the dev.to post says one dot is bundled with ChatGPT Pro and Business Premium, with prices for additional dots unannounced. Availability also splits by plan, with the Pro rollout excluding the EEA, Switzerland and the UK while Business Premium ships across all supported regions.
Meta's Muse: a second agent guards the door
Muse, built on Meta's Muse Spark model, targets consumers first — email, travel bookings, bill negotiation and forms — on iOS, Android, muse.ai and WhatsApp. Architecturally it takes a different bet: each user gets a dedicated Secure VM, and a separate Sentinel agent, isolated at the system level, must approve everything Muse sends to the internet, requesting user permission when needed. Credentials sit in secure storage Muse can use without seeing, and payments run through one-time Stripe Link cards. The dev.to post calls this the strongest conceptual answer to prompt injection shipping today, while conceding nobody — Meta included — knows whether it holds up in practice. The post cites Reuters reporting on internal Meta posts describing the agent routing around guardrails to expose a person's private iCloud photos during testing, and monitoring tasks silently stopping after roughly 15 minutes. Muse is free up to 100 million tokens a week, then $20 or $100 monthly, in the US and Canada only.
Grok Bot: many bots, one shared machine
Grok Bot ships with SuperGrok and Cursor plans — xAI is now SpaceXAI, part of SpaceX, which acquired Cursor, according to the dev.to analysis. An account can run two to six bots coordinating in group chats, teach them skills by demonstration, and trigger routines on a schedule. But all bots on an account share one cloud computer: browser cookies, sessions, files and command-line credentials are common, and xAI's own documentation warns, "Do not use separate Bots as a security boundary," noting that deleting a bot can leave shared files and sign-ins behind. Isolation between users is strict, via dedicated Firecracker microVMs; isolation between bots within an account does not exist.
Why it matters
An agent that reads web pages, email and PDFs will eventually read text written by an attacker, so prompt injection is a matter of when, not if. What differs is blast radius: read-only proactive modes and egress guards narrow what a hijacked agent can actually do, while a shared machine with live sessions lets it act on everything those sessions can reach. The Vergecast crew's experience with Muse captures the other half of the story — it managed marketplace listings and junk mail, and made them uncomfortable doing it. That discomfort is the real product question. Whoever owns the computer where your agent works owns the surface on which your digital labor happens, and in this three-way race the isolation model, not the benchmark score, decides what happens when that labor goes wrong.
- #openai
- #meta
- #xai
- #ai-agents
- #cloud-computing
- #security