Press "Enter" to skip to content

Meta Launches Muse AI Agent Despite Reported Glitches

Meta has launched Muse, a personal AI agent designed to work autonomously on users’ behalf, pairing the agent with a dedicated virtual machine and a separate security agent intended to control what it can do.

Muse can send emails, book travel, fill out forms, make purchases and negotiate on a user’s behalf, according to the company’s blog post. For longer-running assignments, the agent can continue working after a user closes the app and return when circumstances change or it needs approval.

The company described Muse as a first step toward what it calls “personal superintelligence” – AI systems that do not merely answer questions but can remember users’ preferences, pursue longer-term goals and take actions for them.

The agent is powered by Muse Spark, which Meta calls its most capable model to date for real-world agentic work. Users can interact with Muse through a dedicated app or directly through WhatsApp.

Unlike a conventional chatbot that waits for individual prompts, Muse can take a broader goal, develop a personalized plan and coordinate the user’s time and resources while continuing to advance the work on its own. It also maintains memory about the user, allowing it to make suggestions without being prompted and act on information provided in earlier conversations.

Giving an AI system that degree of autonomy also creates new security risks, particularly when an agent has access to email, passwords, payment information and websites. Meta built what it calls Muse Secure VM, a dedicated cloud-based virtual machine that houses both the agent and a user’s data and credentials.

A separate Sentinel agent runs on the same machine but is isolated from Muse at the system level. Meta said nothing Muse does can reach the internet unless Sentinel approves it, and users must approve sensitive actions such as sending an email or making a purchase. Credentials are stored separately so Muse can use them without seeing the underlying passwords or payment information.

Users can choose which services Muse can access and set permissions for each one. Meta also provides an audit trail showing what the agent has done and plans to do. The company said Muse conversations and data stored in its virtual machine are not shared with Meta’s advertising systems, and users can opt out of having their interactions used to train Meta’s AI models.

The safeguards are significant because autonomous agents have proved difficult to secure. Reuters reported that during testing, Meta researchers identified scenarios in which Muse could expose private information or be manipulated into taking unintended actions, highlighting the challenge of giving AI systems access to sensitive data while allowing them to operate independently.

Meta said it plans to add Muse Confidential VM later this year, encrypting the entire virtual machine – including users’ data and conversations – with a key held only by the user so that even Meta cannot access it.

Muse also incorporates commerce infrastructure from Stripe. Its Link wallet can generate a one-time-use payment card so the agent does not see a user’s actual card details, and Muse is the first AI agent covered by Link’s purchase protections. Support for Shop Pay and 1Password is planned.

Muse is rolling out in the U.S. on iOS, Android and the web and is expected to come to AI glasses. Meta said most usage will be free, with subscription plans for heavier users.

×