In short
Meta has launched Muse, a personal AI agent that can automate digital tasks through an app, the web and WhatsApp. The company is leaning on security, privacy and payment safeguards to persuade users to trust a product category that depends on broad access to personal data.
- Meta launched Muse as a personal AI agent for web, app and WhatsApp use.
- The company is centering the product on Secure VM and future Confidential VM privacy features.
- Muse can handle tasks like email, travel, shopping and payments with Stripe-backed protections.
- Meta is offering the service free at first, with heavier use tied to paid AI plans.
- The company is expanding bug bounties to reward prompt-injection and other security findings.
Meta has launched Muse, a new personal AI agent that can be messaged to handle digital tasks in the cloud, marking the company’s latest push to catch up with rivals in the fast-moving AI agent race. The rollout matters because Meta is pitching Muse as useful out of the box while also trying to answer the biggest concern around agentic AI: whether users can trust it with sensitive data and everyday decisions.
The service is available starting Tuesday through a standalone iOS and Android app, the Muse.ai website and, for some interactions, WhatsApp. Meta says support for its AI glasses is also coming soon. Users can try Muse for free, but heavier use will require one of Meta’s paid AI subscription plans.
Muse is designed to let people send natural-language requests and have the system carry out actions on their behalf, including sending emails, planning travel, helping sell a car and making purchases. Meta is positioning the product not merely as another chatbot, but as an agent that can work through tasks autonomously while keeping user data isolated in a security architecture the company says was built in from the start.
What is Muse and why is Meta launching it now?
Muse is Meta’s new consumer AI agent, built to take instructions from users and complete tasks inside a secure cloud environment. Meta is releasing it now because the company believes AI agents are moving from novelty to mainstream utility, and it wants a stronger foothold in a category that has already attracted attention from products such as OpenClaw and Instinct.
For Meta, the release is also a strategic statement. CEO Mark Zuckerberg created Meta Superintelligence Labs roughly a year ago to accelerate the company’s AI effort and close the gap with OpenAI and Anthropic. Muse is one of the first public products to emerge from that unit, which has drawn headlines for aggressively recruiting researchers with lucrative compensation packages.
According to Meta, the product was built to avoid the steep learning curve often associated with agent tools. The company says the goal is to let ordinary users type what they want in plain language and let Muse handle the rest.
Meta says the system is meant to work without much setup, with the company describing it as a product designed so users should not have to learn a complicated workflow before getting value from it.
How does Muse work?
Muse works by allowing users to ask it to complete tasks in natural language, after which the agent carries out those actions across supported apps and websites. Meta says the product can send emails, book trips and manage other digital errands on the user’s behalf.
Unlike a conventional chatbot that mainly generates text, Muse is meant to act. That distinction is central to the company’s pitch: instead of simply advising users, it can initiate steps in external services and finish jobs with limited hand-holding.
What kinds of tasks can Muse perform?
Muse can manage a range of everyday digital chores, including:
- drafting and sending emails
- arranging travel plans
- helping list or sell items such as a car
- making online purchases
- browsing the web and working with third-party apps
Meta has not framed Muse as a fully autonomous replacement for a human assistant. Instead, the company says it built specific checkpoints into the product to prevent actions that go beyond what a user has allowed.
Why is privacy the centerpiece of the launch?
Privacy is the centerpiece of Muse because agentic AI cannot be broadly adopted unless users feel comfortable granting it access to emails, travel details, payment information and third-party accounts. Meta, in particular, has a long history that makes trust a difficult hurdle, so the company is leaning hard on security architecture to separate Muse from older perceptions of its data practices.
The company says it has engineered Muse with privacy and security “built in” rather than added later. That claim is important not only for users, but for Meta’s broader effort to set a standard in how personal agents should be designed.
Internally, Meta has been testing the product under the codename Hatch, and employees reportedly used it to browse the web and operate other applications on their behalf. That experimentation appears to have informed the public release strategy, which emphasizes both convenience and control.
What is Secure VM?
Secure VM is Meta’s default privacy architecture for Muse, and it is meant to isolate each user’s activity inside a virtual machine. The idea is to keep untrusted web data and connected services separate from the part of the agent that is actually allowed to take actions.
Meta says this arrangement helps reduce the risk that malicious content or compromised websites could manipulate the agent into doing something unauthorized. In practice, the system creates a separation layer between information Muse encounters and the permissions it uses to act.
That matters because AI agents are especially vulnerable to prompt injection, a class of attack in which hidden instructions on a webpage or in a document try to trick the system into disobeying the user. Meta says it has designed Muse to defend against that threat by keeping approval checks outside the model itself.
David Singleton, Meta Superintelligence Lab’s vice president of engineering for consumer products, said the company built a monitoring layer that watches what is leaving the virtual machine and either compares it with allowed policies or asks the user to confirm the step.
Singleton also said the human approval prompts are delivered directly to the user rather than being processed through the model, which Meta says helps reduce the risk that a malicious prompt could override the safeguard.
How does Meta handle payments and purchases?
Meta says Muse can make purchases using payment infrastructure from Stripe, which issues a single-use card number for transactions made by agents. That design is intended to protect users from exposing their real card details across websites and services.
Stripe calls the tool Link, and Meta says Muse is the first AI agent covered by Link’s purchase protections for agentic commerce. Those protections include no-fee returns, giving the system a commerce layer that is meant to be safer than simply letting an agent store and re-enter a user’s payment credentials.
This is one of the most significant parts of the launch because it suggests Meta wants Muse to evolve beyond information handling and into the mechanics of actual consumer transactions. If users are willing to let an AI agent buy things on their behalf, payment security becomes as important as model quality.
| Feature | What Meta says it does | Why it matters |
|---|---|---|
| Muse app and web access | Lets users message the agent through iOS, Android and the web | Makes the product widely accessible at launch |
| WhatsApp integration | Allows users to interact with Muse inside WhatsApp | Places the agent inside a major everyday communication platform |
| Secure VM | Separates user activity and action-taking inside a virtual machine | Reduces the risk of unauthorized actions and prompt injection |
| Stripe Link payment system | Uses single-use card numbers for purchases made by the agent | Limits exposure of real payment information |
| Confidential VM | Future version where users control local access keys | Could prevent even Meta from accessing the agent environment |
What makes Confidential VM different?
Confidential VM is Meta’s planned next step, and it is designed to go further than Secure VM by putting control of access keys in the hands of users. In this future model, each virtual machine would run inside a trusted execution environment, and the user would manage the keys locally on their own device.
If implemented as described, that architecture would prevent Meta, or any other party without the keys, from accessing the contents of a user’s Muse environment. The company says this is meant to provide a stronger privacy guarantee than the default Secure VM setup.
Meta is developing that system with help from Moxie Marlinspike, best known as the creator of Signal and a longtime advocate for secure communications. Marlinspike has also worked on Confer, a privacy-focused AI platform, and his involvement signals that Meta wants outside credibility for a feature likely to be scrutinized by security researchers and privacy advocates.
WIRED viewed an advance draft of a technical paper describing the Confidential VM design. The proposal includes measures such as publishing binaries, maintaining a transparency log and allowing selected security companies to audit source materials to verify that the privacy claims hold up in practice.
Why Meta is emphasizing trust and verification
Meta is emphasizing trust and verification because a personal AI agent only succeeds if users are willing to hand it meaningful access. That means access to communications, shopping, travel bookings and possibly internal business tasks. Without confidence that the system will not leak data or act on the wrong instruction, the product loses its utility.
The company also seems aware that trust cannot be built through promises alone. Its pitch includes technical isolation, human approval checkpoints, outside audits and transparency logs. Together, those measures are meant to show that Muse is not just another voice interface, but a system with security controls designed around realistic attack scenarios.
Still, Meta’s own comments reveal a limitation: while the company says policy prevents it from accessing Muse data, it could technically do so. Users are able to opt out of having their data used for training, but the distinction between policy and possibility is likely to draw careful scrutiny.
What does Meta still control?
Meta still operates the service, manages the infrastructure and sets the policy framework, which means it remains an intermediary even if it cannot casually view user data under normal rules. That reality may not be enough for privacy purists, especially given the sensitivity of agentic access.
For that reason, the company is trying to make its future Confidential VM model as verifiable as possible. Publishing machine-readable binaries and transparency logs would let users or third parties check whether the system they are using matches the system Meta claims to be running.
How has Muse been tested and secured so far?
Muse has already gone through multiple layers of internal and external security review, according to Meta. The company says it used both human and agentic red teams to probe the system, along with a private bug bounty program before expanding the product into public release.
Now Meta is extending Muse into its public bounty program as well. The company says it will pay as much as $300,000 for qualifying vulnerabilities, including up to $130,000 for successful prompt injection attacks that affect a single user.
Those figures show how seriously the company is treating the security of the launch. In the AI sector, bug bounty size often reflects not just the perceived value of a product, but the potential impact if an attacker can steer an agent into exposing data or taking a harmful action.
Security review timeline
Meta’s rollout can be understood in phases:
- Internal testing under the Hatch codename
- Human and agentic red-team review
- Private bug bounty validation
- Public rollout of Muse across app, web and messaging surfaces
- Expansion of the public bounty program to include agent-specific exploits
How does Muse fit into the broader AI agent race?
Muse fits into the broader AI agent race as Meta’s bid to become a serious player in a category that could reshape how people use the internet. AI agents promise a future in which users delegate entire tasks rather than manually moving through websites and apps step by step.
That vision is what makes the category so strategically important. If agents become the default interface for scheduling, shopping, emailing and browsing, the company that supplies the most trusted agent may become a critical gateway to digital life.
Meta is not first to the market, and the company appears to know that. Its answer is differentiation through privacy, payments and integration with the company’s existing ecosystem, including WhatsApp and, eventually, its AI glasses.
In that sense, Muse is both a product launch and a platform play. If Meta can make the agent feel safe enough to use, it could connect personal AI directly to services people already use every day.
What are the main advantages and risks?
Muse’s biggest advantage is convenience. Users may be able to hand off repetitive digital chores and get results with fewer steps than conventional apps require. Its biggest risk is trust: the more power the agent has, the more damage a bug, prompt injection or account compromise could cause.
That tradeoff explains why Meta has made privacy and verification such a prominent part of the launch. It also explains why the company is offering human confirmation prompts for certain actions and why it is stressing that users can opt out of training data use.
Potential user benefits
- Less time spent on repetitive online tasks
- Natural-language control instead of multi-step app navigation
- Secure purchasing through single-use payment credentials
- Cross-device availability through mobile, web and messaging
Potential user concerns
- Whether Meta can truly isolate user data
- Risk of prompt injection or malicious web content
- How much autonomy users will comfortably allow
- Whether paid plans will make the most useful features inaccessible to casual users
What happens next?
What happens next is likely to depend on adoption, security performance and whether users find the privacy pitch convincing. Meta will need to show that Muse can be useful without becoming intrusive, and secure without becoming cumbersome.
If the rollout goes well, Meta could use Muse as a bridge between its social products, its AI glasses and a future where personal agents play a central role in everyday computing. If it goes poorly, the company may find that the trust gap around personal AI is harder to close than the technical one.
For now, Muse represents a clear signal of where Meta thinks consumer AI is heading: toward agents that do work, not just chat about it. The company is betting that if it can make that future feel safe, users will be willing to hand over the keys.
| Launch element | Current status | Strategic significance |
|---|---|---|
| Standalone Muse app | Available now | Creates a dedicated entry point for the agent |
| Muse.ai website | Available now | Expands access beyond mobile devices |
| WhatsApp access | Available now | Places Muse inside a mainstream messaging product |
| AI glasses support | Coming soon | Extends the agent into wearable computing |
| Confidential VM | Planned future release | Could become a stronger privacy benchmark for the industry |
Frequently asked questions
What is Meta Muse?
Meta Muse is Meta’s new personal AI agent that users can message to automate digital tasks. It can help with emails, travel bookings, web browsing and purchases, and Meta is offering it through a dedicated app, the web and WhatsApp.
How does Muse protect user privacy?
Muse uses a Secure VM architecture that isolates user activity in a virtual machine and adds human approval checkpoints for sensitive actions. Meta also says a future Confidential VM will give users local control of access keys so even Meta cannot access the environment.
Can Muse make purchases online?
Yes. Muse can complete purchases using Stripe’s Link payment infrastructure, which issues a single-use card number instead of exposing a user’s real payment details. Meta says the system is covered by purchase protections designed for AI agents.
Is Muse free to use?
Muse is available to try for free, but users who want to automate a large number of tasks will need one of Meta’s AI subscription plans. Meta has not said that all advanced features will remain free permanently.
Why is Meta launching a personal AI agent now?
Meta is launching Muse now because it wants a stronger position in the emerging AI agent market, where products can act on behalf of users instead of just answering questions. The company sees agents as a major shift in how people will use the internet and its own products.









