Meta Launches Muse, a Personal AI Agent With Isolated Security Architecture — Followed by Privacy Criticism, a Handle Dispute, and a Training-Data Lawsuit
Meta launched Muse, a US-only personal AI agent for users 18+ on iOS, Android, muse.ai, and WhatsApp, built around a per-user Secure VM, a Sentinel approval agent, and Stripe Link one-time cards; it drew 83,000+ iOS downloads but criticism over inferred…
Meta launched Muse on Tuesday, September 8, 2026 — its first consumer agentic AI assistant, built by Meta Superintelligence Labs and available initially in the US to users 18 and over on iOS, Android, the muse.ai app, and WhatsApp, with free and paid tiers (a paid product costing up to $200/month was reported earlier). The agent automates long-horizon tasks including email, travel booking, form-filling, purchases, and price negotiation, and Meta ties the launch to Mark Zuckerberg's superintelligence vision outlined in a 6,500-word essay. Muse's security architecture centers on a dedicated per-user Secure VM in which the agent runs in a systemd-nspawn cell, isolating untrusted web and integration data from the action layer; a separate Sentinel agent is the sole approver of network egress and connector actions at layers 4/7, injects real credentials only at the network boundary, and routes human-in-the-loop approval prompts directly to users to resist prompt injection. Purchases run through Stripe Link one-time card numbers with no-fee return protections — which Meta calls the first AI agent covered by Link's purchase protection — with Shop Pay and 1Password integrations planned, and a Confidential VM with user-held keys co-developed with Moxie Marlinspike is planned later this year, as are open weights for the underlying Muse Spark 1.3 model (which Meta says cuts tool calls by ~20% and tokens by ~25% versus 1.2 and is near state-of-the-art on prompt-injection resistance). Meta added Muse to its public bug bounty with payouts up to $300,000, including up to $130,000 for single-user prompt injection findings. Adoption and criticism followed quickly: Sensor Tower counted 83,000+ US iOS downloads, moving Muse from 4th to 2nd on the App Store (below Threads' 4.3 million launch-day downloads and ChatGPT's 500,000 first-week installs), while the Android app ranked only No. 338 in Productivity on Google Play. The Verge's hands-on found the agent works — deleting thousands of emails and completing an Amazon purchase — but surfaced detailed inferred interests from Instagram and Facebook API data beyond what users see in ad-topic settings; Meta says Muse only exchanges data needed for third-party integrations and does not share information with advertisers, though interactions can be used for AI training and are deletable on request. Separately, the English rock band Muse (trademark 1999) lost the @muse Instagram and X handles to the agent, moving to @museband around…
- Muse launched Tuesday (Sept 8, 2026) for US users 18+, on iOS, Android, the muse.ai app, and WhatsApp, days after Meta's $18 billion multistate settlement over social media consumer harms.
- Each user gets a dedicated Muse Secure VM; the agent runs in a systemd-nspawn cell that isolates untrusted web and integration data from the action-taking component.
- A separate Sentinel agent is the sole approver of network egress and connector actions at layer 4/7, injects real credentials only at the network boundary, and routes human-in-the-loop approval prompts directly to users; surrogate…
- Payments use Stripe Link single-use card numbers with no-fee return protections — Meta calls Muse the first AI agent covered by Link's purchase protection; Shop Pay and 1Password integrations are planned.
- Muse was added to Meta's public bug bounty with payouts up to $300,000, including up to $130,000 for single-user prompt injection findings.
- The underlying Muse Spark 1.3 model cuts tool calls by ~20% and tokens by ~25% versus 1.2 per Meta, is available via the Meta Model API with open weights on the roadmap, and reportedly scored 44-48 on Artificial Analysis Intelligence Index…
- A Muse Confidential VM running in trusted execution environments with user-held keys, co-developed with Moxie Marlinspike, is planned later this year.
- Privacy policy per Meta: interactions can be used for AI training but are not shared with Meta's ad systems and can be deleted on request; users control per-app access scopes and can revoke them anytime.
Coverage timelineoldest first · each row is one article
- · 8d agoMeta Releases Muse, a Personal AI Agent With Privacy ‘Built Into It’
WIRED · Security· 75
Meta launched Muse, a personal AI agent on iOS, Android, WhatsApp, and web, with VM-isolated execution and prompt-injection protections.