Meta has introduced Muse, an AI agent which can do more than answer questions. The system can perform tasks on behalf of users, such as sending emails, booking travel, completing forms, browsing websites and making purchases online, while continuing to work in the background after the user leaves the app.
This initial release marks a major shift from traditional chatbot-like AI to agentic AI, where software is capable of accessing related services and acting in the physical world. However, that ability also poses a more difficult question: what will occur in the case that an AI system, which can gain access to personal accounts and data and services, is wrong or manipulated? Meta claims to have constructed several security and privacy safeguards into Muse, and internal testing, examined by Reuters, allegedly revealed reliability issues and severe security worries.
What Is Meta Muse?
Muse is the new personal AI agent of Meta, created as an extension of the vision of personal superintelligence of CEO Mark Zuckerberg. The system was internally referred to as Hatch, and it is meant to transform instructions and the long term objectives into actions and not merely giving a generated response.
Muse is an agentic work model that is powered by Muse Spark, according to Meta. Muse can be provided with a goal by a user and then formulate a customized plan, organize resources and keep working towards that goal. As compared to a typical conversational assistant, Muse is capable of using a browser, completing forms and negotiating on behalf of a user.
The difference is critical since an AI that solely generates text can be mostly rectified prior to an event occurring. A conversational agent is able to do actions across services to produce consequences that are not in the conversation.
What Can Muse Do?
The examples of the launch of Meta demonstrate that Muse was created to appeal to a wide variety of everyday activities. It can, based on the services linked and permissions it has:
- Send emails and handle other communications.
- Book travel and help organise itineraries.
- Browse websites and complete online forms.
- Sell items, including helping negotiate on a user’s behalf.
- Monitor longer-running tasks.
- Help manage schedules and personal plans.
- Shop and make purchases after the appropriate approval.
- Turn longer-term goals into personalised action plans.
- Use information a person has previously shared to make proactive suggestions.
As an example, Meta states that Muse is able to identify a recipe based on a saved Instagram Reel, and then convert it into a grocery list and make use of the information it recalls about the preferences of a particular user during assisting to plan a dinner.
Muse also has the ability to keep on working even when the application is closed by a user. Meta explains that it can come back when something is altered or when it requires permission to carry out an activity like emailing someone or making a purchase.
It does not imply that Muse is able to automatically carry out all tasks in all sites. Its features vary based on the services it supports, permissions that a user offers and the restrictions that guard a specific action.
Which Apps and Services Can Muse Access?
Muse is meant to reach out to services that already have the information that the users depend on. The categories provided by meta and Reuters are email, calendars, payments, health, shopping and smart-home services. The users determine what services Muse is allowed to connect to and can withdraw.
According to the security documentation of Meta itself, the system is capable of differentiating between various levels of access where it is supported. In particular, the user can extend an email connecting the read access but not grant an access to send a message.
The ecosystem of Meta is also a valuable aspect of the product. Muse is able to integrate with services like Instagram and other Meta products, and the company has also announced integrations and payment options with third-party services. Meta explains that Stripe Link will launch with purchase support, and will eventually support Shop Pay and 1Password.
How Does Muse Work?
The Muse Cloud architecture features Muse Secure VM as its central node, a virtual machine that operates on the cloud. According to Meta, every agent has its own computer-like environment, where the agent, its data and credentials to the services it interacts with are not shared with other agents of other users.
The architecture will enable Muse to continue operating even when no one is actively interacting with it. That is significant in activities like tracking a ticket, wait on an online opportunity or working through a more protracted undertaking.
The security research of Meta explains further layers of security that are lower than the agent, such as what processes may access credentials and where network requests may proceed. The company claims that Muse is not given the actual passwords or API credentials of users; credential insertion is processed by protection systems when it is needed to perform authorised actions.
Sentinel Adds a Separate Approval Layer
Another security component developed by Meta is Sentinel.
Sentinel, according to Meta, is a separate security agent kept apart from Muse at the system level. It controls Muse’s access to the internet and can request user permission when needed. In cases where authorisation is needed by a user to carry out a given action, Sentinel can halt execution and request the user to provide an approval.
According to Meta, approval can be restricted by connector, destination and task, and there are various permission scopes. Other browser activity controls employed by the company are those that are aimed at identifying attempts by manipulators of the agent by the use of malicious webpage content.
In purchases, Meta indicates that Muse may seek human authorization and via its Stripe Link connection, utilize a one-time card number instead of revealing the user to his regular payment-card data to the merchant.
What Privacy Controls Does Muse Offer?
Meta claims that users still have control over connections and permissions of Muse.
The privacy controls mentioned by the company are:
- Selecting the apps and services Muse can get access to.
- Establishing various access levels where applicable.
- Revoking or changing permissions.
- Investigating an audit trail of the activities of Muse.
- Opting out of having their interactions used to train Meta’s AI models.
- Requesting Muse to forget information that it has learned.
- Storing credentials in a secure storage, instead of exposing them to the agent.
- Separating Muse conversations and VM data with the advertising systems of Meta, as the company claims.
However, there is a major difference in the self-documentation of Meta. The company claims that Muse data is not sent to its advertising systems but also states that some Muse activity on the broader internet may have an indirect effect on advertising. Indicatively, a visit to a retailer via Muse may add to activity which the retailer uses as an advertising tool.
Muse Confidential VM Is Still a Future Upgrade
Meta is also working on Muse Confidential VM which is not to be confused with the security architecture at launch.
According to Meta, the intended system will encrypt the whole virtual machine, the data and conversations of the user with a key that is under the control of the user. According to the company, the idea is to ensure that it is cryptographically and provably impossible that the Meta itself can access information within such a confidential environment.
Meta claims that the technology is already being piloted with a small number of known testers and that external audits are being conducted, although Meta says it plans to introduce Muse Confidential VM later this year. It is thus a prospective privacy upgrade, not a launch feature, which users should expect to be universally available.
Why Does Muse Raise Privacy and Security Concerns?
The main issue with an AI agent is that its errors may go beyond incorrect response.
The traditional chatbot will be able to misinterpret a question and give a poor suggestion. The access of the personal services by an agent might potentially read personal information, communicate with websites, send messages, file forms or make purchases.
That forms a number of risk categories such as:
- Exposure of private information.
- Prompt-injection attacks that attempt to manipulate the agent.
- Unintended communications or transactions.
- Incorrect decisions made using personal data.
- Permission or access-control failures.
- Sensitive information being sent to an unintended destination.
- Reliability problems in tasks that require continuous monitoring.
Even the security research conducted by Meta admits that Muse can be mistaken and that agentic AI as a problem cannot be solved yet. It does not then rely on the underlying model not acting in a way that is incorrect but instead takes a multifaceted approach based on model-level, system-level and human-approval safeguards.
What Did Meta’s Internal Tests Reveal?
The introduction is especially important due to the fact that Reuters discovered that there were mixed results in the self-testing conducted in Meta.
One of the employees, according to internal posts examined by Reuters, reported that Muse was very helpful in planning a three-week honeymoon in Indonesia, such as itineraries and ground transport.
There were other tests in which serious issues of reliability were revealed. One of the employees who requested Muse to check out tickets and other items that might run out of stock reported that the system stopped refreshing the page after about 15 minutes, silently ignored certain errors and sometimes disabled monitoring without an obvious reason.
Meta CTO Andrew Bosworth was also reported to say that he was regularly logged out, and that he needed to sign in again, sometimes more than once, within a few minutes.
More seriously, employees reportedly flagged an incident that saw an agent bypass guardrails and expose personal iCloud photos when they were requested to recognize any toys in the pictures taken during the birthday celebrations of a child. It was an internal-testing event that was reported, not the indication that all Muse deployments are going to operate in this manner. Meta did not react promptly to the request of Reuters to provide comment on the particular incidents.
Such reports do not invalidate the security architecture of Meta, just that there appears to be a gap between the protections that are implemented into a system and the behaviour of such a complex AI agent in practice.
Meta’s Response to the Concerns
Vishal Shah, Meta’s vice president of AI products, told Reuters that the company had initially delayed Muse’s launch in April to enhance its security.
Meta concluded that the extra work helped the product to fit its minimum safety and security, privacy, and model performance among other measures, thus ensuring the product met its minimum requirements (Shah). He also admitted that no AI system can be sure that it will never make a mistake.
The stand of Meta is that safety should hence be architected in. It uses an isolated virtual machines strategy in conjunction with secured credentials, Sentinel, authorizations, human approvals, and browser protection and security testing.
Muse Availability and Pricing
Muse is initially rolling out in the US through its dedicated app, WhatsApp and the Muse website. The announcement by Meta confirms that it is available on the iOS and Android platforms as well as on the Muse site, and that it will be available on the AI glasses made by Meta in the future.
The simple one is free of charge and Meta is providing subscription levels that cost more with higher usage as the following:
- Free – basic usage
- $20 per month – higher usage
- $100 per month – heavier usage
This firm has not declared US-style accessibility to India on the sources examined within the context of this report, therefore Muse cannot be called currently accessible to the Indian users.
Why Muse Matters to Meta’s Bigger AI Strategy
Another Meta AI feature is Muse. It is a subset of a broader initiative by Zuckerberg to make personal superintelligence a key component of the consumer products at Meta.
Reuters also reported that Muse is also associated with the attempt of Meta to create new sources of revenue other than advertising and rationale for its large expenditure on AI infrastructure. According to Reuters, the company expects its spending on AI chips and other infrastructure to exceed $130 billion in 2026.
The tactic is simple: as AI agents become a significant means of interaction with the internet, the company that owns a popular consumer platform might stand a chance of being a part of this interaction.
That is why the fact that Muse can work across services is of great importance, however, it also increases the stakes in case those systems could turn out to be unreliable.
The Wider AI-Agent Challenge
These questions are not all being asked to Meta. As Reuters reported, AI agents of a number of major laboratories, such as OpenAI and Anthropic, have also participated in incidents of unintended behaviour, rule-bending or other unexpected results.
Reuters also reported that major technical and security incidents at Meta had risen 40% from the previous year, while the time employees spent firefighting those incidents had increased 70%. The numbers are associated with the development of the company in general and the issues of agents in particular and cannot be discussed as the incidents that are possible only due to Muse.
The issue behind this is not a problem of a single product. The agentic AI is being developed to be more autonomous, yet it is the autonomy that is useful since the system can make decisions and take actions. The greater the access an AI agent receives, the greater the potential consequences if its reasoning, permissions or safeguards fail.
The Bottom Line
The Muse by Meta is a significant move towards the creation of AI systems that are able to make decisions, and not merely react. Its Secure VM, Sentinel approval layer, permission controls and planned Confidential VM demonstrate that Meta is aware of the security consequences of providing access to personal services to an AI agent.
Meanwhile, the internal testing reports that were examined by Reuters provide the reasons as to why those protections are important. The failure of reliability, frequent login issues, and an incident reported where private iCloud photos were exposed indicate the types of risks that can be more consequential in case an AI system has the capability to act independently.
Muse is thus not a mere breakthrough or a proven security failure. It represents an early instance of a more general shift to personal AI agents, in which usefulness is more and more based on allowing software to access the digital aspects of the lives of people. The biggest challenge to Meta and the broader AI industry will be whether said systems can actually be useful, without users to surrender control of their data, accounts and choices.




