Meta’s consumer agent Muse arrived this week wrapped in a security setup that is rare for a chatbot-style product. Each user’s assistant runs inside its own dedicated virtual machine, which Meta calls the Muse Secure VM, with the agent’s browser and credentials walled off from everything else on the machine.
Muse does more than converse. Once someone connects email, calendars, payments and other services, it can draft messages, arrange travel, push back on monthly bills, complete forms and pay for items through Stripe’s Link checkout. Work keeps progressing after the app closes. Actions that carry risk, such as sending an email or spending money, stop for owner approval, and a running log shows what the agent did and what it intends to do next.
Meta leans on that isolation to answer the obvious trust question. A separate Sentinel process vets each connector action and each network request. Real passwords and payment details never reach Muse itself: placeholder tokens stand in until a secret is needed at the boundary, and the browser helper sees only a simplified view of a page, leaving prompt-injection tricks little to grab.
Muse builds on Muse Spark 1.3, the agent model Meta Superintelligence Labs shipped last week. The US rollout covers the web, iOS, Android and WhatsApp, with Meta’s AI glasses planned later. Casual use is free; Power and Maximum subscriptions run $20 and $100 a month. Meta requires a card at signup, says a usage meter will warn people before paid tiers engage, and insists conversations never feed its ads systems.