Launched

Muse is Meta’s Answer to OpenClaw, And it Comes with Trust Issues

Meta Muse. © Meta Platforms
Meta Muse. © Meta Platforms

Set Trending Topics as a preferred source on Google.

Meta has just unveiled its biggest push into consumer AI so far: Muse, a personal AI agent that does not only talk about tasks but carries them out. The rollout starts in the US, and Muse is available on the web at muse.ai, through apps for iOS and Android, and in chats inside WhatsApp. Meta says its AI glasses will follow. The model underneath is Muse Spark 1.3, which recently put Meta back at the top of the benchmarks.

What Muse Is Supposed to Do

Meta describes Muse as an agent for everyday errands as well as longer-term projects. The listed examples include writing and sending emails, booking travel, renegotiating bills and tariffs, filling out forms, building plans, turning saved Instagram recipe reels into grocery lists, sending party invitations and completing purchases. The agent keeps working after the app is closed and comes back when something changes or when it needs an approval.

Payments run through Link by Stripe, and Meta says Muse is the first agent covered by Link’s purchase protections. Shop Pay and a 1Password integration are set to follow. Muse also remembers what matters to its user and is meant to offer suggestions unprompted. Individual stored details can be deleted on command.

Basic use is free, up to 100 million tokens per week. Once consumption passes a threshold, subscriptions kick in: Power at 20 dollars a month and Maximum at 100 dollars a month. A payment card is required from the start, and a usage meter in the app shows how much of the allowance is left.

Which Data in Which Apps

Muse becomes useful once it has access to the services people already rely on. Meta ships a set of ready-made connectors, and each one is connected individually and deliberately:

  • Communication and organization: email and calendar, plus chats via WhatsApp
  • Payments: payment services for checkout and processing
  • Everyday services: health and fitness, smart home, dining, shopping, music, events
  • Meta’s own apps: Instagram and Facebook among others
  • Everything else: Muse can wire up any service with a public API using credentials the user provides. Where no API exists, the agent operates the service through the browser

For email, access is granular: users decide whether Muse may only read or may also send on their behalf. Permissions can be changed or revoked at any time. Anyone who does not want their interactions feeding into the training of Meta’s AI models can opt out, according to the company.

Where the Data Lives

Every user gets a dedicated virtual machine in Meta’s cloud, the Muse Secure VM. That is where the agent runs, where the data sits, and where OAuth tokens and other credentials for connected services are stored, explicitly not in central Meta infrastructure. Meta calls this VM the system of record for everything that goes into Muse. Only what is needed for inference and telemetry leaves it.

Technically it is an isolated Linux box with its own Chromium browser and enough compute for sub-agents and cron jobs. Inside that box Meta draws a second line. The agent itself runs in a sealed runtime container, while security-relevant services run outside it. Those include credential management, the execution of connector logic under tightly scoped privileges, a Postgres database holding durable state, and independent classifiers meant to catch prompt injection attempts. Because this protective layer sits outside the agent’s reach, Meta says a compromised agent cannot switch it off.

Who Has Access

The central piece is a second, separate agent called Sentinel. It is the only authority that approves connector actions and any outbound network traffic. Muse proposes, Sentinel decides. For sensitive steps such as sending an email or making a purchase, Sentinel asks for approval through a dedicated dialog in the app rather than through the conversation with the agent. Users also see an audit trail of everything the agent has done and plans to do.

The agent itself never sees passwords or payment details. Credentials go into a separate store, and the agent works only with surrogate tokens that get swapped for the real ones at the network boundary. For payments, a single-use card number is issued and tied to a specific merchant, amount and time window. The email connector filters out one-time codes, password reset links and magic links, so a compromised agent cannot use the inbox to take over other accounts. The browser sub-agent sees an accessibility tree of the page instead of the raw DOM and cannot execute JavaScript.

Meta also draws a line toward its advertising business: neither conversations nor the data inside the VM are supposed to flow into Meta’s ad systems. Alongside the launch, Meta is opening its bug bounty program to everyone, with rewards of up to 300,000 dollars, including up to 130,000 dollars for successful prompt injection attacks affecting a single user.

The Confidential VM, and What It Says About Today

One limitation is spelled out by Meta itself, and with unusual clarity. The current architecture isolates users’ data from one another and restricts access by Meta staff through operational policies. It does not prevent Meta from accessing data when that is necessary to operate, secure or support the service. For now, protection against the operator rests on policy rather than cryptography.

That is the gap Muse Confidential VM is meant to close, and Meta says it will arrive before the end of the year. With it, the entire VM including data and conversations is encrypted with a key only the user holds. The goal is to rule out access by Meta in a way that is cryptographic and verifiable. A small group of testers is already working with it, external auditors have the design and source code, and a continuous, publicly inspectable audit is planned once it launches.

In practice that means anyone using Muse at launch is handing their email, calendar and payment activity to a system whose operator can look inside if the need arises. Technically enforced confidentiality comes later.

The Trust Question

Whether that is enough remains open. Meta carries a long history of privacy proceedings, from the FTC settlement in 2011 through the then record 5 billion dollar penalty in 2019 to fresh allegations in 2023. The company recently agreed to an 18 billion dollar settlement with 29 US states over social media harms to children and teenagers. As TechCrunch notes, Muse asks for considerably more trust than social media ever did, because the agent acts on the user’s behalf rather than merely collecting data.

Meta’s answer is transparency plus proximity. Users can name their agent, give it an avatar and configure how it talks to them. Whether the mix of utility and personal attachment is enough for people to hand the company their most sensitive data once again will become clear over the coming months.

Rank My Startup: Erobere die Liga der Top Founder!
Advertisement
Advertisement

Specials from our Partners

Top Posts from our Network

Deep Dives

© Wiener Börse

IPO Spotlight

powered by Wiener Börse

Europe's Top Unicorn Investments 2023

The full list of companies that reached a valuation of € 1B+ this year
© Behnam Norouzi on Unsplash

Crypto Investment Tracker 2022

The biggest deals in the industry, ranked by Trending Topics
ThisisEngineering RAEng on Unsplash

Technology explained

Powered by PwC
© addendum

Inside the Blockchain

Die revolutionäre Technologie von Experten erklärt

Trending Topics Tech Talk

Der Podcast mit smarten Köpfen für smarte Köpfe
© Shannon Rowies on Unsplash

We ❤️ Founders

Die spannendsten Persönlichkeiten der Startup-Szene
Tokio bei Nacht und Regen. © Unsplash

🤖Big in Japan🤖

Startups - Robots - Entrepreneurs - Tech - Trends

Continue Reading

Newsletter

Founders Dispatch

Zwei Mal pro Woche kostenlos in die Inbox: die wichtigsten Startups, Deals und Tech-Entwicklungen aus Europa, handgeschrieben von der Redaktion.

Jederzeit abbestellbar. Mehr über den Newsletter