Back
Technology · Today

Exploring Meta's Muse: Your New AI Assistant

0:00 3:47
metaartificial-intelligenceprivacyamazonunited-state

Other episodes by podcats-reliability-canary.

If you liked this, try these.

The full episode, in writing.

On September 8, 2026, Meta introduced Muse as a personal AI agent powered by its Muse Spark model. Meta said people could give it tasks and longer-term goals through conversations in the Muse app or WhatsApp.
Meta described Muse as capable of moving beyond conversation into direct action. It said the agent could open a browser, fill out forms, negotiate, send email and book travel. Longer-running assignments could continue after the user closed the app, with Muse returning when circumstances changed or it needed approval.
Meta said users would choose which services Muse connected to and how much access it received. Email permissions could be separated, allowing a user to decide independently whether Muse could read email and whether it could send messages on the user’s behalf.
For sensitive actions, Meta said Muse would ask before sending an email or making a purchase. It also described a complete audit trail covering actions Muse had completed and actions it planned to take. Users could change access or disconnect a service.
Meta said Muse operated inside a dedicated cloud virtual machine called Muse Secure VM. That environment housed both the agent and data from the user’s connected services.
A separate Sentinel agent inside Muse Secure VM was described as an approval layer between Muse and the internet. Meta said Sentinel had to approve Muse’s actions before they reached the internet and would request the user’s permission when necessary.
Meta said credentials were placed in secure storage, allowing Muse to use them without seeing passwords or payment details. It also said users could opt out of having their Muse interactions used to train Meta’s AI models.
Meta further said conversations and data held in users’ virtual machines weren’t shared with its advertising systems. Users could also instruct Muse to forget particular information it had learned.
For purchases, Meta said on September 8 that Muse could use Stripe’s Link checkout and one-time-use payment cards. It identified support for Shop Pay and 1Password as planned. By September 23, Meta had also announced PayPal support and connectors covering retail, travel and productivity.
On September 8, Meta said Muse was rolling out in the United States through iOS, Android and muse.ai. It described most uses as free, with subscription plans intended for people who wanted to do more.
At Meta Connect on September 23, the company announced forthcoming additions: a real-time digital avatar, voice access through Meta smart glasses, control of Mac computers and a dedicated Muse email address.
By September 23, Meta had opened the Muse platform to developers building connectors. Alexandr Wang, identified at the time as Meta’s chief AI officer, said the company had received more than 1,500 connector applications in less than a week.
On September 21, security researcher Patrick Wardle was reported to have found a zero-day in Muse. Locally running applications or terminal commands could change an undocumented transcription-endpoint setting and obtain the token used to authenticate a user’s Muse account.
Wardle’s proof-of-concept attacks used that account control to write files and take pictures. Meta said it released a hotfix more than 12 hours after the article describing the vulnerability was published.
Amazon said it had begun blocking Muse from shopping on Amazon because it considered Muse an unauthorized AI agent that violated its Conditions of Use, and Amazon said it had asked Meta to remove Amazon from the Muse experience.

Hear the full story.
Listen in PodCats.

The full episode, all the chapters, your own library — and a feed of voices worth following.

Download on theApp Store
Hear the full episode Open in PodCats