Meta Launches Muse, a Personal AI Agent Designed With Privacy in Mind
Meta on Tuesday introduced Muse, a personal AI agent that automates digital tasks in a secure cloud environment, available now on iOS, Android, the web, and WhatsApp.

Meta has announced the launch of Muse, a personal AI agent that people can message to automate digital tasks in a secure cloud environment, with security and privacy described as key features from the start.
Muse is rolling out Tuesday to users on iOS and Android through a dedicated app, as well as on the Muse.ai website. Users can also message the agent directly on WhatsApp. Meta says owners of its AI glasses will be able to interact with Muse soon. Basic access to Muse is free, but those who want to automate a large number of digital tasks will need one of Meta's AI subscription plans.
Muse is Meta's answer to viral AI agents such as OpenClaw and Instinct. The agent was developed by Meta Superintelligence Labs, the unit that CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic. WIRED previously reported that Muse was being tested internally under the codename "Hatch," with employees using it to operate third-party apps and browse the web.
Meta claims the product has no learning curve, and users can give prompts in natural language. Muse can send emails, book travel, or help sell a car. It can also make purchases using payment infrastructure built by Stripe called Link, which gives agents a single-use card number so they don't enter a person's real financial information across the internet. Meta says Muse is the first AI agent covered by Link's purchase protections for agents, including no-fee returns.
Meta seems to be differentiating Muse with a privacy-focused architecture called Secure VM. This setup isolates each user's activity in a virtual machine, keeping untrusted web data and integrations separate from the part of the agent that can take actions. A system called Sentinel watches everything moving out of the VM; if an action doesn't match an existing permission policy, it asks the user for approval. The prompts go directly to the user and aren't filtered through the model, which Meta says protects against prompt injection attacks.
Meta acknowledges that Secure VM is not a truly locked box. While policy bars Meta from accessing user Muse data, doing so would still be technically possible. Users can opt out of having their data used for training. In the future, Meta plans to offer "Confidential VM," in which each VM runs in a trusted execution environment and users manage their own access keys locally. That would mean no one else, including Meta, could access a user's agent VM. This work is tied to Meta's cooperation with Moxie Marlinspike, creator of Signal and developer of the privacy-focused platform Confer.
A technical white paper viewed by WIRED shows that Meta is also planning to give selected security firms access to the Confidential VM source code for regular audits. The company will publish binaries and a transparency log so users can verify the integrity of their connection. David Singleton, vice president of engineering for consumer products at Meta Superintelligence Lab, said Secure VM has already been vetted by human and agentic red teams and through Meta's private bug bounty. Now Muse is being added to the public bug bounty program, with payouts up to $300,000 for valid vulnerability findings, including up to $130,000 for successful prompt injection attacks that affect a single user.


