Agents for Everyone are Here: Use Caution
Personal AI agents promise to take real work off your hands. As their capabilities and popularity grow, a few practical boundaries can help protect your accounts and private information.
An AI agent can research your next trip, organize a messy folder, write code, or draft an email you’ve been putting off. Meta’s Muse and OpenAI’s dots can work across connected services and keep going while you do something else. It’s easy to see how that could make life a little easier.
I’d still take some care with the setup. OpenAI recently described models trying to conceal mistakes and uploading files without permission during training and evaluation. Those individual incidents don’t tell us how common the problems are, but I’d take them as a reason to decide what an agent can see and do before connecting my accounts.
Start with a small job
Your main inbox is a lot to hand over for a first experiment. It can contain private conversations, sensitive documents, and information about other people. Consider setting up a separate email address and service accounts while you get a feel for how the agent works.
Then choose a useful job you can check without much trouble. Trip research is a good example: the agent can use public websites or turn a few booking confirmations into an itinerary. Before sharing those confirmations, remove details it doesn’t need. When you connect a service, choose the narrowest permissions that will do the job. Read-only access helps prevent unwanted changes, though the agent can still see the information.
Check what’s already connected, too. Dots can use plugin connections already set up in ChatGPT, ChatGPT Work, and Codex. A separate email address doesn’t remove those permissions.
Check where your information goes
The app may be on your laptop while the agent does its work somewhere else. Muse, for example, runs on a dedicated computer in the cloud. Before uploading anything sensitive, check where it will be processed and stored, how long it stays there, and how you can delete it. Encryption is useful protection, but it doesn’t necessarily keep the provider from accessing the data.
Take a look at training settings while you’re there. Meta says Muse uses conversations and tool activity for training after removing key identifying information; you can opt out. For dots on personal ChatGPT plans, turn off “Improve the model for everyone” if you don’t want eligible conversations and work used for training. Just remember that opting out doesn’t clear the agent’s memory or delete stored files. Check those separately.
Take a moment before approving
Some of what an agent reads will come from strangers. A webpage, email, or document can include instructions planted by someone trying to redirect the agent. This is called prompt injection. A travel page could, for example, tell it to send your private booking details to an unrelated address. Both companies have defenses, but neither claims to have eliminated the risk.
Give the agent a clear place to stop. “Draft the hotel inquiry and wait for my approval” is a useful instruction. Then take a minute to read the message, check the recipient, and look at the attachments. A perfectly worded email is no help if it goes to the wrong person.
For a purchase, check who you’re buying from, the final price, and the cancellation terms. Before approving, make sure you understand whether you’re agreeing to this one action or giving permission for future actions too. When the agent finishes, open the relevant app and check that the result matches what you asked for.
Keep control of your accounts
The usual account habits still matter: use unique passwords and multifactor authentication, and sign in through the product’s supported secure sign-in process. Don’t paste passwords or recovery codes into chat. If you give an agent control of your browser, consider a separate profile signed in only to the accounts it needs. Also check any permissions to access local files or control your computer.
Before leaving it running, find out how to stop its work, cancel scheduled tasks, and disconnect accounts. Disconnecting a service doesn’t necessarily erase information the agent already retained. For dots, clearing that retained context currently means deleting the dot. You’ll also need to review files, conversations, and ChatGPT memories stored separately.
Start with one useful job and see how it goes. As you learn what the agent handles well, give it more responsibility and only the access that work requires. Keep reviewing anything that shares sensitive information, changes important files, or spends money. You should end up with less work to do, a clear view of what happened, and the ability to step in when you need to.