Meta bets on AI agent Muse to catch up in AI race
Unlike standard chatbots, Muse can operate browsers and third-party apps independently, using a Secure VM and Stripe integration to handle transactions.
Meta has launched Muse, a personal AI agent capable of autonomously negotiating bills, booking travel, and making purchases. The rollout follows less than two weeks after the company agreed to an $18 billion multistate settlement regarding social media consumer harms, creating a sharp tension between the high level of autonomy the agent requires and Meta's documented trust deficit.
Unlike traditional AI chatbots that retrieve information or draft text, Muse is designed for "agentic" AI. This means it can take direct action: opening a web browser, filling out forms, and operating third-party applications independently. For lengthy projects, Meta says Muse continues to work in the background after a user closes the app, requesting human approval only for specific triggers, such as finalizing a financial transaction.
Related video and Instagram post



The 'Agentic' Shift: Beyond the Chatbot
The release of Muse represents a transition from generative AI that answers questions to AI that manages workflows. According to Pbs, while chatbots retrieve information, agents execute jobs like a computer program but use large language models to complete tasks without step-by-step instructions. For example, rather than just drafting an email, the agent can theoretically handle the entire process of receiving a message and firing off a response on its own.
Meta's Muse Spark model allows the agent to handle diverse requests, from turning recipe reels into grocery lists to creating yearlong exercise plans or setting up a new business. If a requested service has a public API, Muse can connect using provided credentials; otherwise, it interacts with the service via a browser.
The service is currently available in the U.S. For users aged 18 and over via iOS, Android, and muse.ai, with integration into WhatsApp and upcoming support for Meta's AI glasses.
The Security Stack: Secure VM and Sentinel
Because an agent requires access to passwords and payment methods, Meta employs a system called Secure VM. Wired describes this as a virtual machine in the cloud that isolates each user's activity, preventing untrusted web data from interacting with the part of the agent that takes action. Meta states that Muse has no visibility into passwords or payment methods.
A second AI agent, dubbed "Sentinel," acts as a virtual traffic cop. Tarek Sheasha, vice president of Superintelligence Labs, stated that Sentinel ensures no interaction with the outside world occurs without approval and that the primary agent cannot override these restrictions. David Singleton, Meta Superintelligence Lab's vice president of engineering for consumer products, noted that these check-in prompts come directly to the user and are not filtered through the model to protect against prompt injections.
To mitigate financial risk, Meta integrated Stripe's Link. This infrastructure issues a single-use card number for checkouts, ensuring the AI never enters a user's real financial information into a website. Meta claims Muse is the first agent covered by Link's purchase protections, which include no-fee returns.
| Plan Tier | Monthly Cost | Primary Feature/Limit |
|---|---|---|
| Free | $0 | Up to 100 million tokens per week |
| Power | $20 | Increased task automation capacity |
| Maximum | $100 | Highest usage tier for complex tasks |
The Trust Gap and Privacy History
Meta's push for "superintelligence" faces a hurdle in its history of privacy failures. Techcrunch notes that the company settled with the FTC over deceiving consumers about private information in 2011 and faced a record $5 billion penalty in 2019 for privacy violations. In 2023, the FTC charged Meta with violating a privacy order filed after the 2019 settlement.
Technical lapses have further complicated this trust. In 2019, Meta discovered a number of users' passwords were stored in readable formats. The company also dealt with the Cambridge Analytica scandal, where data from millions of consumers was collected by a third party without consent. Recent AI-specific missteps reported by The Verge include a "Discover" feature that leaked other users' prompts and a support chatbot that facilitated the hacking of over 20,000 Instagram accounts.
Meta is attempting to address these concerns by allowing users to opt out of having their interactions used for model training and permitting them to instruct Muse to forget
specific learned details.
Roadmap to Confidential VM
Under the current Secure VM, Meta is barred by policy from accessing user data, but David Singleton admitted it would still be technically possible. To solve this, Meta is developing "Confidential VM" in collaboration with Moxie Marlinspike, the creator of Signal.
This upcoming architecture will run in a "trusted execution environment" where users manage their own access keys locally on their devices. This design intends to ensure that neither Meta nor any other entity can access the agent's VM. To verify these privacy guarantees, Meta intends to allow select security firms to audit the source code and will publish binaries and a transparency log to verify the integrity of the connection.
Frequently Asked Questions
How does Muse differ from a standard chatbot?
While a chatbot answers questions or drafts content, Muse is an agent that takes autonomous action, such as filling out forms, sending emails, and making purchases.
Is my financial information safe when Muse makes a purchase?
Meta uses Stripe's Link to issue single-use card numbers, meaning the agent does not use or expose the user's real credit card details during checkout.
Can Meta see the data inside the AI agent?
Under the current Secure VM, Meta is barred by policy from accessing data, though it remains technically possible. The upcoming Confidential VM aims to prevent this entirely via user-controlled access keys.
Archypedia is dedicated to independent, evidence-backed reporting. This briefing was synthesized from primary source reporting, corroborated across independent newsrooms, and verified against our Editorial Standards.
Transparency record
Evidence behind this report
This report synthesizes 6 distinct sources. Open the source ledger below to compare the underlying coverage.
Prepared under the Archypedia Editorial Policy by the Niko Vale editorial desk profile. AI-assisted tools may support drafting and verification; public accountability remains with Archypedia. Report an error.