Most AI assistants talk. Muse is supposed to act. Meta announced Muse today, a personal AI agent designed to take on real tasks, from booking travel to negotiating a lower bill, without requiring users to babysit every step. That’s a harder problem than it sounds, and it puts Meta in direct competition with OpenAI’s Operator, Google’s Project Mariner, and Anthropic’s computer-use capabilities. The difference Meta is betting on is trust infrastructure, specifically, a dedicated virtual machine that no other agent on the market currently offers.
What Muse actually does
Muse runs on something Meta calls Muse Secure VM, a dedicated cloud computer assigned to each user. The agent lives there, along with any credentials or data the user connects. It’s powered by Muse Spark, Meta’s latest model built for agentic work. Users interact with it through the Muse app or directly inside WhatsApp, which is a smart distribution move given WhatsApp’s global user base.
The agent can handle short tasks like sending an email, and longer ones like managing a fitness plan that adapts as someone’s schedule changes. For extended tasks, it keeps working after the app is closed and checks back in when it needs approval or when something changes. It can open a browser, fill out forms, and negotiate on a user’s behalf. That last part is where it gets interesting: Meta is pitching Muse as something closer to a personal chief of staff than a chatbot.
On the commerce side, Muse integrates with Link by Stripe and is the first AI agent covered by Link’s purchase protections. That includes coverage for damaged or lost items, price drop refunds, no-fee returns, and a one-time-use virtual card so real payment details stay out of the loop. Shop Pay is coming soon, and 1Password integration will let Muse use existing logins without exposing credentials.
The security architecture is the real story
Meta built a separate “Sentinel” agent that runs on the same virtual machine as Muse, kept apart at the system level. Nothing Muse does reaches the internet unless the Sentinel approves it. Muse itself never sees passwords or payment details. Those go into secure storage, and Muse uses them without reading them, even when a user types a password directly into a browser.
The privacy posture is notable:
- Muse conversations and VM data are not shared with Meta’s ad systems
- Users can opt out of interactions being used to train Meta’s models
- Users choose which apps Muse connects to and what level of access it gets
- A full audit trail shows everything Muse has done or plans to do
- Users can tell Muse to forget specific things it has learned
- Later this year, Muse Confidential VM will encrypt the entire VM with a key only the user holds, so Meta itself cannot access it
That last point matters. End-to-end encrypted AI agents where even the provider can’t read your data is a design goal that almost no one has shipped yet. If Meta delivers on it, that’s a meaningful differentiator.
Why this matters beyond the feature list
Agentic AI is the current battleground. OpenAI has Operator. Anthropic has computer use. Google has Mariner and a deep integration story through Workspace. But none of them have built a dedicated per-user virtual machine with a guardian agent sitting between the AI and the internet. That’s a real architectural choice, not a marketing bullet point.
The WhatsApp angle is also worth watching. Distributing a capable AI agent through an app that already has billions of active users means Meta doesn’t need to win an app download war. It just needs people to start a new chat.
Muse is free for most use cases and rolling out now in the US on iOS, Android, and muse.ai, with AI glasses support coming soon. Subscription plans will exist for heavier usage. So the pricing is accessible, the distribution is built-in, and the security story is stronger than anything comparable on the market right now. Whether the agent actually performs well in practice is the part no announcement can answer.




