
Meta launches Muse, a personal AI agent for automating tasks across apps and devices
Meta announced the release of Muse, a personal AI agent that users can message to automate digital tasks in a secure cloud environment. The company says Muse is rolling out today for iOS and Android users through a dedicated Muse app and via Muse.ai, with WhatsApp support and AI glasses access planned soon.
Messaging and task automation
Users can interact with Muse through the Muse app, Muse.ai, and directly in WhatsApp. Meta says people can prompt Muse in natural language to handle tasks such as sending emails, booking travel, and even helping sell a car on a user’s behalf. Meta also says Muse can make purchases using special payment infrastructure designed with Stripe.
Secure VM and human approvals
Meta is debuting Muse with an architecture called Secure VM, designed to isolate each user’s activity in a virtual machine. The goal is to separate untrusted data from the agent’s action-taking components and limit exposure to web inputs and third-party integrations.
Meta also describes a Sentinel system that monitors activity leaving the VM. It either applies existing permissions or triggers a human-in-the-loop approval dialog. Meta says these check-in prompts reach users directly and are not filtered through the model to reduce the risk of attacks such as prompt injection.
Stripe Link purchase protections
For purchases, Meta says Muse uses Stripe Link, which issues a single-use card number so agents do not enter a person’s real financial information across the internet. Meta adds that Muse is the first AI agent covered by Link’s purchase protections, which include no-fee returns.
Confidential VM, audits, and bug bounties
Meta says it will later offer Muse “Confidential VM”, intended to run each user’s VM in a trusted execution environment where users manage access keys locally on their devices. Meta says this prevents access by others, including Meta itself, and that the approach builds on work involving Moxie Marlinspike and the privacy-focused AI platform Confer.
Meta also plans to publish Confidential VM binaries and a transparency log, and to provide select security firms access to the source for regular audits. The company says Muse Secure VM has been vetted by Meta’s red teams and through a private bug bounty, and is now included in a public bounty with payouts up to $300,000 for valid vulnerability findings, including up to $130,000 for successful prompt injection attacks affecting a single user.
Why it matters
Personal AI agents require broad access to user data and actions, which makes trust and containment central to adoption. Meta’s launch pairs consumer-facing agent features with an explicit security model, including isolation via Secure VM, direct user approvals, and payment protections tied to Stripe Link.