Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Meta launches Muse personal AI agent for background tasks

Meta is rolling out Muse in the US, where the agent can browse and handle transactions. The company says permission gates, isolated cloud computing and user controls are designed to limit security and privacy risks.

D
Sep 10, 2026 · 3 min read

Meta introduced Muse on September 8 and began rolling out the personal AI agent in the US. Meta says Muse can use a browser and keep working through multi-step tasks after its app closes. It is rolling out through a dedicated iOS and Android app and at muse.ai, and people can also communicate with it through WhatsApp. Support for Meta AI glasses is planned but is not part of the launch.

Muse goes beyond answering prompts to acting on a user’s behalf, extending Meta’s broader consumer AI assistant push. Meta says the agent can open websites, fill in forms, negotiate and return with progress updates or requests for approval. That access requires users to entrust an autonomous system with account activity, personal data and purchases. The security, privacy and performance protections described for those actions are Meta’s claims and have not been independently validated in the sources reviewed for this article.

Meta says each user receives a dedicated cloud virtual machine, or VM, that separates the agent’s working environment from security-sensitive services, credentials and lasting application data. According to the company’s technical account of Muse’s safeguards, limited information still leaves the VM for model inference and telemetry. The launch system does not technically prevent Meta from accessing VM data when needed to support, secure or operate the service, though Meta says personnel access is restricted by operational policies.

Meta says a separate host-side system called Sentinel controls connector actions and network access. It applies user-defined permissions and can stop Muse to request approval. Permissions can cover one action, a session, a task, a fixed period or ongoing access. Read-only, previously allowed or actions Meta classifies as low risk may proceed without a new prompt.

Meta also says authentication material is held outside the agent runtime. Muse receives substitute tokens rather than real credentials, while credentials entered in a browser are injected without being shown to the agent. Users can inspect an activity log and approved permissions. Meta’s design overview says they can also read and edit the memory files Muse uses to personalize its work.

Even with those controls, some user activity enters Meta’s model-development pipeline. Meta says sanitized conversation and tool-use trajectories are used for training by default after key personally identifiable information is removed. Users can turn that use off in Muse settings. The company says Muse conversations and VM data are not shared with its advertising systems, but acknowledges that browsing, reservations or Marketplace activity performed through Muse may indirectly affect the ads a person sees.

For purchases, Stripe says US consumers can connect its Link wallet to Muse. According to Stripe, users must approve the total for each purchase. At merchants that do not accept Link, the payment service creates a single-use virtual card limited to the approved transaction.

Meta acknowledges that Muse can make mistakes and is not immune to attacks, including prompt injection, in which hostile instructions embedded in content try to redirect an agent. No independent security audit, penetration-test report or real-world incident data was available in the reviewed material. Meta also has not specified how quickly the US rollout will reach eligible users, the account or age requirements, subscription prices, free-tier limits, or the volume and retention of inference and telemetry data that leaves the VM.

Meta says most use will be free and heavier use will require a subscription. The company plans to introduce a Confidential VM later in 2026 that it says will cryptographically prevent Meta from accessing the environment. That system is currently limited to trusted testers and external-auditor review, whose scope and findings Meta has not disclosed.

More news