Meta introduced Muse on September 8, a personal AI agent it says can book travel, send email and negotiate purchases inside a person’s own accounts, according to the company’s newsroom announcement. Muse ships now in the United States on iOS, Android and muse.ai, running on Muse Spark, Meta’s newest model built for this kind of task execution, which puts an acting agent on consumer phones at a scale no developer-facing coding tool has reached. Meta calls it “the world’s first personal AI agent built for everyone,” a promotional superlative worth noting once and setting aside, because the substantive question is what happens once the agent starts acting.
Execution happens in what Meta calls a Muse Secure VM, a walled-off cloud instance which is also where credentials live for whatever accounts someone links. According to Meta, a distinct process called Sentinel operates on that same machine, kept separate from Muse at the software layer, and nothing Muse does reaches the open internet without Sentinel’s clearance. That split is the part of this launch worth taking seriously. Instead of asking one model to both take an action and judge whether that action is safe, Meta has assigned the job to two systems, one that acts and one built only to review.
What Meta has not published is how Sentinel makes that call, how often it lets through something it should have blocked, or what happens procedurally when Sentinel and Muse disagree about a step. Before anything consequential, a purchase going through or a message going out, Meta says the agent stops and asks, and it keeps a visible record of both completed and intended steps. Those are Meta’s own claims about its own system. No outside researcher has published an audit of the Sentinel boundary, and until one does, the design should be read as Meta’s stated architecture rather than a proven guarantee.
A gap also separates what ships today from what Meta is promising. The company says a second offering, Muse Confidential VM, will arrive later this year: the entire virtual machine, including stored conversations, sealed with a key only the person controls, so that Meta itself could not read it. The version launching now does not have that layer. Anyone weighing the privacy claims in this announcement should keep the current Secure VM, which stores data in Meta’s cloud under Meta’s own protections, distinct from the confidential-computing version that does not exist yet.
Payment is where the stakes of “acting” agent become concrete. Muse can check out using a one-time virtual card issued through Stripe’s Link service, with support for Shop Pay and saved 1Password logins described as arriving soon. That is meaningfully different from a chatbot that drafts a suggestion: it is software authorized to fill out forms, hold saved logins and complete purchases on hundreds of millions of ordinary phones, not developer sandboxes. An agent with that kind of standing access is holding real credentials on a consumer device, which changes the question from whether the isolation architecture is well built to who is liable when an agent, acting inside an account its user authorized, gets something wrong: an unwanted refund accepted, an email sent to the wrong person, a purchase completed past the confirmation step Meta says it requires.
Operators watching this space have two concrete things to track over the next ninety days: whether Meta or an independent group publishes any external review of the Sentinel boundary, and how Meta assigns responsibility once the first disputed transaction from an acting agent becomes public. Consumer-facing agent products from other large platforms will likely copy this supervisor pattern regardless of whether Meta’s version holds up, so the terms Meta sets now for liability and audit access are worth reading closely before they become the industry default.
Meta announced Muse in a company newsroom post published September 8, 2026.