Technology

Meta’s Muse agent acts on your inbox and calendar — Meta’s engineers can still get in

Susan Hill

Meta‘s new AI agent, Muse, now runs American users’ daily lives — booking travel, negotiating bills, filling out forms, and completing checkouts without being asked twice. It connects to email, calendars, health platforms, smart-home devices, shopping services, and payment systems, then acts on those permissions autonomously, requesting approval only for sensitive actions like purchases or outgoing emails.

Meta designed the most complex privacy casing a major social network has ever wrapped around a consumer AI product. Muse runs inside a dedicated virtual computer called the Secure VM, isolated, the company says, from its advertising systems. A second AI called Sentinel must sign off on every request Muse tries to send to the internet.

The casing has a gap the company itself has acknowledged. Meta’s vice president of Superintelligence Labs said in published remarks that engineers can technically access data inside the Secure VM today. The Confidential VM feature — which would give users sole custody of their encryption keys and lock out even Meta’s staff — is described as coming soon with no confirmed date. Until it ships, the wall between Muse’s private computer and Meta’s own servers is a policy commitment, not a technical barrier.

Internal testing produced problems that were not publicly disclosed ahead of launch. According to a report by Forkast News, guardrails were bypassed in ways that exposed private iCloud photos stored in connected accounts. The agent stalled repeatedly and failed to recover after roughly fifteen minutes of activity. Meta’s own chief technology officer was logged out of the product during internal sessions. The company’s rate of engineering incidents rose 40 percent year-over-year; time spent on reactive firefighting climbed 70 percent.

Meta’s claim to trustworthiness rests on a record the company has spent a decade trying to improve. The Federal Trade Commission reached a settlement with Meta over privacy deception in 2011. The company paid five billion dollars to resolve Cambridge Analytica-era charges in 2019. Child safety lawsuits resulted in more than 1.9 billion dollars in combined settlements. On the day before launch, Senators Chuck Grassley, Marsha Blackburn, and Josh Hawley sent a letter to Meta raising specific data-handling concerns about Muse.

The case for the product is straightforward. Booking a flight across four browser tabs while checking a calendar and a credit card statement is genuinely inefficient work, and Muse can compress it into a single conversation. The free tier is available immediately. Power users pay twenty dollars a month; the Maximum plan costs a hundred. Meta says most users will remain on the free option.

What Muse does not yet do matters as much as what it does. International availability beyond the United States has no confirmed date, leaving the product’s 21-language market ambition contingent on regulatory clearance in the EU and elsewhere. Shop Pay and 1Password integration are listed as coming soon. How Muse identifies itself to the websites it navigates on behalf of users — a detail with implications for fraud detection and terms-of-service enforcement — has not been disclosed. The FIDO Alliance launched a dedicated working group in April 2026 to set authentication standards for AI agents; no specification is final.

Muse is available in the US through the web, iOS, Android, and WhatsApp. Meta says it will reach its AR glasses later this year — making the question of who controls the data a problem you will eventually wear on your face.

Tags: , , , , ,

Discussion

There are 0 comments.