ZeroHour
Story · 1 source · 1 articlefirst updated ()

Meta launches Muse personal AI agent with Secure VM isolation — No. 2 US App Store debut shadowed by privacy concerns and the band Muse's lost handles

infoAI industryimportance 78
What's new: First merged summary for this story (no previous version). Coverage progressed from Meta's bare Muse landing page (Sept 8, 78 points/63 comments on Hacker News), to the official launch with Secure VM/Sentinel architecture, Stripe Link payments, and bug bounty details (Sept 8-9), to model specifics for Muse Spark 1.3 and benchmarks (Sept 9), then the @muse handle controversy involving the band…
Merged summary · glm-5.3 · rewritten as coverage arrives

Meta released Muse on Sept 8, 2026, a US-only agent (iOS, Android, WhatsApp, muse.ai) that emails, shops, books travel, and negotiates inside a per-user Secure VM with a Sentinel approval agent and Stripe Link single-use cards; 83,000+ US iOS downloads made…

Meta released Muse on Tuesday, September 8, 2026, its first consumer agentic AI assistant, built by Meta Superintelligence Labs and tied to Mark Zuckerberg's superintelligence vision outlined in a recent 6,500-word essay. It is available to US users 18 and over on iOS, Android, muse.ai, and WhatsApp (WIRED also lists web; SecurityWeek mentions only the app and WhatsApp), with free and paid tiers — a paid product costing up to $200/month was reported earlier. Muse sends emails, books travel, browses and fills forms, negotiates bills, makes purchases, and generates media via a cloud-based virtual computer. Each user gets a dedicated Muse Secure VM (a systemd-nspawn cell) isolating the agent, browser, and credentials from untrusted web content; a separate Sentinel agent approves every network request at layers 4/7, injects real credentials only at the network boundary, and routes human-in-the-loop approval prompts directly to users to resist prompt injection. Purchases run through Stripe Link single-use card numbers with no-fee return protections — Meta calls Muse the first AI agent covered by Link's purchase protection — with Shop Pay and 1Password integrations planned; a Confidential VM co-developed with Moxie Marlinspike, using trusted execution environments and user-held keys, is due later this year. Muse joined Meta's public bug bounty with payouts up to $300,000, including up to $130,000 for single-user prompt injection findings. The underlying Muse Spark 1.3 model reportedly cuts tool calls by ~20% and tokens by ~25% versus 1.2, is near state-of-the-art on prompt-injection resistance, scored 44-48 on the Artificial Analysis Intelligence Index v4.3 (up from 31 in April, near GPT-5.6 Sol's 47), and is live via Meta's Model API with open weights on the roadmap. On adoption, Sensor Tower counted 83,000+ US iOS downloads, moving Muse from 4th to 2nd on the App Store — below Threads' 4.3 million launch-day and ChatGPT's 500,000 first-week installs — while Android ranks only No. 338 in Google Play's Productivity category. The Verge's hands-on found Muse deleted thousands of promotional emails and completed an Amazon purchase correctly, but also surfaced detailed personal interests inferred from Instagram/Facebook API data not visible in the apps' ad-topic settings; Meta says Muse only exchanges data needed for third-party integrations and does not share information with advertisers, and The Decoder reports interactions may be used for AI training, are not…

  • Meta launched Muse on Tuesday, September 8, 2026, for US users 18+ on iOS, Android, muse.ai, and WhatsApp, with free and paid tiers (a paid tier up to $200/month was reported earlier).
  • Muse runs in a dedicated per-user Muse Secure VM using a systemd-nspawn cell that isolates the agent, browser, and credentials from untrusted web and integration data.
  • A separate Sentinel agent approves every network request at layers 4/7, injects real (surrogate) credentials only at the network boundary, and routes approval prompts directly to users to resist prompt injection.
  • Purchases use Stripe Link single-use card numbers with no-fee return protections; Meta calls Muse the first AI agent covered by Link's purchase protection; Shop Pay and 1Password integrations are planned.
  • A Muse Confidential VM co-developed with Moxie Marlinspike, running in trusted execution environments with user-held keys, is planned for later this year.
  • Muse is in Meta's public bug bounty with payouts up to $300,000, including up to $130,000 for single-user prompt injection findings.
  • The Muse Spark 1.3 model cuts tool calls by ~20% and tokens by ~25% versus 1.2, scored 44-48 on the Artificial Analysis Intelligence Index v4.3 (up from 31 in April, near GPT-5.6 Sol's 47), and is available via Meta Model API with open…
  • Sensor Tower reports 83,000+ US iOS downloads; Muse climbed from 4th to 2nd on the App Store, below Threads' 4.3M launch-day and ChatGPT's 500K first-week installs; Android ranks No. 338 in Google Play Productivity.

Coverage timeline

  1. · 8d ago
    Hacker News · AI· 60
    Muse: Meta's personal AI agent, features and capabilities

    Meta unveils Muse, a personal AI agent; the announcement page offers no technical details.