Wednesday, September 16, 2026
Meta Launches Muse AI Agent With Secure VM and Connected-App Actions

Meta Launches Muse AI Agent With Secure VM and Connected-App Actions



Meta launches Muse AI agent in the United States as a personal assistant that can carry out digital work across connected services, not merely answer questions. The September 8 release puts email, travel booking, forms, shopping and longer-running projects inside a dedicated cloud environment controlled through natural-language messages.

 

Muse launches with three capabilities at the center of Meta’s pitch:

  • Autonomous work across approved apps and websites.
  • A dedicated Secure VM monitored by a separate Sentinel agent.
  • User approval before sensitive actions such as sending email or making purchases.

 

Meta Launches Muse AI Agent Across Apps and the Web

Muse is rolling out to U.S. adults through dedicated iOS and Android apps and at Muse.ai. Meta also lets users message the agent through WhatsApp, while support for the company’s AI glasses is planned for a later release.

 

The product is powered by Meta’s Muse Spark model and is designed to continue working after a user closes the app. It can return when circumstances change or when an action requires approval, turning the interaction into an ongoing workflow instead of a single chat response.

 

Meta says Muse can open a browser, fill out forms, send email, book travel and negotiate on a user’s behalf. It can also build plans around longer-term goals, coordinate time and resources, and remember selected details that may improve later suggestions.

 

The launch is distinct from Meta’s earlier Muse-branded models. Muse Spark supplies the reasoning and tool-use foundation, while the newly released Muse product packages those capabilities as a consumer agent with app connections, permissions and persistent cloud execution.

 

Secure VM and Sentinel Divide the Agent’s Powers

Meta’s central technical claim is that every Muse runs on a dedicated Secure VM, a virtual computer with its own browser. The agent, connected-service data and stored credentials operate inside that environment rather than directly on a user’s phone.

 

A separate system called Sentinel controls what can leave the virtual machine. Meta says Sentinel evaluates outbound actions against permissions granted by the user or the system and presents a human approval prompt when a request falls outside those boundaries.

 

Credentials are intended to remain hidden from the Muse model. Users can choose which services to connect, limit whether email access is read-only or includes sending, review an audit trail, revoke access and ask the system to forget selected remembered information.

 

Those controls matter because a general-purpose agent encounters untrusted instructions while browsing. A malicious webpage, email or document could attempt a prompt-injection attack that directs the agent to disclose information or perform an action the user never requested.

 

Meta’s architecture separates the model planning a task from the system authorizing internet access. The company has also placed Muse within its public bug-bounty program, offering researchers a channel to report vulnerabilities that escape internal red-team testing.

 

Payments Use One-Time Cards and Human Approval

Muse can make online purchases through Stripe’s Link payment system. According to Meta, Link generates a one-time card number for an agent transaction, preventing a merchant or the agent workflow from receiving the user’s underlying card details.

 

Meta says Muse checks with the user before completing a purchase. Link also extends purchase protections to eligible agent transactions, while Shop Pay and 1Password support are planned as additional payment and credential options.

 

The arrangement illustrates how consumer agents may need purpose-built infrastructure rather than ordinary browser automation. Payments, logins and messages carry consequences that require stronger identity, authorization and recovery mechanisms than a chatbot producing text.

 

Muse is free for most uses, with subscription plans available for users who want more capacity. Meta has not presented the initial U.S. rollout as a finished global launch, and adoption will depend on whether consumers trust it with the broad access needed to make autonomous help useful.

 

Confidential VM Is Meta’s Planned Privacy Upgrade

Secure VM is not Meta’s final privacy design. The company plans to introduce a Confidential VM later in 2026, encrypting the entire agent environment with a key held by the user so that Meta itself cannot access the contents.

 

Meta says the future design will use a trusted execution environment, published binaries and a transparency log, with outside security firms able to audit the system. That approach aims to make privacy claims technically verifiable rather than dependent only on company policy.

 

For now, the current Secure VM still leaves Meta technically capable of accessing Muse data even though company policy restricts that access, according to WIRED’s reporting. Users can opt out of having their interactions used to train Meta’s models, and Meta says Muse data is not shared with its advertising systems.

 

The product therefore arrives with both an ambitious capability claim and a demanding trust test. Its practical value will be measured by whether it completes multi-step tasks reliably while resisting malicious instructions, honoring permissions and making consequential actions visible before they occur.

 

Further Reading

THEFLGHT
author

THEFLGHT

Elevating narratives from the heart of London's intellectual epicentre.

0 Comments:

Leave a Reply

AI Agent Data Breach: Spain Discloses Its First Report
Google Launches Gemini 3.8 Live and Extended Thinking Voice Models
Meta Launches Meta One AI Subscriptions Across Instagram, WhatsApp and Facebook
Axelera Launches Europa AI Chip for Dell and Supermicro Systems
Einride Autonomous Truck Launches Into Daily Lidl Service in Germany
DeepSeek IPO Plan Taps Yan Wentao as First CFO