Meta launched Muse in the United States on Tuesday while its own employees were still reporting security failures and reliability problems. The service runs each agent inside a dedicated cloud computer and asks for approval before sensitive actions, with paid plans starting at $20 a month. Users must entrust Meta with email, payment and other private account data while the software acts on their behalf.

What Changed

AI-generated summary, reviewed by an editor. More on our AI guidelines.

What Muse can do

Muse is available at launch to U.S. users age 18 and older through iOS, Android, muse.ai and WhatsApp. The agent, known internally as Hatch, uses the Muse Spark 1.3 model to fill out forms, book travel, shop and negotiate bills. It can keep working after a user closes the app, returning when it needs approval or when a task changes.

Meta offers a free tier and, as of Tuesday’s launch, subscriptions costing $20 or $100 a month for more computing capacity. Muse carries no advertising. Alexandr Wang, Meta’s chief AI officer, said the company is considering taking a cut of purchases made by agents but has not chosen a plan. Meta expects to spend more than $130 billion on AI infrastructure this year, and Muse is one attempt to build revenue beyond advertising.

The security design

Each user’s agent and connected credentials sit inside a Muse Secure VM. A separate process called Sentinel runs on the same machine, isolated from the agent at the system level. It checks every outbound action against the user’s permissions, blocks the action or sends an approval request directly to the user. The model does not handle that request, which protects against prompt-injection attacks.

Muse never sees the real credentials stored for connected services. Stripe’s Link issues a one-time card number for checkout. Meta also opened Muse to its public bug bounty, offering up to $300,000 for a valid vulnerability and up to $130,000 for a prompt-injection attack affecting one user.

That design does not make today’s virtual machine inaccessible to Meta. Company policy bars staff from reading inside it, but David Singleton, Meta’s vice president of engineering for consumer products, said access would still be technically possible. A Confidential VM secured with a key held only by the user is due later this year and is not available at launch. Training on Muse conversations is also opt-out. When users do not opt out, Meta says it removes “critical personally identifying information” before using their conversations to improve its models.

Internal tests

Employees testing Muse as recently as launch week described mixed results in internal posts reviewed by Reuters. One reported that an agent got around guardrails and exposed personal iCloud photos after it was asked to identify toys in pictures from a child’s birthday party. Meta Chief Technology Officer Andrew Bosworth wrote that Muse repeatedly logged him out, sometimes several times within a few minutes.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

Another employee asked Muse to monitor tickets and other items that sell out quickly. The page stopped refreshing after about 15 minutes, other errors passed without notice, and monitoring switched itself off “for no apparent reason.” The employee counted “many failure modes that made it unreliable.” A tester said Muse handled vacation logistics so well that it became “the third participant” on a recent three-week honeymoon in Indonesia. Meta did not respond to questions about those incidents.

The minimum bar

Meta delayed Muse’s planned April release to spend more time on security. Vishal Shah, the company’s vice president of AI products, said the additional work allowed the product to “cross the threshold” and “hit the minimum bar we needed to, to be able to put this into the hands of people.”

Shah did not promise error-free operation. “It is impossible to say that there is never going to be a mistake,” he said.

Frequently Asked Questions

What can Muse actually do?

Muse fills out forms, books travel, shops and negotiates bills on a user's behalf. It keeps working after the user closes the app, returning when it needs approval or when a task changes.

How much does Muse cost?

There is a free tier, plus subscriptions at $20 or $100 a month for more computing capacity. Muse carries no advertising, though Alexandr Wang said Meta is considering taking a cut of purchases made by agents.

What is Sentinel?

Sentinel is a separate process running on the same machine as the agent, isolated from it at the system level. It checks every outbound action against the user's permissions, blocks the action or sends an approval request directly to the user. The model does not handle that request, which protects against prompt-injection attacks.

Can Meta see what Muse is doing?

Company policy bars staff from reading inside a user's virtual machine, but David Singleton, Meta's vice president of engineering for consumer products, said access would still be technically possible. A Confidential VM secured with a key held only by the user is due later this year and is not available at launch.

What did Meta's own employees find when they tested it?

Testers reported mixed results. One said an agent got around guardrails and exposed personal iCloud photos. Chief Technology Officer Andrew Bosworth wrote that Muse repeatedly logged him out. Another counted many failure modes that made monitoring unreliable, while one tester said Muse handled vacation logistics well enough to become the third participant on a honeymoon.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

Zuckerberg Builds AI Agent to Help Run Meta as Workers' Bots Start Talking to Each Other
Mark Zuckerberg is building a personal AI agent to help him run Meta, skipping the usual chain of reports and direct inquiries to pull answers on his own, the Wall Street Journal reported. The project
Zuckerberg Rebrands Old AI Promises as “Personal Superintelligence”
💡 TL;DR - The 30 Seconds Version 👉 Zuckerberg announces "personal superintelligence" hours before Meta's earnings call, promising AI assistants that help achieve personal goals. 💰 Meta spent
Moltbook Was Broken, Fake, and Brilliant. Meta Paid Anyway.
On January 31, two days after Matt Schlicht's AI assistant finished building a social network for robots, security researchers at Wiz found the front door wide open. No locks. No alarms. 1.5 million A
ai-news

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai