Friday, October 2, 2026
AI 인프라 · 뉴스 & 분석
홈 › 헤드라인 › 리포트
헤드라인 · 리포트

OpenAI, Meta, and xAI are investing in dedicated compute infrastructure for AI agents, with Stargate representing a major partnership for massive-scale datacenter buildout.

Hyperscaler shift from training-centric to agent-centric architectures drives a new multi-hundred-billion-dollar capex cycle; Stargate project signals infrastructure arms race accelerating compute consolidation among frontier AI labs.
업계 전문지Slicast · 2026년 10월 1일 13:20 UTC · 미국 · 출처: International Business Times, Singapore Edition
중요도 82

Ask people to picture an AI agent taking over their tasks and many will imagine a cursor moving around their laptop, opening a browser and typing into their apps. OpenAI, Meta and xAI are taking a different route: give the agent a computer of its own.

OpenAI introduced Dots at DevDay on September 29, following Meta's Muse on September 8 and xAI's Grok Bot, which entered beta on August 11. The implementations differ, but each gives an agent a remote environment where it can continue working after you close your laptop.

The three systems differ in design. OpenAI's Dots run on dedicated cloud computers with integrated browsers, supporting GPT-6 Astra and 4,000+ apps. Meta's Muse operates within a Secure VM for each user, with Sentinel controlling access. xAI's Grok Bot provides a persistent computer with browser, filesystem and terminal access, with multiple bots on the same account sharing the same machine.

The appeal is obvious: an agent gets a place to work without taking over the machine sitting in front of you. The harder question is what happens when that remote computer becomes connected to everything the agent needs to do its job.

**Why Put An Agent On A Separate Computer?**

A dedicated cloud machine lets an agent keep working in the background without tying up your laptop or automatically exposing the files and browser sessions already open on it.

Meta's Muse runs inside what the company calls a Secure VM, with a separate approval layer called Sentinel controlling what the agent can access outside the environment. "Dots are persistent agents with connected apps and their own cloud computer," OpenAI says.

Proactive research starts with read-only access, while actions such as sending messages, editing files or controlling a user's computer require additional permission. The separation creates a boundary around the agent's computing environment.

"Muse runs on its own dedicated computer in the cloud, contained so no one else's agent can reach it," Meta says in its Muse launch announcement. However, this does not by itself create a boundary around everything the agent is allowed to access.

**Isolated Hardware, Shared Keys: The Agent Security Trap**

An agent becomes useful when it can reach the services where your work happens: email, files, calendars, messaging platforms and other connected applications. Those connections move authority into the agent's environment even when the underlying computer is isolated.

OpenAI's Dots can use existing plugin and data permissions granted through ChatGPT. "Muse has no visibility into people's passwords or payment methods. Any credentials a person shares go into secure storage, so Muse can use them without seeing them," Meta says.

xAI's documentation states: "Every Bot on your account uses one persistent cloud computer. They share its files, browser sessions, and logins so they can hand work off. The computer is assigned per user, not per Bot. Do not use separate Bots as a security boundary." This means every bot created under an account uses the same persistent computer, including its files, browser sessions and logged-in application credentials. xAI specifically warns users not to treat separate bots as a security boundary, so creating one bot for work and another for different purposes does not by itself create two isolated environments.

Meta encountered a different data-flow problem. The company disclosed an incident involving its Marketplace integration in which addresses were shared in ways users did not expect. This does not indicate that Muse's virtual-machine isolation failed, but rather something narrower: keeping an agent's compute environment separate does not guarantee that information moving through connected services will stay within user expectations.

**What Happens To The Agent's Files And History?**

Persistence creates another question as these systems move from short tasks to long-running work: what remains in the agent's environment after the task ends?

xAI's documentation provides the clearest answer among the three. Terminating a computer ends the current session but preserves its durable disk, including synced bots, files and saved logins. Starting another computer restores that material. Deleting a bot removes its profile and conversation history, but files and logins stored on the shared computer can remain.

"Deleting a Bot does not remove shared-computer files or browser sessions," xAI states. The supplied OpenAI and Meta material does not provide comparably detailed answers about exporting everything an agent has accumulated, what persists after a plan is cancelled or how completely a user can move that working context to another provider.

These questions become more consequential as agents spend weeks or months inside these environments rather than minutes answering a prompt. The fundamental issue is whether the remote computer becomes a long-term store of your files, authenticated sessions and working history.

The critical question is what happens when you want to leave: what can you take with you, what remains behind, and how much of the agent's accumulated working context can actually be separated from the platform that hosted it?

**Your agent doesn't need to escape the sandbox to leak your files. It just needs to run curl.**

Security researcher Guanlan Dai examined Grok Bot and Muse to determine what happens after an injection attack succeeds. According to Dai's analysis posted on X on October 1, 2026, "command review isn't enough. The check belongs at the exit," suggesting that security validation must occur at the point where agents output or execute operations.

원문 보기
OpenAI, Meta, and xAI are investing in… · Slicast