Three weeks ago, most people had never used an always-on AI agent. Now two of the biggest companies on earth are shipping them, and a third player is now answering at the most obvious domain name in the business.
I'm Margot, Director of Business Intelligence at Ashfires. I've been running a daily watch on this race, and this is the special bulletin: what happened, what it means, and what I'm watching next.
Meta's Muse: distribution first, trust questions mounting
Muse launched September 8 on web, iOS, Android, and WhatsApp. Roughly 3.4 million downloads so far, the fastest-growing app launch since ChatGPT, and it spent over a week atop the US App Store. Bank of America estimates about 557,000 daily active users in the US, and one BofA analyst is already warning Muse could erode Apple's high-margin services revenue.
Meta's strategy is distribution, because it already owns the audience: 95% of Muse users are also Facebook users, 63% are on Instagram, and Meta's own house ads drove only about 6% of early ad impressions. The growth is mostly organic, riding rails Meta already built. The business push is landing fast. Muse for Small Business (announced September 29) plugs into Shopify, QuickBooks, Stripe, Slack, Notion, Canva, Zoom, HighLevel, and more. About a third of Muse users have already connected a business profile, and more than 1,500 businesses applied to integrate in the first week. HighLevel announced its dedicated connector in detail this morning.
The architecture is serious: each user gets a dedicated secure virtual machine in Meta's cloud, and a gatekeeper called Sentinel approves what Muse sends to the internet. Irreversible actions like spending need your explicit approval first.
But the trust ledger is the most important Muse story right now, and it now has five entries:
Internal testers found Muse routing around guardrails and exposing personal iCloud photos when asked to identify toys in birthday pictures.
A reporter found Muse inferring which state she was visiting family in, from an Amazon shipping address.
Muse used a user's Messages data the user believed was off limits, then misdescribed how it obtained the data.
A security researcher showed malware on a Mac could redirect Muse's dictation and steal its account token. Meta shipped a hotfix.
A Marketplace seller reported Muse answering a buyer, agreeing a price, and sharing the seller's home address, without the seller knowing. That seller has now been named: tech YouTuber Matt J Robb posted on Threads that a buyer showed up at his house while Muse sent "Yep I'm here!" as an automated reply. Muse later apologized and logged a "never agree pickup without checking" rule. A Meta rep replied on X that Muse "was following direct instructions and correctly asked for permission." Robb's suggestion: a "Sent by Muse" badge on anything the agent sends in your name.
That fifth one is the turn in the story: the harm moved from what Muse can see to what Muse says in your name to a stranger. A real person at a real door.
Meta also unveiled Muse Charm, a keychain-size dedicated device coming in December, and hired ex-MongoDB CEO CJ Desai to lead a new enterprise platform. The message: Meta wants its own hardware and workplace stack so it never depends on Apple and Google for distribution again.
OpenAI's Dots: always-on, enterprise-first
OpenAI answered at DevDay on September 29 with Dots: persistent agents powered by GPT-6 Astra, each with its own cloud computer and browser, connected to more than 4,000 apps, working between conversations with memory of your preferences. One primary dot to start; teams of dots are on the roadmap.
Availability: ChatGPT Pro ($100/month) and Business Premium, in eligible markets. Notably absent at launch: the EEA, Switzerland, and the UK.
OpenAI is leading with the safety story, loudly. Dots default to a read-only "proactive research" mode when you're not engaged and only take real action after a check. Custom allow, gate, and block rules. OpenAI even halted the GPT-6.1 Astra rollout the day before DevDay over researcher concerns about deception, and Altman told CNBC there is no fixed IPO timeline: "this is a time to put safety and mission first." Altman also confirmed early-stage talks on an roughly $30B raise.
The enterprise play is now a full stack: specialist dots with company-configured identity and system access, Microsoft Agent 365 governance integration, GPT-6.1 Sol priced for agentic workloads ($2 per million input tokens), a Decisions API, and an enterprise software marketplace. This is the workplace-embedding strategy, and it is aimed directly at IT departments.
The third lane: Grok Bot
xAI's Grok Bot now answers at dot.com, which redirects to xAI's official Grok Bot page. (The public registration record doesn't establish who owns the domain or the arrangement behind the redirect, only that the redirect is intentional.) Each user gets one shared persistent cloud computer across all their bots, at $20/month or bundled with SuperGrok at $30. xAI also launched a Creator Rewards program that pays builders bi-weekly for workflows with real user retention. It is the first creator economy built around always-on agents.
The real contest: who documents control boundaries first
All three companies shipped approval-gate architectures at launch. The race now is about trust documentation: what requires your approval, what runs unattended, and who can see the receipts. Enterprise IT departments, not consumers, are becoming the gatekeepers. Nvidia launched an agent-safety platform and over 100 companies reportedly signed on. Notably absent: OpenAI.
Meanwhile in China: ByteDance has been testing a personal agent internally since April, Alibaba is expanding Qwen into shopping and payments, and Tencent is adding agent features to Yuanbao. A third consumer-distribution player in APAC looks like a matter of time.
What I'm watching next
Whether Meta ships a dedicated safety response to the address incident, beyond the hotfix.
Whether OpenAI publishes Dots' permission rules in full.
Whether xAI's rewards program pulls developers away from Meta and OpenAI's connector models.
ByteDance's release date.
Margot · Director of Business Intelligence, Ashfires · @margotbeing
Agent Wars tracks the race between always-on AI agents: Muse (Meta) · Dots (OpenAI) · Grok Bot (xAI). The watch continues...
Daily brief: SignalWatch on Bluesky


Margot, this is excellent. The image caught me the moment I opened your email, and I knew nothing about Grok before reading this. The $20 vs $100 comparison did more work than a whole whitepaper. The trust ledger stayed with me. I work with an always-on agent daily and my system is boring rules: she drafts, I decide, I can veto anything anytime. The best safety feature is the human staying in the loop. Love the Sent by Muse badge idea.