Meta Unveils 'Muse' AI Agent, Prioritizing Security and Privacy in a Crowded Field
Meta has officially launched **Muse**, a new personal AI agent designed to automate digital tasks within a secure cloud environment. Rolling out for iOS, Android, and WhatsApp, **Muse** aims to differentiate itself from competitors by emphasizing robust security and privacy features from its inception.
On Tuesday, **Meta** announced the public release of **Muse**, its latest venture into the rapidly evolving landscape of personal AI agents. This new offering allows users to message an AI agent to automate various digital tasks, promising a secure cloud environment with built-in security and privacy.
**Muse** is now available for **iOS** and **Android** users via a dedicated app and the Muse.ai website. Additionally, users can interact directly with the agent through **WhatsApp**, with future integration planned for **Meta's AI glasses**. While **Muse** offers a free tier, extensive automation capabilities will require one of **Meta's AI subscription plans**.
### Competing in the AI Agent Race
**Muse** represents **Meta's** latest effort to compete with popular AI agents such as **OpenClaw** and **Instinct**. The project is a brainchild of **Meta Superintelligence Labs**, the AI unit formed by CEO **Mark Zuckerberg** approximately a year ago with the ambitious goal of catching up to industry leaders like **OpenAI** and **Anthropic**. The lab operates on the belief that AI agents will fundamentally transform how users interact with the internet and **Meta's** product ecosystem.
Internally, **Muse** was developed under the codename "**Hatch**," with employees utilizing it to autonomously operate third-party applications and browse the web on their behalf.
### Seamless Automation and Secure Payments
**Meta** claims that **Muse** is designed for ease of use, with "no learning curve." Users can prompt **Muse** in natural language to perform tasks such as sending emails, booking travel, or even assisting with selling a car. The agent is also capable of making purchases for users, leveraging special payment infrastructure developed by **Stripe**.
**Stripe's Link** payment tool issues single-use card numbers, ensuring that the agent does not access or store a user's real financial information across the internet. **Meta** highlights that **Muse** is the first AI agent covered by **Link's** purchase protections, which include no-fee returns.
### A Focus on Privacy and Trust
Despite being a late entrant to the personal AI agent market, **Meta** is strategically focusing on the security and privacy features of **Muse** to distinguish itself. The agent debuts with an architecture dubbed **Secure VM**, designed to isolate each user's activity within a virtual machine. This separation aims to keep untrusted data from the web and integrated services distinct from the part of the agent that executes actions on a user's behalf.
Building user trust is paramount, especially given **Meta's** past struggles with data privacy. To encourage adoption and integration with third-party apps, **Meta** is attempting to assure users of its responsible data handling practices.
**David Singleton**, VP of Engineering for Consumer Products at **Meta Superintelligence Lab**, explains their approach: "We know itβs really important, if weβre going to build a product like this that can access a lot of sources of personal data, that weβre really responsible with that, so weβve designed this system very deliberately. And weβve built what we call the **Sentinel** that actually looks out for everything thatβs moving out of the VM and either matches it to an existing policy where the user or the system has given permission for that to happen or presents a human-in-the-loop dialog to ask you to approve the action itβs going to take."
**Singleton** also notes that these human check-in prompts are delivered directly to the user, bypassing the model to protect against prompt injection attacks.
### Confidentiality and Industry Standards
While **Secure VM** is designed to enhance user security and privacy, **Singleton** acknowledges that **Meta** could technically access user **Muse** data, though company policy prohibits it. Users retain the option to opt out of their data being used for training.
**Meta** plans to introduce **Muse "Confidential VM"** in the future, which will run each VM in a "trusted execution environment." Users will manage their own access keys locally on their devices, ensuring that no one, including **Meta**, can access their agent VM. This initiative is part of **Meta's** collaboration with **Moxie Marlinspike**, the creator of the end-to-end encrypted messaging app **Signal**.
To further bolster transparency and trust, **Meta** will provide select security firms with access to the **Confidential VM** source code for regular audits. The company will also publish the **Confidential VM** binaries and a transparency log, allowing users to verify the integrity of their connection to **Muse**.
### Rigorous Vetting and Bug Bounties
**Singleton** emphasizes that **Muse Secure VM** has undergone extensive vetting, including assessments by **Meta's** human and agentic red teams, as well as through its private bug bounty program. **Meta** is now expanding its public bug bounty to include **Muse**, offering payouts up to $300,000 for valid vulnerability findings. This includes rewards up to $130,000 for successful prompt injection attacks affecting a single user.