Meta is introducing Muse, a secure, private personal AI agent that proactively helps with people's goals and suggests ideas. The agent runs on Muse Secure VM, a dedicated virtual machine that houses both the agent and a person's data. Muse is designed around existing communication patterns, working like messaging another person through the Muse app or directly in WhatsApp.
People tell Muse what needs to get done, and it takes action, powered by Muse Spark, Meta's most capable model to date, built for real-world agentic work.
How It Works
Muse was built to work for billions of people worldwide with no learning curve—anyone can use it without technical experience. It handles routine tasks like sending emails or booking travel, as well as larger goals. Once a person shares a goal, Muse develops a personalized plan, coordinates time and resources, and advances the work independently. It can open a browser, fill out forms, and negotiate on behalf of users.
For longer tasks, Muse continues working after people close the app and returns when something changes or approval is needed, such as before sending an email or making a purchase. Users can achieve better results with less effort: selling a car for more, lowering a bill, or adjusting a training plan as circumstances shift.
When paying, Muse uses Link, built by Stripe, and is the first AI agent covered by Link's purchase protections: free coverage for damaged or lost items, price drops, no-fee returns, and a return guarantee on eligible purchases. Link's wallet generates a one-time-use card to keep real card details hidden. Shop Pay is coming soon, along with 1Password support so Muse can use existing logins.
Muse also remembers what matters to a person and can make unprompted suggestions. It can turn a saved Instagram recipe reel into a grocery list, suggest a dinner party menu, and remember friends' dietary restrictions before sending invites.
Built to be Private, Safe, and Secure
Muse Secure VM provides first-of-its-kind privacy, safety, and security protections:
- Muse runs on its own dedicated cloud computer, isolated so no other agent can access it. Data and credentials for connected services are securely stored there.
- A separate Sentinel agent runs on the same machine, kept apart at the system level. Nothing Muse does reaches the internet unless the Sentinel approves it and asks the person for permission when needed.
- Muse has no visibility into passwords or payment methods. Credentials go into secure storage so Muse can use them without seeing them, including passwords people type into the browser themselves.
- Muse checks with people before sensitive actions like sending an email or making a purchase, showing a complete audit trail of everything it has done and plans to do.
- People choose which apps Muse connects to and exactly how much access it gets—for email, whether it reads mail or can also send on their behalf.
- People can change access or disconnect a service whenever they want and can opt out of their interactions being used to train Meta's AI models.
- Muse doesn't share conversations or VM data with Meta's ad systems.
- Muse can forget specific things people tell it to forget.
Later this year, Meta will introduce Muse Confidential VM, where the entire VM, including conversations and data, is encrypted with a key only the user holds, so not even Meta can access it.
Looking Ahead
Muse is rolling out in the US on iOS, Android, and muse.ai, with availability on AI glasses coming soon. It's free for most uses, with subscription plans available for those who want additional capabilities.
Most Read










