Key Points
- Meta's Muse and OpenAI's Dots give each user a cloud computer hosting a personal agent.
- Local setups like OpenClaw still run on a user's own hardware, trading convenience for data control.
- Capability comes with exposure: a Muse flaw risked access to sensitive user data, per a report.
The latest:
Personal AI agents no longer require an always-on machine at home. Companies including Meta and OpenAI now run a persistent virtual computer inside their data centers, with the agent, its memory, browser and tools living there and continuing to work after the user closes a laptop or phone. Meta describes Muse as an agent that performs work on a user’s behalf rather than only answering questions.
Details:
- The cloud model: Each Muse agent runs inside a dedicated virtual machine branded Muse Secure VM, with its own browser and the credentials needed to reach services the user has connected. The agent keeps working after the app is closed, and users message it through the Muse app or WhatsApp.
- OpenAI’s version: OpenAI applies a similar design with Dots, where every Dot owns its own cloud computer and browser and can keep executing tasks while the user’s machine is switched off. Dots also lets users set which apps are connected, define permissions, and write rules blocking certain actions or requiring approval.
- A third approach: Instinct sits closer to a traditional personal assistant: users reach it by message or phone call, and it operates the phone, computer and apps the way a human assistant would. It is available on iPhone and Android through iMessage and WhatsApp, with access via a waitlist.
- Running it yourself: OpenClaw hosts an assistant on the user’s own hardware, running on macOS, Linux or a virtual server and reachable through WhatsApp, Telegram, Slack, Signal and iMessage. It can call cloud models from OpenAI or Anthropic, or drive a local model through LM Studio, Ollama or llama.cpp.
- The key distinction: Hosting the agent locally does not mean the model itself runs locally. The agent, its memory and tools can sit on a home machine while the reasoning happens in the cloud; the fully independent setup runs both on one device, with memory and processing demands rising as model size grows.
- Other local tools: AgenticSeek is a privacy-focused local assistant that browses the web, writes code and plans tasks, but typically needs more setup than OpenClaw, including a GitHub install. Open Interpreter turns a model into an assistant handling files, programs and the browser via text commands, while OpenHands targets developers.
- Security exposure: Weeks after Muse launched, a report disclosed a vulnerability that could have allowed access to sensitive personal data stored inside users’ virtual machines, prompting Meta to strengthen the service’s security warnings. Meta has not detailed further remediation steps beyond those warnings.
- Errors without hacking: Practical trials showed an agent can misread an instruction, act on inaccurate information, or carry out something the user never intended. In one published test, executing a task deleted data from the user’s Notion account — the cost of error changes once a system can act rather than only advise.
- The trade-off: Local operation gives maximum control over the model, data storage and tools, at the cost of hardware spending, setup and maintenance time. Cloud agents remove that burden, but the more of a user’s life an agent manages, the more data and permissions it needs on provider servers.
- Access and pricing: Grok Bot from xAI is available through some SuperGrok and Cursor plans, while Dots comes with ChatGPT Pro and Business Premium. Cue by Manus is closer to a phone app for building agents for daily tasks.
Background:
Open-weight models first let users run language models on their own machines instead of sending every request to OpenAI, Google or Anthropic servers. A model alone was not an agent: it needed memory, tools for files, web and apps, and a way to run continuously.
Between the lines:
The shift from local hardware to provider-run virtual machines moves the technical burden off the user and onto the company — and moves the risk with it. The Muse vulnerability and the deleted Notion data point at the same thing from two directions: an agent with real permissions fails expensively, whether through a security flaw or a simple misreading of intent.
What’s next
Watch whether providers expand permission controls of the kind Dots already offers, how Meta follows its Muse security warnings, and when Instinct moves off its waitlist to open access.