Meta Debuts Muse AI Agent That Runs in Its Own Secure VM
TL;DR
- Each Muse user gets a dedicated Linux VM with a full Chromium browser, Debian runtime container, and eBPF-based kernel monitoring that revokes autonomous permissions when untrusted content is detected.
- A separate Sentinel process controls all network egress and cannot be overridden by the agent; the authd daemon injects credentials at the network boundary so the model never sees raw secrets.
- SiliconAngle reports Meta technically retains server-side access to SecureVMs today, a credibility gap the upcoming Confidential VM tier directly addresses by giving users sole encryption key custody.
Meta rolled out Muse, a personal AI agent that plugs into a user's email, calendar, payments, health and fitness apps, smart-home devices, dining and shopping services, and completes errands from inside those accounts, TechCrunch reported. It launches for US users at muse.ai, on iOS and Android, and inside WhatsApp, with Meta's AI glasses to follow.
The security pitch is architectural. Muse runs inside its own "dedicated, secure computer with its own browser," the Muse Secure VM, and Meta says the agent "won't have visibility into people's passwords or payment methods." Payments route through Link by Stripe; Shopify Shop Pay and 1Password integrations are listed as coming soon. Meta also says conversations and data are not shared with its ads systems.
The free tier is metered. Paid Power costs $20 a month and Maximum costs $100. The agent is powered by Meta's Muse Spark model.
The bulk of the TechCrunch piece is about trust. The outlet walks through Meta's regulatory history: a 2011 FTC settlement over exposing private information; a 2019 FTC penalty that was "a then record-breaking $5 billion settlement over eight separate privacy-related violations"; a 2023 FTC charge that Meta had violated that same order; an "$18 billion multistate settlement" reached with 29 states in August over social media's consumer harms; and a New Mexico judgment ordering Meta to pay $942 million over harms for children. It also notes the Cambridge Analytica scandal and the 2019 discovery of user passwords stored in readable formats. Muse joins more than a hundred Meta items we have logged in the last ninety days, and it lands into that record rather than around it.
What others are reporting
-
Meta Newsroom Read →
First-party post confirms credential zero-visibility design, Confidential VM roadmap for late 2026, and explicit exclusion of all Muse conversation data from Meta's ad targeting systems.
It doesn't just answer questions, it actually does the work. It helps people stay on top of things, takes tasks off their plate.
-
SiliconAngle Read →
Flags that Meta technically retains server-side access to SecureVMs today, undercutting privacy claims; grounds Muse's credibility problem in Meta's prior legal and regulatory history.
The harness runs in its own isolated cell, it doesn't see real credentials, and every interaction runs through a Sentinel which the agent can't override.
-
PBS NewsHour Read →
Mainstream framing centers on consumer adoption skepticism; PBS describes Zuckerberg's broader AI vision document as 'fantastical,' signaling editorial distance from the company's promises.
Once a person shares a goal with Muse, it helps them develop a personalized plan and coordinate their time and resources, then advances the work on its own.
-
Vellum Read →
Deepest technical sourcing available: documents systemd-nspawn container isolation, the authd authentication daemon architecture, and eBPF-based tainted-data tracking at the kernel level.
Every user is provisioned a dedicated Linux environment called Muse Secure VM, containing a Chromium browser, Debian container, local storage, and capacity to compile code and run subagents.
-
Apple App Store Read →
Confirms iOS 18+ requirement and 18+ age rating at launch; lists email, calendar, social media, health, and financial account integrations available on day one.
Shared on Bluesky by 1 AI expert
Originally reported by techcrunch.com
Read the original article →Original headline: Meta Launches Muse Personal AI Agent With Dedicated Secure VM, Rolls Out in US