{"slug": "meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it", "title": "Meta Releases Muse, a Personal AI Agent With Privacy ‘Built Into It’", "summary": "Meta released Muse, a personal AI agent available Tuesday for iOS, Android, web, and WhatsApp, designed to automate tasks like sending emails, booking travel, and making purchases with privacy 'built into it' via a Secure VM architecture. The agent, developed by Meta Superintelligence Labs, is free to try but requires an AI subscription for heavy use, and is the first AI agent covered by Stripe's Link purchase protections.", "body_md": "Meta announced Tuesday the release of Muse, a personal [AI agent](https://www.wired.com/tag/agentic-ai/) that people can message to automate digital tasks in a secure cloud environment, all while relying on security and privacy that the company says is “built into it” from the start.\n\nMeta says Muse is rolling out today for iOS and Android users in a dedicated Muse app, as well as the website Muse.ai. The company also says users can directly message Muse in WhatsApp to interact with the agent. Meta says users of [its AI glasses](https://www.wired.com/story/meta-smart-glasses-face-recognition-nametag-connections/) will soon be able to interact with its Muse agent as well. Meta says people can try out Muse for free, but users who want to automate lots of digital tasks will need one of the company’s [AI subscription plans.](https://techcrunch.com/2026/05/27/meta-officially-launches-instagram-facebook-and-whatsapp-subscriptions-with-more-to-come-including-ai-plans/)\n\nMuse is Meta’s latest attempt to compete with viral AI agents such as [OpenClaw](https://www.wired.com/story/i-gave-my-openclaw-agent-physical-body-robot/) and [Instinct](https://www.wsj.com/tech/ai/the-latest-viral-ai-assistant-rocketing-across-silicon-valley-abb46276), which users can message with to automate digital tasks. Muse is a product of [Meta Superintelligence Labs](https://www.wired.com/story/mark-zuckerberg-welcomes-superintelligence-team/), the AI unit CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic, offering some researchers [eye-popping compensation packages](https://www.wired.com/story/mark-zuckerberg-meta-offer-top-ai-talent-300-million/) to join. The unit was built on the belief that AI agents will transform how everyday users navigate the internet, as well as Meta’s products.\n\nWIRED previously reported that Meta has been testing Muse internally under the codename “[Hatch](https://www.wired.com/story/meta-pushes-its-new-ai-agent-on-employees-but-eases-off-on-tokenmaxxing/),” and that employees have been using it to autonomously operate third-party applications and browse the web on their behalf.\n\nMeta claims in a [blog post](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/) that anyone can use Muse out of the box, and that the product was designed “so there’s no learning curve.” The company says users can prompt Muse in natural language, and the agent will work on its own to send emails, book travel, or even help sell a car on a user’s behalf.\n\nMuse is also capable of making purchases on behalf of users, checking out using special payment infrastructure designed by Stripe. The payment tool, which Stripe calls Link, issues a single-use card number so that agents aren’t going around entering a person’s real financial information across the internet. Meta says Muse is the first AI agent covered by Link’s purchase protections for agents, which guarantees no-fee returns.\n\nMeta is late to release a personal agent, but it seems to be seeking to differentiate itself by [focusing](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse) on security and privacy features for Muse. The agent is debuting with an architecture for all users dubbed Secure VM, which is meant to isolate each user’s activity in a so-called virtual machine to keep untrusted data from the web and any integrations separate from the part of the agent that can actually take action on a user’s behalf.\n\nA personal AI agent requires a lot of user trust, something Meta in particular has [struggled](https://www.wired.com/story/meta-failed-to-catch-hundreds-of-ai-child-abuse-ads-some-included-images-of-real-kids/) with [significantly](https://www.wired.com/story/meta-will-pay-up-to-dollar167-billion-to-settle-its-social-media-harms-case-and-thats-just-for-starters/) over the [years](https://www.wired.com/story/facebook-security-breach-third-party-sites/). To get users to try out Muse—and allow the agent to be integrated with users’ third-party apps and services—Meta is attempting to convince people that they can trust the company to handle their data appropriately.\n\n“We know it’s really important, if we’re going to build a product like this that can access a lot of sources of personal data, that we’re really responsible with that, so we’ve designed this system very deliberately,” says David Singleton, Meta Superintelligence Lab’s vice president of engineering for consumer products. “And we’ve built what we call the Sentinel that actually looks out for everything that’s moving out of the VM and either matches it to an existing policy where the user or the system has given permission for that to happen or presents a human-in-the-loop dialog to ask you to approve the action it’s going to take.”\n\nSingleton notes that these check-in prompts for humans come directly to the user and aren’t filtered through the model, to protect against attacks like prompt injections.\n\nWhile Secure VM is built to maintain user security and privacy, it is not a truly locked box. Singleton notes that while Meta is barred by policy from accessing user Muse data, it would still be technically possible. Users can opt out of allowing their data to be used for training.\n\nThe architecture of Secure VM is noteworthy from a privacy standpoint, if only as a way to set a new industry standard for AI agents. Eventually, Meta will also offer Muse “Confidential VM,” designed so each VM runs in a “trusted execution environment” and users manage their own access keys locally on their devices. This way no one else, including Meta, can access that user’s agent VM.\n\nConfidential VM comes as part of [Meta’s work with Moxie Marlinspike](https://www.wired.com/story/signals-creator-is-helping-encrypt-meta-ai/), creator of the end-to-end encrypted messaging app [Signal](https://www.wired.com/story/signal-tips-private-messaging-encryption/) who also developed the privacy-focused AI platform Confer in recent years.\n\nWIRED viewed an advance draft of a technical white paper describing Confidential VM. In addition to structuring the system so the user controls their access keys, Meta is also giving select security firms access to the Confidential VM source to regularly audit and verify its privacy guarantees. Meta will also publish the Confidential VM binaries (machine-readable instruction files) and a transparency log, so users can verify the validity and integrity of their connection to Muse.\n\nSingleton emphasizes that Muse Secure VM has already been extensively vetted, including by Meta’s human and agentic red teams as well as through the company’s private bug bounty. And now Meta is adding Muse to the scope of its public bounty as well, with payouts up to $300,000 for valid vulnerability findings, including up to $130,000 for successful prompt injection attacks that affect a single user.", "url": "https://wpnews.pro/news/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it", "canonical_source": "https://www.wired.com/story/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it/", "published_at": "2026-09-08 20:12:51+00:00", "updated_at": "2026-09-08 20:21:48.219133+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-products", "ai-agents", "ai-safety"], "entities": ["Meta", "Muse", "Meta Superintelligence Labs", "Mark Zuckerberg", "Stripe", "Link", "OpenAI", "Anthropic"], "alternates": {"html": "https://wpnews.pro/news/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it", "markdown": "https://wpnews.pro/news/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it.md", "text": "https://wpnews.pro/news/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it.txt", "jsonld": "https://wpnews.pro/news/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it.jsonld"}}