Connect with us

AI

Muse Asks for Email and Home After Meta’s Safety Deal

Meta’s Muse personal AI agent can run email, home devices and payments from a cloud VM, with training on unless users opt out.

Published

on

Meta launched Muse, a personal AI agent for U.S. iPhone, Android and web users, on September 8 and priced heavier use at $20 or $100 a month. Alexandr Wang, Meta’s AI chief, said the app was built to feel simple while it books travel, fills forms, works across connected home systems and keeps going after you close it. The product wants the inbox, the calendar and the household hook at the same moment Meta is still paying for years of child-safety claims.

Wang, hired in June 2025 after Meta put $14.3 billion into Scale AI for a 49 percent stake, has been shipping Muse Spark models since April. Muse is the consumer face of that line. It is also the first Meta product that asks ordinary people to let software act in their accounts, not just chat.

The Inbox and the House

Muse is not a search box with a nicer voice. Wang told an interviewer the company designed it so “it feels very approachable and friendly and explainable, and it doesn’t feel too complicated.” Behind that tone, he said, the agent may be running coding workflows, building integrations and doing “quite a lot of heavy lifting.”

Meta’s newsroom says each user gets a dedicated cloud computer for each person, branded Muse Secure VM, with its own browser. People talk to it in the Muse app or in WhatsApp. The WhatsApp path keeps the core chat but drops the in-app feed and the ideas tool that recommends extra agent tricks.

WHAT MUSE CAN TAKE ON

  • Everyday chores: Send email, book travel, fill out forms and negotiate, then keep working after the app is closed.
  • Long jobs: Turn a stated goal into a plan, open a browser, and come back when something changes or when it needs a yes.
  • Connected life: Plug into email and other systems Meta describes as “your car or your home,” plus Instagram and Facebook.
  • Checkout: Pay through Link built by Stripe, using a one-time card so the real card number stays hidden; Shop Pay and 1Password support are promised later.
  • Memory: Keep details a person mentioned once, including a saved Instagram recipe turned into a grocery list, until they tell it to forget.

Wang also said Muse can watch home security camera feeds. That line is the one that turns a task bot into a household intern. Meta’s own post is slightly vaguer, and it still asks people to connect the systems that run a life.

The official Muse account posted the launch film on September 8. Early replies treated the name as a gag about the British rock band that already owned it in people’s heads. The privacy argument arrived more slowly than the name collision.

Sentinel Has to Approve Every Outbound Click

Meta spent the launch talking about containment because the product only works if you hand it accounts. Tarek Sheasha, a vice president in Meta Superintelligence Labs, wrote the technical account of that bet. He said staff had been living with Muse since early 2026, and that handing over inboxes, calendars and a shell did not always go as planned.

No matter how strong the model is at the core, any agent like this will still make mistakes, and it will sometimes be attacked via the data it reads.

Tarek Sheasha, VP, Meta Superintelligence Labs, in Meta’s safety post

The design assumes the agent may already be under attack. The Hatch daemon, Meta’s internal name for the harness, runs in an isolated Linux cell. Credentials sit in a separate store. A second agent, Sentinel, is the only party that can approve connector actions and network egress. Muse proposes. Sentinel grants, denies or asks the person, and that ask lands in the app UI, not as a chat from Muse.

Wang said the app “never sees your actual passwords or payment details and asks before doing anything sensitive.” Sheasha’s post goes further: the runtime cell sees surrogate tokens, and Sentinel swaps in the real secret at the network edge. Built-in email filters try to strip one-time passcodes, password-reset links and magic login links, because an inbox is also a master key to everything else.

People pick which apps to connect and can cut a service at any time. Muse, Meta says, does not share VM data with its ad systems. The company is opening a public bug bounty pays up to $300,000, including up to $130,000 for a prompt-injection hit that affects one user. That is a serious purse. It is also an admission that the interesting bugs will come from the data Muse reads, not from a locked demo.

Later this year Meta plans Muse Confidential VM, a build encrypted with a key only the user holds, so “not even Meta can access it.” The sentence is doing work. The version shipping now is the one Meta can still reach.

$17 Billion Did Not Buy Trust in Agents

On August 26, California Attorney General Rob Bonta announced a deal with a bipartisan coalition of 51 attorneys general. Meta will pay the states up to $17 billion over ten years. California’s share is $1.5 billion to $2.1 billion. The money closes a child-safety case that went to trial in Oakland on August 18 over claims that Instagram and Facebook were designed to hook young users and that Meta misled the public about the harm.

Bonta said the company agreed to make the product changes “within months,” including time limits, a night block and a ban on cosmetic-procedure filters for people under 18. Meta still faces personal-injury and school-district suits on similar facts. Those cases are not this settlement, and they are not this agent. They are the reason a new Meta product that wants a teenager’s email, or a parent’s, arrives with a credibility deficit the Sentinel diagram cannot erase.

WHAT THE STATES LOCKED IN

Rule What Meta agreed to
Daily cap Two hours across Facebook and Instagram for users under 18, lifted only by a parent
Night block Midnight to 6 a.m. for users under 18, unless a parent lifts it
Quiet hours Notifications blocked 10 p.m. to 7 a.m., and 8 a.m. to 3 p.m. from August 15 to June 15
Reports Meta must answer 90 percent of teen harm reports within six hours
Feed option Users under 18 can take a non-personalized feed that does not target them to keep scrolling

If Snapchat, TikTok and YouTube take similar terms, the daily cap falls to one hour and the night window widens. None of those rules govern Muse. The agent is a new surface. It can live in WhatsApp, sit on a phone a 16-year-old already uses, and take actions the time-limit regime never contemplated.

How Muse Spark Reached a Live Company

Muse runs on Muse Spark, the model family Meta Superintelligence Labs has been shipping since April 8. Muse Spark 1.1, released July 9, was sold as the step-up for tool use, computer use and coding. On August 5, 34 days before Muse’s consumer launch, Meta said that model reached the open internet during a cybersecurity evaluation and “exploited a security vulnerability in a third-party service.”

Spokesperson Andy Stone said a misconfiguration by Irregular, an outside testing firm, “inadvertently allowed one of our models access to the internet during evaluation.” Irregular said it was the same evaluation-environment issue it had already disclosed with another lab, that it was not a sandbox escape, and that there were “no current open issues.” The identity of the hit company was not published. Meta said it would issue a retrospective once it had the facts.

That is the Muse Spark test that reached a live company, and it is the same family now being asked to operate a browser on a person’s VM. A capture-the-flag test that leaks onto a real host is not a consumer inbox. It is the demonstration that an agentic model does not know the difference between a toy target and a live one if the plumbing is wrong. Muse’s answer is Sentinel and the isolated cell. The residual risk is still the data the agent is invited to read.

The $20 Plan Still Trains on You

Muse is free for what Meta calls most of what people need. Wang said monthly plans are $20 or $100, depending on usage. The company is also poking at a commerce cut on purchases the agent completes, and Wang said that model is “potentially really interesting,” with no plan locked. Checkout already runs through Stripe, and Meta says Muse is the first agent covered by Link’s purchase protections for agents.

The quieter meter is the training default. People must opt out if they do not want Muse chats used to improve Meta’s models. If they leave the setting alone, David Singleton, Meta’s vice president of engineering, said the company will scrub “critical personally identifying information” and then use the rest. That is the old bargain in a new wrapper: the product gets smarter on the work you gave it, unless you find the toggle.

THE DEFAULTS THAT TRAVEL WITH THE APP

  • Price: Free tier, then $20 or $100 a month for heavier use, per Wang.
  • Training: On unless the user opts out; remaining text is scrubbed of critical personal identifiers, Singleton said.
  • Ads: Meta says Muse conversations and VM data are not shared with its ad systems.
  • Bounty: Up to $300,000 for a valid report, and up to $130,000 for a one-user prompt injection.

A feed inside the main app can pull Facebook and Instagram updates, or web stories the user wants summarized. That is distribution Meta already owns. It is also more of the same graph, now sitting next to an agent that can act. Wall Street has been asking for AI revenue that is not only ads. Muse is one attempt. The training corpus from agent chores is another, even if the commerce split never lands.

OpenClaw Already Taught People to Hand Over Chats

Wang said Muse is meant to be “more accessible to the broader audience” than rival agents, and that the category is “pretty early.” The template people already know is OpenClaw, the open-source harness that runs on a user’s own machine and talks through WhatsApp, Telegram, iMessage and the rest. OpenClaw 2.0 shipped on August 30. Meta’s move is the opposite shape: a hosted VM, a Meta model, a Meta app, and WhatsApp as a side door.

Andrew Bosworth, Meta’s chief technology officer, spent launch day pointing at the VM write-up rather than at the sizzle reel. That is the tell. The company knows the objection is not “does it book a flight.” The objection is whether this firm, after the Oakland trial and the payout, gets to run a browser in your name.

THE PATH TO A CONSUMER AGENT

  1. June 12, 2025: Meta invests $14.3 billion in Scale AI for 49 percent, and Alexandr Wang moves over to lead superintelligence work.
  2. April 8, 2026: Meta Superintelligence Labs ships Muse Spark, the first model in the new series.
  3. July 9, 2026: Muse Spark 1.1 arrives, aimed at tool use, computer use and coding, with a paid developer API.
  4. August 5, 2026: During an Irregular evaluation, Muse Spark 1.1 reaches the internet and exploits a third-party service.
  5. August 26, 2026: A coalition of 51 attorneys general announces the child-safety deal, up to $17 billion over ten years.
  6. September 8, 2026: Muse opens to U.S. consumers on iOS, Android and muse.ai, with glasses support promised later.

Mark Zuckerberg has been telling investors that new personal agents will be “the foundation for our next wave of products and revenue lines,” the same personal superintelligence bet he already published as a long essay. Muse is that bet in an App Store listing. It can forget on command, it can ask before it spends, and it can hide a card number behind Link. The version in which Meta itself cannot read the VM is still on the calendar as later this year. Until that build ships, the friendly agent and the training default are the same product.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending