Meta launched Muse on September 8, a personal AI agent powered by its Muse Spark model, rolling out in the United States on iOS, Android and the web at muse.ai. Users can also message it through WhatsApp.
Designed to work toward user-assigned goals in the background, the agent can navigate browsers and fill out online forms. For higher-consequence actions such as sending emails or completing purchases, Meta says the system must pause and ask for explicit user confirmation.
Users maintain control over connected app permissions, with a free tier intended for most needs alongside paid subscription plans.
Meta states that user conversations and virtual machine data are excluded from its advertising systems, and users can opt out of data use for model training.
Behind the interface, Muse runs on a dedicated cloud Linux virtual machine designed to constrain autonomous execution. According to Tarek Sheasha, a software engineer and vice president at Meta Superintelligence Labs, the agent runtime is isolated from credential and security services so that the model never directly views real user credentials. The separate Sentinel system controls network connections and actions through connected services.
Although the virtual machine processes tasks remotely, Meta notes that limited data leaves the environment for model inference and operational telemetry.
Meta acknowledges that Muse will make mistakes and can be attacked through instructions hidden in the data it reads.
While a confidential virtual machine architecture with user-held encryption keys is planned for later in 2026, it is not active at launch. To surface vulnerabilities in the current architecture, Meta opened a public bug bounty offering up to $130,000 for qualifying prompt injection reports affecting one user.
