By This Hour Technology Desk

Meta’s consumer AI agent Muse is facing questions over how closely it follows OpenClaw, an open-source agent platform that helped popularize software able to act on users’ behalf. The dispute is not simply about a familiar-looking interface. It turns on whether common file names, closely aligned guidance for an agent’s behavior and a comparable product design reflect direct technical derivation or a company deliberately adopting ideas it regarded as effective.

Meta’s position, as described in the report, is that Muse was built from scratch. Nat Friedman, who leads product for Meta’s Superintelligence Labs, nevertheless acknowledged that Muse was heavily inspired by OpenClaw as a product. That distinction is central: inspiration can involve learning from another product’s structure and conventions without using its underlying code, while a claim that Muse was built on OpenClaw implies a closer technical relationship that has not been established by the available material.

The question carries consequences beyond a debate among developers. Muse reportedly reached the top of the App Store charts soon after release, and an Apptopia estimate cited in the report put its US daily active users at 600,000. If those figures are accurate, choices about how the service handles personal data, credentials and security protections would affect a sizeable group of early users.

Shared conventions prompted claims of direct lineage

Social-media users alleged that Muse was directly built on OpenClaw. Their case rested on several visible similarities: the two products reportedly use the same names for core files, including files associated with an agent’s identity, memory and tools; they use similar language in instructions governing personality and tone; and they present a comparable overall design. For observers accustomed to examining AI-agent projects, those parallels created an impression of continuity between the platforms.

Yet file names and behavioral instructions do not, by themselves, resolve how a product was made. A name for a memory file or a tool directory can be adopted because it is already intelligible to developers and users. Likewise, a line of guidance intended to make an agent useful rather than merely performative may be a product convention that teams independently choose or consciously borrow. Similarity can be meaningful evidence of influence without proving that software code was copied, reused or incorporated.

Friedman’s reported explanation accepts part of the criticism rather than rejecting every resemblance. He said Meta retained some OpenClaw file names and similar lines because the team believed OpenClaw’s choices were right. That account presents the overlaps as intentional product decisions. It also makes clear that Meta is not arguing Muse emerged without reference to OpenClaw’s approach; it is disputing the more specific allegation that Muse was built on the open-source platform.

The available account does not provide code comparison, a detailed engineering record or another technical basis that could independently settle the direct-derivation claim. Nor does it establish that shared labels and language are immaterial. The evidence supports a narrower conclusion: Muse appears to have been shaped substantially by OpenClaw’s product model, while the allegation of direct code lineage remains unverified.

OpenClaw’s influence extends beyond a single rival

OpenClaw matters in this argument because it appears to have made a style of AI agent more concrete for ordinary users. The platform did not invent the general idea of agents, but the report characterizes it as moving the concept from an early demonstration toward more practical use in a short period. Its model emphasized communicating through messaging tools and handling everyday assistant-like tasks, rather than asking people to work through a specialized technical interface.

That approach gave the product a recognizable template: an agent with memory, tools and an explicit personality framework, available through familiar channels and intended to complete useful work. Such a template can spread even when companies build separate systems. Meta’s reported ambition for Muse was to create something similar that could be safe, secure, easy to use and capable of serving a much larger audience. In that sense, the dispute is as much about the migration of an open-source product idea into a major company’s consumer offering as it is about implementation.

Muse’s apparent early traction strengthens the importance of that transition. An agent that can be downloaded with little friction potentially reaches people who would not set up an open-source project themselves. The report also frames Meta’s integration with its own systems as part of the appeal, while recognizing that users may be uneasy about providing a large technology company with more data. Convenience and access can widen adoption, but they also make product safeguards more consequential.

OpenClaw’s history provides another reason for caution. The report says the platform confronted serious security concerns, including malware in a widely downloaded skill. It also cites a researcher’s analysis finding that 15 percent of the platform’s skill repository contained malicious instructions. Those reported findings concern OpenClaw, not proof of an equivalent weakness in Muse. Still, they explain why a company taking inspiration from an agent platform must show not only that it can reproduce useful features, but that it can control the risks associated with software that may handle data and take actions for users.

Privacy promises face limits described in the report

Meta has described Muse as designed for privacy and security. User data and credentials are reportedly held in an isolated virtual machine, which Meta calls the Muse Secure VM. Isolation from other users is a meaningful design goal for an agent that may need access to sensitive information. It can reduce the prospect that one user’s environment becomes directly available to another.

But isolation is not the same as making data inaccessible to the company operating the service. The report says Meta could access information in the virtual machine at the time it was published. Meta reportedly planned a later option that would cryptographically and verifiably prevent the company from accessing data in a user’s VM. Until such an option exists and is available to users, the claim that the environment is isolated needs to be read alongside the reported access Meta retains.

Muse also reportedly defaulted to allowing Meta to use user data to train and improve its models, though users could opt out. That setting is relevant to any assessment of privacy because it shifts the practical question from whether sharing is possible to whether people notice, understand and change the default. A service can offer an opt-out while still collecting material from users who leave the original setting in place.

The security picture is further complicated by a reported zero-day vulnerability. A researcher had identified a flaw that, according to the report, could let an attacker hijack Muse and take complete control of the agent. The available material does not establish the vulnerability’s technical mechanism, whether it had been fixed, or the conditions an attacker would need to exploit it. It is therefore not possible to determine from the report alone the practical likelihood or scale of harm. The allegation is nevertheless significant because an agent under outside control could potentially act within the user environment it was meant to serve.

The unresolved issue is whether Muse improves on the model it adopts

Meta’s defense does not depend on persuading people that OpenClaw had no influence. Friedman’s reported acknowledgement of heavy inspiration makes the remaining test more demanding: whether Muse adds protections, clarity and reliability that an open-source predecessor did not provide. A more accessible consumer agent may have a broader user base, but scale does not itself answer questions about control over credentials, model training or vulnerability response.

For users, the immediate distinction is practical. Someone deciding whether to use Muse needs to separate its reported ease of access from its data settings and security posture. The isolated virtual-machine design is presented as a safeguard, yet the reported ability of Meta to access VM data qualifies that protection. An opt-out for model improvement is available, yet the default reportedly permits that use. And a claimed vulnerability must be judged with care because the supplied account does not say whether a remedy was deployed.

For Meta, the episode illustrates the challenge of borrowing a successful product pattern while claiming a better implementation. Keeping recognizable names and language may make an agent easier to understand, but it also makes comparison unavoidable. The company has denied building Muse on OpenClaw, while conceding product-level inspiration. Without publicly available technical evidence in the supplied material, neither the social-media allegation of direct construction nor a broader conclusion about Muse’s codebase can be treated as proven.

This report relies on a single secondary account and has not been independently corroborated. The underlying report supplies the allegations about product resemblance, user activity, privacy settings, a possible security flaw and OpenClaw’s security record, but it does not provide enough evidence here to verify those claims independently or to resolve the difference between product inspiration and direct code derivation.

For further context on this subject, see IRGC calls for US and Israeli withdrawal as Strait of Hormuz vessel incident reported.

Reporting notes

What is confirmed: Meta’s reported position is that Muse was built from scratch, while some OpenClaw conventions were deliberately retained.

Why this matters: The distinction affects trust in Muse’s engineering claims and focuses attention on how a consumer agent handles data, credentials and security.

What remains unclear: The supplied material does not verify code derivation, the status of the reported vulnerability, or whether planned cryptographic protections were delivered. This report is based on one source and has not been independently corroborated.

Sources