google-site-verification: googlec7193c3de77668c9.html
Thursday , September 24 2026

Muse sure looks a lot like OpenClaw

We seem to be entering into an AI agent renaissance. Meta’s new consumer-facing AI agent, Muse, topped the App Store charts soon after its release and has 600,000 daily active users in the US, by an Apptopia estimate. And AI agent platform Instinct, whose eponymous creator is fundraising at a $2.5 billion valuation, has been making the rounds in the tech industry. Under the hood, though, there are some obvious similarities to the platform that started it all: OpenClaw.

For the past week or so, some social media users have alleged that Muse is directly built on OpenClaw. The two platforms use the same names for core files (SOUL.md, memory, tools, etc.), and have a lot of similar lines in the doc that governs personality, tone, and more (“Be genuinely helpful, not performatively helpful”). They also have a similar design. One Redditor argued that “Muse is just a wrapper app built on top of” OpenClaw — alleging it probably also came with that platform’s significant security risks. “Only non-tech ppl are buying the hype.”

Meta has denied the claims. Nat Friedman, head of product for Meta’s Superintelligence Labs wrote on X that Meta built Muse “from scratch.” He did, however, acknowledge Muse is “heavily inspired as a product” by OpenClaw. After he first used OpenClaw in January, he said, he purchased hundreds of Mac Minis for his team at Meta. And with Muse, he aimed to build a similar platform “that we could make safe and secure and easy to use and scale to billions of people.” As for why the OpenClaw file names and lines carried over, Friedman said the team believed that Steinberger had gotten those things “exactly right.”

Instinct appears less directly derivative. But like OpenClaw’s then-revolutionary messaging features, it allows users to communicate with their AI agents directly through messaging tools, and people have been using it for the same types of everyday, personal-assistant-esque use cases that made OpenClaw gain traction. One Instinct user raved on X that the AI agent filled out paperwork for an in-network doctor visit, canceled subscriptions, organized a bachelor party, booked activities for a vacation, booked a DMV appointment, paid an outstanding toll bill, and more. Another said their Instinct agent handled the recovery of a lost item they’d left at a hotel in Canada.

Even if both platforms were built from scratch, it’s clear how much they owe to OpenClaw.

OpenClaw didn’t invent the concept of AI agents, but in just 10 months, it took them from a proof of concept to something genuinely useful. Cobbled together as a one-man weekend project and running off users’ personal computers, it conversed with users the way they talked to other people: on messaging platforms like WhatsApp, Telegram, Slack, Teams, or Discord. In about a week, it garnered two million visitors and 100,000 stars on GitHub, spurring people to buy Mac Minis to run their agents 24/7, inspiring someone to create a social media network for the AI agents to “chat” on, and sparking a series of in-person meetups around the world for OpenClaw users.

Major AI companies were already betting big on agentic AI, but none of their products had broken through like OpenClaw, and Big Tech took notice. In February, OpenAI hired OpenClaw creator Peter Steinberger to work on agents for the company. In May, Google announced its consumer AI agent bets at its annual event. In June, Apple decided to go all-in on agents. In August, Instinct grew rapidly in its private beta and raised hundreds of millions of dollars. And in September, Meta introduced Muse. It’s fair to say that OpenClaw at least partially inspired all of them.

The real question isn’t whether products like Muse copied OpenClaw, but whether they improved it. As Friedman noted, one of OpenClaw’s only glaring issues was security. One of the top-downloaded skills on the platform contained malware, and by one researcher’s analysis, 15 percent of OpenClaw’s skill repository contained “malicious instructions” to secretly access user data or perform other suspicious tasks. By contrast, Zuckerberg wrote that Muse is “built from the ground up for privacy and security” and that user data and credentials are stored on the Muse Secure VM, an “isolated linux computer with a browser, CPU, memory, and storage.”

Right now, however, Muse may not improve security as much as it claims. Although user data is isolated from other users, Meta can still access it. The company said it plans to introduce a way “to cryptographically and verifiably prevent Meta from accessing data in your VM” later this year. Muse also defaults to letting Meta train and improve its models with user data, though users can opt out. And perhaps worst of all, a zero-day vulnerability flagged by a researcher on X this week allows anyone, with a simple attack, to hijack the agent, taking complete control. Instinct, for its part, has come under fire for criticism that its terms of service are overly broad, although the company seems to have adjusted them since.

See also  Deception in democracy: Beware the most common types of election-related scams

Meta and Instinct’s most important evolution is, in actuality, just making AI agents more broadly accessible. One reason some people find Muse useful is its ability to integrate with Meta’s systems, even if they’re uncomfortable handing over all their data to the company. And Insight allows users to chat with their AI agents via Apple’s default messaging product — significantly expanding the user base willing to try it out. While you can use both on dedicated local devices — and there are potential security benefits to that — it’s not the default option, also expanding the number of people willing to try them. At least for now, they’re less expensive than competing products like Google’s Spark, and although Instinct is still in beta, Muse’s one-tap downloading has overcome a lot of the friction tied to using OpenClaw.

In March, The Verge wrote that the OpenClaw user community sees the open-source AI agent as a “grassroots crusade and a noble pursuit, offering an escape hatch from an industry controlled by a handful of people at leading AI companies.” Now, those leading AI companies are putting up a fight.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.


Advertisements

See also  The FCC just gave itself the power to make a DJI drone ban stick

Check Also

You might not miss what Nikon removed from its cheaper full-frame Z5 IIC

Nikon waited five years to update its full-frame Z5 camera to the Z5 II, but …

People’s Picks: Shopping for a TV for the Holidays? This Is the Brand Readers Say You Should Stick To

Early holiday sales will kick off in the next few weeks, like Amazon’s October Prime …

Why can’t we just keep rogue AIs off the internet?

AI agents keep getting loose, escaping supposedly secure tests to attack real-world targets, commandeer obscure …

Leave a Reply

Available for Amazon Prime