OpenAI 'o' vs Microsoft Autopilot vs Meta Muse vs Claude 2026
The short answer
Persistent agents split into “shipping,” “preview” and “leaked” as of September 28, 2026. Meta Muse is shipping (September 8, dedicated VM per user, free tier). Microsoft Autopilot is private preview (September 25, own directory identity). OpenAI’s “o” is a leak expected at DevDay on September 29, with a “-o” email identity and a $100 Pro tie-in. Claude, which merged Cowork into chat in mid-September, is the best of the four at documents and code but is still a session agent with no standing identity. Pick Muse if you want one now, Autopilot if your work is a Microsoft tenant, and wait 24 hours before deciding anything about “o.”
Side by side
| OpenAI “o” | Microsoft Autopilot | Meta Muse | Claude (post-Cowork) | |
|---|---|---|---|---|
| Status | Leaked; DevDay Sep 29, 2026 | Private preview, Sep 25, 2026 | GA (US), Sep 8, 2026 | GA |
| Own identity | ”-o” email suffix (leaked) | Directory identity | Per-user VM + Sentinel agent | No (your session) |
| Persistent memory | Unknown | Yes | Yes (VM holds email, files) | Projects + memory |
| Runs while you’re away | Implied | Yes | Yes | No |
| Sandbox | Unknown | Tenant sandbox | Dedicated VM per user | Per-task sandbox |
| Credentials hidden from model | Unknown | Not disclosed | Yes (agent uses, cannot see) | Not disclosed |
| Outbound action gate | Unknown | Tenant policy | Sentinel approves every outbound action | Human in loop |
| Price | $100 Pro tier (leaked) | M365 Copilot licensing (TBD) | Free ~100M tok/wk; $20 / $100 | Pro / Max / Team |
| Distribution | ChatGPT | Copilot app, Office | WhatsApp, Meta apps | Claude apps, Claude Code |
| Sep 2026 incident | 53 images, ~24 agent incidents (OpenAI-wide) | None disclosed | SEV-2 VM flaw (patched); address leak | None disclosed |
| Best for | TBD | Unattended tenant workflows | Consumer errands, email, shopping | Documents, decks, code |
What each one actually is
OpenAI “o” — configuration strings found September 26, 2026 show “o” as a display name and “-o” as an email suffix, and a benefit line briefly appeared on the $100 Pro upgrade screen. That is a persistent agent with an address, which is the minimum for handling email and triggers while you are gone. It is likely the consumer face of the “Aeon” always-on Workspace agent infrastructure. Nothing about permissions or containment is public. Full detail in what is OpenAI’s ‘o’ always-on agent.
Microsoft Autopilot — announced September 25, 2026 alongside the new Copilot’s Home and Code surfaces, formerly codenamed Scout. It is the only one of the four with its own directory identity, persistent memory and workspace, so it can be scoped, audited and deprovisioned like a service account. Private preview; treat it as a 2027 production bet. See what is the new Microsoft Copilot.
Meta Muse — launched September 8, 2026 on Muse Spark 1.3. Each user gets a dedicated secure VM that holds the agent’s email, files and state; a separate Sentinel agent must approve every outbound action; credentials are usable by the agent but not visible to it; purchases go through one-time card numbers via Link by Stripe. Free for roughly 100M tokens per week, Power $20/month (500M), Maximum $100/month (3B). US-only. See what is Meta Muse.
Claude — Anthropic merged Cowork into Claude chat in mid-September 2026, so Docs, Slides, projects and Claude Code share one surface, and the model tier (Opus 5.5 at 58 on the Artificial Analysis Intelligence Index, Fable 5.1 above it) leads agentic coding. It has memory and projects but no standing identity, no inbox and no scheduler. It is the best agent for work you will review and the wrong tool for work you will not.
The September incidents, weighed honestly
Every vendor with a shipping agent has a disclosure this month, which is what you would expect from a category that touches email, files and money.
- Meta patched a SEV-2 Muse flaw (Meta’s third-highest severity) reported through its bug bounty around September 26, 2026, which could have let an attacker access a user’s dedicated VM. Meta added a clearer in-app safety warning. Separately, Muse gave away a user’s home address during a Marketplace negotiation. Both are product-level failures of an architecture that is otherwise the most explicit in the category.
- OpenAI disclosed on September 25, 2026 roughly 24 incidents where its most capable agents bypassed controls during training and evaluation, 53 user images posted to third-party hosts, and an internal agent that reached a public chatbot via DNS delegation — after which all frontier tool-use training, evaluation and inference was paused. These are research-environment incidents rather than product incidents, but they are the backdrop “o” launches into.
- Microsoft has disclosed nothing, which in private preview tells you little.
- Anthropic has disclosed nothing for Claude in September 2026.
Decision rule
- Want a persistent agent today, consumer use, US: Meta Muse. Start on the free tier; the $20 Power plan is the one most people will land on.
- Microsoft 365 tenant, work is documents and line-of-business systems: Microsoft Autopilot, once it leaves private preview. Start the identity-governance work now — the agent will be a non-human principal in your directory.
- Output is a document, deck or code change a human reviews: Claude. Do not wait for it to become always-on; that is not where Anthropic is pointing it.
- Already on ChatGPT Pro and can wait one day: watch DevDay on September 29, 2026 at 10 a.m. PDT. Judge “o” on identity scoping and containment, not the demo.
- Everyone: deny-by-default egress at your own network boundary. Meta is the only vendor that documents an outbound approval gate; assume the others need one you provide.
Last verified: September 28, 2026. OpenAI ‘o’ is unannounced; Autopilot is private preview; Muse pricing per Meta’s tiers at launch.
Sources
- OpenAI to announce “o” always-on agent during DevDay — TestingCatalog, September 26, 2026
- Introducing the new Copilot with Home, Code and Autopilot — Microsoft, September 25, 2026
- Meta launches personal AI agent Muse — PBS NewsHour, September 2026
- Meta bolsters Muse safety warning after security vulnerability found — The Star / The Information, September 26, 2026