Product · September 12, 2026

Meta Launches Muse AI Agent with Secure Virtual Machine Architecture

person using MacBook Pro
Campaign Creators / Unsplash

Meta has officially launched Muse, a personal artificial intelligence agent designed to execute complex tasks on behalf of users, including booking travel, sending emails, and making purchases. The new system is available in the United States and operates through the Muse application and WhatsApp. Techsauce reported the story, highlighting the company's focus on security infrastructure rather than just model capability. The launch marks a significant shift in how personal agents interact with digital services, emphasizing a dedicated secure environment for every user.

The core of the Muse system is the Muse Secure VM, a dedicated virtual machine created specifically for the agent to inhabit. Each user receives their own isolated instance on the cloud, ensuring that other agents cannot access their data. Personal information and service credentials are stored within this specific machine. A separate agent named Sentinel operates on the same machine but is isolated at the operating system level. Sentinel acts as a rule enforcer, reviewing all outgoing internet requests from Muse. If a request aligns with user-approved policies, it is allowed; otherwise, the system prompts the user for confirmation. Muse cannot bypass Sentinel, ensuring that all external communications are monitored.

Meta addresses the vulnerability of prompt injection, where malicious commands are hidden in web pages or files. The company has implemented multiple layers of defense, including training the model to resist manipulation, labeling untrusted data, and using a separate system to detect attack patterns. Users must also confirm sensitive actions. Meta acknowledges that prompt injection remains an unsolved industry-wide problem and that Muse may occasionally fail. The architectural goal is to limit the damage when such failures occur rather than guaranteeing absolute security. To further enhance safety, Meta has launched a bug bounty program offering rewards of up to 300,000 USD for reporting vulnerabilities.

Payment processing is handled through Link, a payment system by Stripe. Muse is the first AI agent to receive Link's purchase protection, which covers damaged goods, price adjustments, and returns. The system uses one-time-use cards for each transaction, ensuring that the agent or merchants never see the user's actual card number. Meta plans to add Shop Pay and 1Password support in the future. Users can control access permissions, choosing which apps to connect and what level of access to grant. All actions are logged in an audit trail. Conversations and data within the virtual machine are not used for advertising or model training. A future update, Muse Confidential VM, will encrypt the entire machine with keys held only by the user, preventing even Meta from accessing the data.

The agent is currently available in the United States on iOS, Android, and the web at muse.ai. It supports commands via WhatsApp, with support for Meta's AI glasses to follow later. Pricing includes a free tier with a limited weekly quota. Paid subscriptions are available at two levels: Power at 20 USD per month and Maximum at 100 USD per month. The underlying model is Muse Spark, recently updated for agent-specific tasks. The system allows users to set goals, after which Muse plans, allocates resources, and executes tasks such as browsing, filling forms, and negotiating. It can continue working after the app is closed and notifies users when approval is needed or when status changes occur.