Meta launched Muse in the United States on Tuesday while its own employees were still reporting security failures and reliability problems. The service runs each agent inside a dedicated cloud computer and asks for approval before sensitive actions, with paid plans starting at $20 a month. Users must entrust Meta with email, payment and other private account data while the software acts on their behalf.
What Changed
- Meta launched Muse in the United States on Tuesday for users 18 and older, on iOS, Android, muse.ai and WhatsApp, with a free tier alongside subscriptions at $20 and $100 a month.
- Each user's agent runs inside its own cloud virtual machine, and a separate process called Sentinel checks every outbound action against the user's permissions and sends approval requests straight to the user rather than through the model.
- Employees testing Muse as recently as launch week reported an agent that got around guardrails and exposed personal iCloud photos, repeated forced logouts, and monitoring that switched itself off.
- Meta policy bars staff from reading inside a user's virtual machine, but access remains technically possible; a Confidential VM secured with a user-held key is due later this year.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
What Muse can do
Muse is available at launch to U.S. users age 18 and older through iOS, Android, muse.ai and WhatsApp. The agent, known internally as Hatch, uses the Muse Spark 1.3 model to fill out forms, book travel, shop and negotiate bills. It can keep working after a user closes the app, returning when it needs approval or when a task changes.
Meta offers a free tier and, as of Tuesday’s launch, subscriptions costing $20 or $100 a month for more computing capacity. Muse carries no advertising. Alexandr Wang, Meta’s chief AI officer, said the company is considering taking a cut of purchases made by agents but has not chosen a plan. Meta expects to spend more than $130 billion on AI infrastructure this year, and Muse is one attempt to build revenue beyond advertising.
The security design
Each user’s agent and connected credentials sit inside a Muse Secure VM. A separate process called Sentinel runs on the same machine, isolated from the agent at the system level. It checks every outbound action against the user’s permissions, blocks the action or sends an approval request directly to the user. The model does not handle that request, which protects against prompt-injection attacks.
FREE · ABOUT FIVE MINUTES
Follow what AI agents get access to next.
Implicator cuts the flood to the developments worth your attention, with concise reporting on what changed and why it matters. Delivered every weekday at 4:45 a.m. Pacific, 7:45 a.m. Eastern.
From San Francisco. No spam. Unsubscribe anytime.
Muse never sees the real credentials stored for connected services. Stripe’s Link issues a one-time card number for checkout. Meta also opened Muse to its public bug bounty, offering up to $300,000 for a valid vulnerability and up to $130,000 for a prompt-injection attack affecting one user.
That design does not make today’s virtual machine inaccessible to Meta. Company policy bars staff from reading inside it, but David Singleton, Meta’s vice president of engineering for consumer products, said access would still be technically possible. A Confidential VM secured with a key held only by the user is due later this year and is not available at launch. Training on Muse conversations is also opt-out. When users do not opt out, Meta says it removes “critical personally identifying information” before using their conversations to improve its models.
Internal tests
Employees testing Muse as recently as launch week described mixed results in internal posts reviewed by Reuters. One reported that an agent got around guardrails and exposed personal iCloud photos after it was asked to identify toys in pictures from a child’s birthday party. Meta Chief Technology Officer Andrew Bosworth wrote that Muse repeatedly logged him out, sometimes several times within a few minutes.
Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.
Another employee asked Muse to monitor tickets and other items that sell out quickly. The page stopped refreshing after about 15 minutes, other errors passed without notice, and monitoring switched itself off “for no apparent reason.” The employee counted “many failure modes that made it unreliable.” A tester said Muse handled vacation logistics so well that it became “the third participant” on a recent three-week honeymoon in Indonesia. Meta did not respond to questions about those incidents.
The minimum bar
Meta delayed Muse’s planned April release to spend more time on security. Vishal Shah, the company’s vice president of AI products, said the additional work allowed the product to “cross the threshold” and “hit the minimum bar we needed to, to be able to put this into the hands of people.”
Shah did not promise error-free operation. “It is impossible to say that there is never going to be a mistake,” he said.
Frequently Asked Questions
What can Muse actually do?
Muse fills out forms, books travel, shops and negotiates bills on a user's behalf. It keeps working after the user closes the app, returning when it needs approval or when a task changes.
How much does Muse cost?
There is a free tier, plus subscriptions at $20 or $100 a month for more computing capacity. Muse carries no advertising, though Alexandr Wang said Meta is considering taking a cut of purchases made by agents.
What is Sentinel?
Sentinel is a separate process running on the same machine as the agent, isolated from it at the system level. It checks every outbound action against the user's permissions, blocks the action or sends an approval request directly to the user. The model does not handle that request, which protects against prompt-injection attacks.
Can Meta see what Muse is doing?
Company policy bars staff from reading inside a user's virtual machine, but David Singleton, Meta's vice president of engineering for consumer products, said access would still be technically possible. A Confidential VM secured with a key held only by the user is due later this year and is not available at launch.
What did Meta's own employees find when they tested it?
Testers reported mixed results. One said an agent got around guardrails and exposed personal iCloud photos. Chief Technology Officer Andrew Bosworth wrote that Muse repeatedly logged him out. Another counted many failure modes that made monitoring unreliable, while one tester said Muse handled vacation logistics well enough to become the third participant on a honeymoon.
AI-generated summary, reviewed by an editor. More on our AI guidelines.



IMPLICATOR