Key Notes
- Meta launched Muse, a personal AI agent that can browse, fill out forms, shop, negotiate and manage tasks on a user's behalf, running on Muse Spark 1.3 inside a dedicated per-user "Muse Secure VM".
- The core security design: a separate "Sentinel" agent, isolated at the system level, approves every network request and connector action before Muse can reach the internet.
- Meta says Muse doesn't share conversations or VM data with its ad systems and won't train on interactions unless a user opts in, with a fully user-encrypted "Confidential VM" option coming later this year that Meta says even it can't access.
- .
Meta launched Muse, a personal AI agent designed to take real-world action on a user’s behalf rather than only answer questions. Built on Muse Spark 1.3, Meta’s latest AI model, Muse can open a browser, fill out forms, book travel, send emails and negotiate purchases once given a goal, continuing to work after a person closes the app and returning when it needs approval or something changes. It’s rolling out for free to most US users on iOS, Android, the Muse app and directly inside WhatsApp, with support for Meta’s AI glasses to follow; subscription plans are available for heavier use.
The product’s central pitch is architectural trust. Each user gets Muse Secure VM, a dedicated, isolated virtual machine in the cloud that houses the agent, a person’s data, and any credentials for connected services, walled off so no other user’s agent can reach it. Running on that same machine but kept separate at the system level is Sentinel, a distinct oversight agent that must approve every outbound network request and connector action before Muse can act; if no existing policy covers a request, Sentinel prompts the user directly for permission.
According to a more technical account from Meta researchers, the agent itself never sees real credentials, only placeholder tokens, with Sentinel injecting actual secrets at the network boundary, and the browser component reads pages through an accessibility tree rather than raw code, without the ability to execute JavaScript, protections aimed specifically at making prompt-injection attacks structurally harder to exploit.
For payments, Muse checks out through Link, a wallet built by Stripe, generating one-time-use virtual cards so a person’s real card details stay hidden; it is the first AI agent covered by Link’s purchase protections, including coverage for damaged or lost items, price-drop refunds and no-fee returns. Support for Shop Pay and 1Password logins is coming soon.
Muse also builds a persistent memory of what matters to a person, letting it act on details mentioned only once, such as turning a saved recipe into a grocery list, though users can tell it to forget specific things it has learned, revoke app access at any time, and opt out of having their interactions used to train Meta’s models.
What Meta Is Asking Users to Trust
Meta states plainly that Muse does not share a person’s conversations or the data in their VM with Meta’s advertising systems, a specific and consequential claim given that advertising is the source of nearly all of Meta’s revenue. Later this year, the company plans to introduce a Confidential VM option, encrypting an entire virtual machine, including all data and conversations, with a key only the user holds, which Meta says would make the contents inaccessible even to Meta itself; the company says it is incorporating outside auditor feedback and will make the system continuously inspectable once launched.
These are, at this stage, Meta’s own claims about its own architecture, not yet independently audited. That distinction matters because Muse asks for an unusually high degree of trust, handling email, calendars, payment authority and smart-home or shopping accounts, at a company with a well-documented privacy history: a 2019 Federal Trade Commission settlement that was then a record $5 billion over privacy violations, a 2023 FTC finding that Meta had violated that same order, a 2011 FTC settlement over exposed private information, the Cambridge Analytica scandal, and an $18 billion multistate settlement reached with 29 states just last month over social media harms to consumers.
None of that history means Muse’s specific technical safeguards are inadequate, but it is the backdrop against which Meta is asking people to hand a Meta-built agent real-world authority over their money and personal accounts, and it is likely to shape how much of the public is willing to adopt the product regardless of how sound the underlying architecture proves to be.
Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.