The Always-On Agent Showdown: Architectural, Security, and Autonomy Comparison Across Meta Muse, OpenAI Dots, Google Gemini Spark, and Perplexity Computer
A head-to-head architectural breakdown of the leading 2026 always-on agent frameworks: Meta Muse, OpenAI Dots, Google Gemini Spark, and Perplexity Computer across sandboxes, security, routing, and autonomy.

Series: Always-On Autonomous Agents - Part 5
Series: ← Part 4: Perplexity Computer: The Multi-Model Digital Worker, 400+ Connectors, and Portable Sandboxes (Previous)
Summary
The autumn of 2026 transformed artificial intelligence from an era of episodic, prompt-driven assistants into a high-stakes battleground of always-on, ambient autonomous agents. Rather than waiting passively in an open browser tab, frontier systems now operate as persistent background coworkers: executing multi-day objectives, monitoring enterprise communications, dispatching scheduled workflows, and directly driving graphical operating systems inside isolated cloud virtual machines.
Yet, despite sharing the promise of continuous agency, the four leading pioneers—Meta Muse, OpenAI Dots, Google Gemini Spark, and Perplexity Computer—approach the problem from radically divergent architectural philosophies. Meta anchored its architecture to consumer device integration and host-side eBPF kernel security. OpenAI built dedicated single-tenant microVM computers around GPT-6 Astra paired with a human-gated mutation hierarchy. Google tethered Spark directly to its Workspace enterprise graph, Model Context Protocol (MCP), and FIDO-standardized cryptographic payments (AP2). Meanwhile, Perplexity rejected single-model monopolies entirely, engineering an asynchronous DAG execution engine that routes subtasks across frontier models and runs seamlessly on both cloud microVMs and on-premises edge hardware. This architectural deep dive delivers a head-to-head evaluation across execution runtimes, security sandboxes, multi-model routing, identity governance, and financial autonomy.
Master Architectural Comparison Matrix
| Architectural Dimension | Meta Muse | OpenAI Dots | Google Gemini Spark | Perplexity Computer |
|---|---|---|---|---|
| Primary Target Domain | Consumer & Personal Life Ops | Enterprise Knowledge & Coding | Enterprise Workspace & Operations | Multi-Model Engineering & Research |
| Core Foundation Model | Muse Spark 1.3 | GPT-6 Astra (with Sol for tasks) | Gemini 4 Argon & Gemini 3.8 | Dynamic Multi-Model (Claude, GPT, Gemini, Grok) |
| Execution Sandbox | Single-tenant Secure VM + eBPF | Single-tenant microVM + Chromium | Google Cloud microVM daemons | Firecracker microVMs + On-Prem Appliance |
| Hardware Option | Cloud Only (Meta DC) | Cloud Only (Azure / OAI DC) | Cloud Only (Google Cloud) | Hybrid (Cloud + NVIDIA DGX Spark / RTX AI PCs) |
| Tool / App Ecosystem | Consumer mobile apps & web APIs | 4,000+ commercial app plugins | Google Workspace + MCP Servers | 400+ Pre-authenticated SaaS connectors |
| Financial Autonomy | Stripe Link single-use checkout | Hard Handover (User manual only) | FIDO Agent Payments Protocol (AP2) | OAuth token delegation & read-only gates |
| Workflow Paradigm | Goal trees & dynamic Artifacts | Persistent daemons & Custom Rules | Ambient background Workspace threads | Asynchronous Directed Acyclic Graphs (DAGs) |
| Security Containment | Sentinel daemon + eBPF taint tracking | 4-tier Custom Rules (Act/Approve/Ask/Handoff) | IAM boundaries + AP2 digital mandates | Signed Connector Gateway & zero data retention |
Prior Reading Material
To trace the architectural evolution of each framework evaluated in this showdown, explore our standalone deep dives across the Always-On series:
- Introducing Meta Muse: Personal AI Agents, Muse Spark, and Secure VM Architecture — Part 1: Host-side Sentinel security, eBPF kernel taint tracking, and Stripe Link integration.
- OpenAI DOTS: Inside the Always-On Agentic Architecture, Bubbly Avatars, and GPT-6 Astra Cloud Sandboxes — Part 2: Isolated cloud computers, Chromium automation, and the four-tiered governance hierarchy.
- Google Gemini Spark: Always-On Workspace Intelligence, AP2 Protocols, and Cloud VM Isolation — Part 3: Deep Google Workspace daemons, MCP tool routing, and FIDO cryptographic mandates.
- Perplexity Computer: The Multi-Model Digital Worker, 400+ Connectors, and Portable Sandboxes — Part 4: Asynchronous DAG task orchestration, dynamic model routing, and on-premises Portable hardware.
1. The Four Philosophies of Ambient Agency
Every major tech titan has converged on the conclusion that conversational chat interfaces are a UX dead end for complex workflows. However, the architectural foundation each lab chose reflects their core business model and defensive moat.
flowchart TD
subgraph MetaPhil["1. Meta Muse: The Consumer Life Concierge"]
direction TB
M1["Personal Goals & Real-Time Context"] --> M2["Secure VM with Host-Side eBPF Sentinel"]
M2 --> M3["Ephemeral Web Browser & Single-Use Stripe Link"]
M3 --> M4["Interactive Live Artifacts on Mobile"]
end
style MetaPhil fill:#0f172a,stroke:#a855f7,stroke-width:2px,color:#ffffff
style M1 fill:#1e1b4b,stroke:#a855f7,stroke-width:1px,color:#ffffff
style M2 fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style M3 fill:#0f382c,stroke:#10b981,stroke-width:1px,color:#ffffff
style M4 fill:#3b1e2b,stroke:#f43f5e,stroke-width:1px,color:#ffffff
Meta designed Muse as a personal superintelligence that lives on your mobile device and operates in the background to handle daily life logistics: monitoring product drops, planning complex family itineraries, booking travel, and negotiating deals. Because it interacts directly with unverified consumer web forms and personal credit instruments, Meta’s architectural obsession is containment against prompt injection and unauthorized financial egress.
flowchart TD
subgraph OAIPhil["2. OpenAI Dots: The Digital Enterprise Coworker"]
direction TB
O1["Delegated Objectives from Slack, Teams, or ChatGPT"] --> O2["Dedicated Sandboxed Cloud Computer"]
O2 --> O3["GPT-6 Astra Execution Core + 4,000+ App Connectors"]
O3 --> O4["Four-Tier Custom Rules Governance"]
end
style OAIPhil fill:#0f172a,stroke:#00e5ff,stroke-width:2px,color:#ffffff
style O1 fill:#1e293b,stroke:#38bdf8,stroke-width:1px,color:#ffffff
style O2 fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style O3 fill:#1e1b4b,stroke:#818cf8,stroke-width:1px,color:#ffffff
style O4 fill:#0f382c,stroke:#10b981,stroke-width:1px,color:#ffffff
OpenAI approached always-on agency from the perspective of knowledge workers. A Dot is given its own virtual computer running in the cloud, loaded with a browser and standard tooling. It is not an assistant waiting for prompts; it is a coworker that participates in team communication channels, performs asynchronous triage, and presents finished deliverables for human approval.
flowchart TD
subgraph GooglePhil["3. Google Gemini Spark: The Ecosystem Native"]
direction TB
G1["Deep Workspace Graph: Gmail, Calendar, Docs, Drive"] --> G2["Persistent Daemons on Google Cloud MicroVMs"]
G2 --> G3["Model Context Protocol (MCP) Tool Mesh"]
G3 --> G4["FIDO Agent Payments Protocol (AP2) Mandates"]
end
style GooglePhil fill:#0f172a,stroke:#10b981,stroke-width:2px,color:#ffffff
style G1 fill:#1e293b,stroke:#38bdf8,stroke-width:1px,color:#ffffff
style G2 fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style G3 fill:#1e1b4b,stroke:#818cf8,stroke-width:1px,color:#ffffff
style G4 fill:#0f382c,stroke:#10b981,stroke-width:1px,color:#ffffff
Google built Gemini Spark around the enterprise data graph where knowledge work already resides: Google Workspace. Instead of forcing users to configure external SaaS connectors, Spark natively taps into company inboxes, shared calendars, and corporate Drive hierarchies. By pioneering the AP2 protocol, Google enabled cryptographically verifiable agent commerce without handing raw credit card tokens to LLMs.
flowchart TD
subgraph PerpPhil["4. Perplexity Computer: The Multi-Model General Contractor"]
direction TB
P1["High-Level Multi-Stage Enterprise Objective"] --> P2["Asynchronous Directed Acyclic Graph (DAG) Engine"]
P2 --> P3["Dynamic Model Router: Claude Opus 5.5, GPT-6, Gemini 4"]
P3 --> P4["Dual Runtime: Ephemeral Cloud MicroVMs or On-Prem Portable Hardware"]
end
style PerpPhil fill:#0f172a,stroke:#38bdf8,stroke-width:2px,color:#ffffff
style P1 fill:#1e293b,stroke:#38bdf8,stroke-width:1px,color:#ffffff
style P2 fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style P3 fill:#1e1b4b,stroke:#818cf8,stroke-width:1px,color:#ffffff
style P4 fill:#0f382c,stroke:#10b981,stroke-width:1px,color:#ffffff
Perplexity realized that no single frontier foundation model is best-in-class at every cognitive discipline. By separating orchestration from inference, Perplexity Computer functions as a general contractor: decomposing requests into DAGs, selecting specialized models for each node, and resolving compliance bottlenecks through dedicated on-premises hardware.
2. Sandbox Runtimes & Isolation Architectures
An always-on agent cannot run arbitrary code or browse the open web on a user’s local machine without posing catastrophic security risks. The four frameworks solve containerization and runtime isolation through distinct virtualization strategies:
Figure 1: Architectural comparison of the four sandbox virtualization topologies: Meta Muse (eBPF Sentinel + Secure VM), OpenAI Dots (isolated microVM + Chromium), Google Gemini Spark (Google Cloud microVMs + Borg), and Perplexity Computer (hybrid Firecracker + on-premise DGX Spark appliance).
1. Meta Muse: Kernel-Level eBPF Taint Tracking
Meta places its execution engine inside an ephemeral Secure VM, monitored from the outside by an independent host daemon called the Sentinel. Rather than trusting the model’s internal prompt adherence, the Sentinel leverages Linux eBPF probes inside the kernel to track data flow across memory buffers. If data originating from an untrusted web page attempts to flow into an outgoing network socket without explicit user confirmation, the eBPF filter immediately terminates the process.
2. OpenAI Dots: Single-Tenant Cloud Desktops
OpenAI provisions a persistent virtual Linux machine for every active Dot. Each sandbox contains a full headless Chromium browser, standard developer shells, and persistent storage volumes. State is maintained across restarts, allowing the agent to resume long-running tasks. However, this persistence creates potential security exposure: if an agent’s memory registers are poisoned by malicious indirect prompt injections, the compromised state persists across subsequent executions until administratively flushed.
3. Google Gemini Spark: Borg and Cloud MicroVMs
Google leverages its massive internal infrastructure, deploying Spark daemons across managed Google Cloud microVMs running on top of hardened Borg containers. Workspace files are never copied into the VM’s file system; instead, the agent queries Google’s internal APIs using fine-grained, short-lived OAuth access tokens governed by enterprise Google Workspace admin policies.
4. Perplexity Computer: The Hybrid Cloud-to-Edge Model
Perplexity adopts a dual-path architecture. In the cloud, it provisions ephemeral Firecracker microVMs that spin up in under 5 milliseconds to execute a DAG node and are destroyed immediately upon task completion. For regulated enterprises (healthcare, defense, financial services) where corporate data cannot leave the building, Perplexity introduced the Portable Computer appliance: pre-configured NVIDIA DGX Spark or RTX AI PC workstations that run the execution runtime entirely on-premises while maintaining encrypted telemetry connections to Perplexity’s cloud orchestrator.
3. Foundation Models: Monolithic Monopolies vs. Dynamic Routing
How does each platform make decisions, and how vulnerable is each architecture to model stagnation?
Figure 2: Foundation model deployment strategies: proprietary monolithic cores (Meta Muse Spark 1.3, OpenAI GPT-6 Astra/Sol, Google Gemini 4 Argon) vs. heterogeneous multi-model DAG dynamic routing in Perplexity Computer (Claude Opus 5.5, GPT-6, Gemini 4, Sonar).
- OpenAI Dots: Bound exclusively to GPT-6 Astra for complex reasoning and the newly discounted GPT-6.1 Sol ($0.10 cached inputs) for high-frequency sub-tasks. OpenAI’s advantage is deep integration between the model and the execution harness, but customers are entirely locked into OpenAI’s model release cycle.
- Meta Muse: Powered by Muse Spark 1.3, a fine-tuned model optimized specifically for multi-modal perception, goal decomposition, and UI interaction. It prioritizes low-latency consumer workflows over multi-file software engineering.
- Google Gemini Spark: Powered by Gemini 4 Argon and Gemini 3.8 Flash. Spark leverages Google’s unmatched 1-million-token output horizon and native audio-visual perception, making it uniquely capable of ingesting hours of recorded Google Meet calls and multi-gigabyte corporate Drive folders in a single pass.
- Perplexity Computer: Rejects single-vendor dependency. Its heuristic router evaluates each DAG execution node across complexity, context length, coding intensity, and cost thresholds. Need deep AST parsing for a 200,000-line codebase? Route to Claude Opus 5.5. Need massive document cross-referencing? Route to Gemini 4 Argon. Need fast fact retrieval? Route to Sonar. Perplexity’s telemetry reveals this dynamic approach reduces end-to-end token costs by 42% while delivering superior execution accuracy compared to any single model.
4. Security, Identity, and Governance: Who Controls the Keys?
When an AI agent is empowered to interact with the world 24/7, identity governance and credential protection become the paramount operational challenges.
flowchart TD
subgraph GovernanceTiers["Identity & Credential Isolation Approaches"]
direction TB
G_Meta["Meta Muse: Surrogate Token Swapping via hatch-authd"]
G_OAI["OpenAI Dots: 4-Tier Custom Rules + Hard Handover Air-Gap"]
G_Google["Gemini Spark: Google Workspace IAM + FIDO AP2 Cryptographic Keys"]
G_Perp["Perplexity: Signed Connector Gateway + Zero Credential Context"]
G_Meta --> G_OAI --> G_Google --> G_Perp
end
style GovernanceTiers fill:#0f172a,stroke:#00e5ff,stroke-width:2px,color:#ffffff
style G_Meta fill:#1e1b4b,stroke:#a855f7,stroke-width:1px,color:#ffffff
style G_OAI fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style G_Google fill:#0f382c,stroke:#10b981,stroke-width:1px,color:#ffffff
style G_Perp fill:#1e293b,stroke:#38bdf8,stroke-width:1px,color:#ffffff
Credential Handling
- Meta Muse (
hatch-authd): Implements surrogate authentication. The model never sees real passwords or session cookies. When Muse needs to authenticate with a merchant or service, a privileged host-side daemon injects an ephemeral token directly into the browser session without exposing it to the model’s context window. - OpenAI Dots: Relies on OAuth grants across 4,000+ app connectors. Secrets are stored in Azure Key Vault instances tied to the user’s tenant. However, passwords and sensitive operations are explicitly designated as “Hard Handover” operations, requiring the user to take control of the session directly.
- Google Gemini Spark: Inherits Google Workspace’s existing enterprise Identity and Access Management (IAM). Spark operates under the exact role-based access controls (RBAC) assigned to the employee, ensuring that an agent assisting an engineer cannot read confidential executive HR files.
- Perplexity Computer: Employs a Signed Connector Gateway. The model outputs abstract API requests (e.g.,
github.create_pull_request(branch, title)), which are signed and executed by an out-of-band proxy. Long-lived enterprise secrets are never injected into prompt context.
5. Financial Autonomy and Real-World Commerce
Can these agents actually spend money on your behalf? The industry has split cleanly into two camps: cryptographic protocol pioneers and conservative human-in-the-loop gating.
flowchart TD
subgraph CommerceFlows["Agent Financial Autonomy Frameworks"]
direction TB
AP2["Google AP2: FIDO Digital Mandates with Hard Spend Caps (Autonomous)"]
StripeLink["Meta Muse: Ephemeral Single-Use Stripe Link Tokens (Autonomous)"]
DotsGate["OpenAI Dots: Hard Handover Air-Gap (Manual User Entry Required)"]
PerpGate["Perplexity: Signed Connector Gateway (Mutations Require Approval)"]
AP2 --> StripeLink --> DotsGate --> PerpGate
end
style CommerceFlows fill:#0f172a,stroke:#00e5ff,stroke-width:2px,color:#ffffff
style AP2 fill:#0f382c,stroke:#10b981,stroke-width:2px,color:#ffffff
style StripeLink fill:#1e1b4b,stroke:#a855f7,stroke-width:2px,color:#ffffff
style DotsGate fill:#3b1e2b,stroke:#ef4444,stroke-width:2px,color:#ffffff
style PerpGate fill:#1e293b,stroke:#38bdf8,stroke-width:2px,color:#ffffff
- Google’s AP2 Revolution: Google solved agent commerce by donating the Agent Payments Protocol (AP2) to the FIDO Alliance. Instead of passing credit cards, users issue cryptographically signed digital mandates with strict policy constraints (e.g., “Authorize up to $150 for flights on United Airlines before Oct 15”). Merchants verify the signature via public-key cryptography, processing the payment with zero risk of card compromise.
- Meta Muse & Stripe Link: Meta partnered with Stripe to issue dynamic, single-use checkout tokens. The user pre-authorizes purchases up to a specific dollar cap, and the Sentinel approves transactions only when itemized receipts match the original user intent.
- OpenAI Dots & Perplexity: Both maintain a conservative posture. OpenAI strictly excludes financial checkout from autonomous execution, routing users to a interactive screen share whenever payment information is requested. Perplexity supports enterprise procurement webhooks, but requires explicit human authorization on every write or purchase action.
6. The Verdict: Choosing the Right Always-On Agent
No single framework dominates all four operational axes. The optimal choice depends directly on your organizational topology:
flowchart TD
subgraph DecisionTree["Framework Selection Matrix"]
direction TB
Start["Define Core Operational Objective"] --> Q1{"What is the primary use case?"}
Q1 -- "Personal Life & Consumer Ops" --> PickMuse["Select Meta Muse: Mobile artifacts, eBPF safety, consumer shopping"]
Q1 -- "Enterprise Collaboration & Knowledge" --> Q2{"Where does your enterprise data live?"}
Q2 -- "Google Workspace Core" --> PickSpark["Select Gemini Spark: Native Drive/Gmail access, AP2 payments"]
Q2 -- "Microsoft 365, Slack, GitHub" --> PickDots["Select OpenAI Dots: 4,000+ connectors, cloud computers, Pro integration"]
Q1 -- "Complex Multi-Stage Engineering & On-Prem" --> PickPerp["Select Perplexity Computer: Multi-model DAG routing, on-prem hardware"]
end
style DecisionTree fill:#0f172a,stroke:#00e5ff,stroke-width:2px,color:#ffffff
style Start fill:#1e293b,stroke:#38bdf8,stroke-width:1px,color:#ffffff
style Q1 fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style Q2 fill:#0d2b45,stroke:#00e5ff,stroke-width:1px,color:#ffffff
style PickMuse fill:#1e1b4b,stroke:#a855f7,stroke-width:2px,color:#ffffff
style PickSpark fill:#0f382c,stroke:#10b981,stroke-width:2px,color:#ffffff
style PickDots fill:#00e5ff,stroke:#ffffff,stroke-width:2px,color:#000000
style PickPerp fill:#1e1b4b,stroke:#38bdf8,stroke-width:2px,color:#ffffff
- Choose Meta Muse if your goal is personal productivity, lifestyle coordination, and autonomous mobile concierge capabilities protected by kernel-level security guarantees.
- Choose OpenAI Dots if your team lives in Slack, Teams, and GitHub, and you want an autonomous digital coworker that can jump on a cloud desktop, investigate test failures, and prepare deliverables for executive review.
- Choose Google Gemini Spark if your enterprise runs on Google Workspace and you require deep compliance boundaries, massive context ingestion across meetings and docs, and standardized autonomous purchasing via AP2.
- Choose Perplexity Computer if your workflows require multi-model cognitive specialization, complex DAG pipelines, and on-premises physical hardware isolation to comply with strict data residency regulations.
7. References & Prior Reading Material
- Introducing Meta Muse: Personal AI Agents, Muse Spark, and Secure VM Architecture
- OpenAI DOTS: Inside the Always-On Agentic Architecture, Bubbly Avatars, and GPT-6 Astra Cloud Sandboxes
- Google Gemini Spark: Always-On Workspace Intelligence, AP2 Protocols, and Cloud VM Isolation
- Perplexity Computer: The Multi-Model Digital Worker, 400+ Connectors, and Portable Sandboxes
- FIDO Alliance — Agent Payments Protocol (AP2) Specification Overview
- LMSYS & SGLang — Quantized KV Caches for Scaled Agentic Serving
