Meta announced Tuesday the launch of Muse, a personal AI assistant that users can message to handle digital tasks like booking travel, sending emails, or selling a car on their behalf, all within a secure cloud setup. The company says the agent was designed with security and privacy features from the ground up, a deliberate effort to address trust concerns that have dogged Meta for years. Muse is available now for iOS and Android through a standalone app and the website Muse.ai, and users can also interact with it via WhatsApp, with support for Meta's AI glasses coming soon.
The product is Meta's latest move to compete with viral AI agents like OpenClaw and Instinct, emerging from Meta Superintelligence Labs, the AI division CEO Mark Zuckerberg created about a year ago to close the gap with OpenAI and Anthropic. The agent operates using what Meta calls Secure VM, an architecture that isolates each person's activity in a virtual machine to keep untrusted web data and third-party integrations separate from the part of the agent that can actually act on someone's behalf. Muse can handle purchases through Stripe's Link payment tool, which issues single-use card numbers so agents don't enter real financial information across the web, and Meta says Muse is the first AI agent covered by Link's no-fee return guarantees for agents. The company is also offering Muse to the public bug bounty program with payouts up to $300,000 for valid security flaws, including up to $130,000 for successful prompt injection attacks affecting a single user.
Meta says people can use Muse for free out of the box with no learning curve, prompting the agent in natural language to complete tasks autonomously, though users who want to automate many digital tasks will need one of the company's AI subscription plans. The company has built a system called Sentinel that monitors everything leaving the virtual machine, either matching it to an existing policy where the user or system has granted permission or presenting a human-in-the-loop prompt to ask for approval before taking action, according to David Singleton, Meta Superintelligence Lab's vice president of engineering for consumer products. Singleton notes these check-in prompts go directly to the user and aren't filtered through the model, protecting against prompt injection attacks, though he acknowledges that while Meta is barred by policy from accessing user Muse data, it would still be technically possible under Secure VM, and users can opt out of having their data used for training.
Meta will eventually offer Muse "Confidential VM," designed so each virtual machine runs in a trusted execution environment where users manage their own access keys locally on their devices, meaning no one else, including Meta, can access that user's agent VM. This architecture comes from Meta's work with Moxie Marlinspike, creator of the end-to-end encrypted messaging app Signal and the privacy-focused AI platform Confer. In addition to letting users control their access keys, Meta is giving select security firms access to the Confidential VM source code to regularly audit and verify its privacy guarantees, and the company will publish the Confidential VM binaries and a transparency log so users can verify the validity and integrity of their connection to Muse. Singleton emphasizes that Muse Secure VM has already been extensively tested by Meta's human and agentic red teams and through the company's private bug bounty before joining the public program. The company's bet is that isolating user activity in virtual machines and eventually handing over access control to users themselves will convince people to trust Meta with the deep integration an AI agent requires to be useful. The challenge for Meta is whether privacy architecture alone can overcome years of user skepticism about how the company handles personal information.

