Launches

Meta launches Muse AI agent with privacy-first architecture, stock jumps 6%

Meta Platforms has unveiled Muse, a personal AI assistant designed to handle everyday digital tasks through a dedicated app while prioritizing user privacy and data security.

·4 min read
Meta debuts its ‘secure by design’ personal AI agent Muse, stock rises 6%
Meta debuts its ‘secure by design’ personal AI agent Muse, stock rises 6%

Meta Platforms Inc. is wagering that broader adoption of AI agents hinges on making them both accessible and trustworthy. On Wednesday, the company introduced Muse, a personal artificial intelligence assistant that lets users communicate via a standalone application to delegate and automate various digital responsibilities. The agent operates within a protected cloud infrastructure, with Meta emphasizing that privacy safeguards are embedded throughout its design.

Muse rolled out today across the U.S. on both iOS and Android platforms, with web access available at Muse.ai. Users can also interact with the agent through WhatsApp. In the coming months, those with Meta's smart glasses will gain access to Muse as well. The service is available at no cost for initial use, though heavy automation workloads will likely require a paid subscription.

Meta's announcement triggered a 6% surge in the company's stock price during Wednesday trading. The agent represents Meta's competitive response to emerging AI assistants like OpenClaw, Claw AI and NanoClaw, functioning through a messaging interface where users direct the system to execute specific operations.

Meta Superintelligence Labs, the company's dedicated AI research division established roughly a year ago, developed the application. This unit was created to strengthen Meta's position against rivals including Google LLC, OpenAI Group PBC and Anthropic PBC. Mark Zuckerberg, Meta's founder and chief executive, established the labs based on his conviction that AI agents will eventually become central to daily life and reshape how people navigate the internet.

Internal testing of Muse occurred under the codename "Hatch," where staff members deployed the agent to manage third-party software and web browsing. According to Meta's announcement, Muse prioritizes user-friendliness with an immediate learning curve, enabling users to begin using it immediately. The agent can handle tasks including composing and sending emails, purchasing airline and bus tickets, making restaurant reservations, processing payments and facilitating vehicle sales.

Stripe Inc. powers Muse's transaction capabilities through a payment system called Link. For each transaction, Link generates a single-use card number for the agent, preventing access to the user's actual payment card information and reducing exposure of sensitive financial data. Link incorporates purchase safeguards for agents, including guaranteed fee-free returns.

Secure by design, sort of

https://x.com/alexandr_wang/status/2097402344061510004?ref_src=twsrc%5Etfw

While Meta isn't pioneering personal AI agents, the company aims to distinguish Muse through enhanced privacy and security mechanisms. This positioning presents challenges given Meta's track record and recent legal troubles, yet the organization contends that user information will remain protected and confidential through Muse.

Meta requires users to grant Muse access to substantially more personal information than Facebook and Instagram typically receive. For the agent to function effectively on behalf of users, it must integrate with email, calendar, financial records, health and fitness applications, smart home systems and comparable services.

Consequently, Muse operates on a secure infrastructure Meta calls Secure VM, engineered to confine the agent's operations within an isolated virtual machine. Tarek Sheasha, vice president of Superintelligence Labs, explained that this architecture ensures sensitive data remains disconnected from the internet and isolated from the component of the agent capable of taking action.

Meta has also created Sentinel, a monitoring system designed to track all data flowing from the user's virtual machine. The tool compares outbound data against pre-established authorization policies; when no matching policy exists, it notifies the user and requests approval for the intended action. According to Sheasha, "The harness runs in its own isolated cell, it doesn't see real credentials, and every interaction with the outside world runs through a Sentinel which the agent can't override."

Nonetheless, users must ultimately place confidence in Meta's operational conduct. Although Meta's guidelines prohibit examining the contents of user SecureVMs, the company technically possesses the capability to do so if it chose to, according to David Singleton, vice president of engineering for consumer products at Superintelligence Labs, in comments to Wired.

Meta intends to address this limitation in a forthcoming release. Singleton indicated the company will introduce a Muse variant featuring a "Confidential VM," where each virtual machine executes within a trusted execution environment controlled by user-managed security keys. This configuration would prevent even Meta from accessing the virtual machine.

Meta permits free users to consume up to "100 million tokens per week." Since each token represents four characters, this allowance should grant substantial capacity for experimentation before encountering payment restrictions.