Meta 发布个人 AI 智能体 Muse,可代发邮件、订旅行、议价账单并跟进长期目标,现已在美国 iOS、Android 和 muse.ai 推出,含免费档与付费档。
行业动态MarkTechPost(RSS)
今日 AI 情报摘要
Meta 发布个人 AI 智能体 Muse,可代发邮件、订旅行、议价账单并跟进长期目标,现已在美国 iOS、Android 和 muse.ai 推出,含免费档与付费档。
中文正文 · AI 翻译
今天,Meta 推出了 Muse:https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/,这是一款个人 AI 代理,它可以采取行动,而不仅仅是回答问题。Muse 可以发送电子邮件、预订旅行、协商账单,并追求长期目标。即使在你关闭应用后,它也会继续工作,只有在需要批准时才会返回。对于 AI 开发者来说,更重要的消息是其架构。每个用户都拥有一个专用的云虚拟机,称为 Muse Secure VM:https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse,代理、浏览器和所有凭证都在隔离环境中运行。它可部署吗?Muse 本身是一个面向消费者的服务,目前在美国的 iOS、Android 和 muse.ai:https://muse.ai/ 上推出,提供免费套餐和付费计划。开发者不能自行托管 Muse,但其底层模型 Muse Spark 1.3 已通过 Meta Model API 和 Muse Code 提供,并且 Meta 已在其路线图上宣布将开放权重发布。
下面的嵌入内容展示了 Meta 蓝色主题下的 5 个阶段审批流程。它包括 2 个场景:正常购买和被阻止的提示注入尝试。
需要与我们合作以推广您的 GitHub 仓库、Hugging Face 页面、产品发布或网络研讨会等?请与我们联系:https://forms.gle/wbash1wF6efRj8G58
Michal Sutter 是一名数据科学专业人士,拥有帕多瓦大学的数据科学硕士学位。凭借在统计分析、机器学习和数据工程方面的坚实基础,Michal 擅长将复杂的数据集转化为可操作的洞察。
实践者优先的 AI/ML 新闻与分析,每月有超过 100 万开发者和研究人员阅读。
Today, Meta has introduced Muse:https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/, a personal AI agent that takes actions rather than just answering questions. Muse can send emails, book travel, negotiate bills, and pursue long term goals. It keeps working after you close the app and returns only when it needs approval. The bigger story for AI devs is architectural. Each user gets a dedicated cloud virtual machine, called Muse Secure VM:https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse, where the agent, its browser, and all credentials live in isolation. Is it deployable? Muse itself is a consumer service, rolling out now in the US on iOS, Android, and muse.ai:https://muse.ai/, with a free tier and paid plans. Developers cannot self host Muse, but its underlying model, Muse Spark 1.3, is available today through Meta Model API and Muse Code, with an open weights release on Meta’s stated roadmap.
Muse is built around messaging. Users describe a task or a goal, and the agent plans and executes. It can open its browser, fill forms, and negotiate on a person’s behalf. Meta’s examples include selling a car for more, lowering a bill, and adapting a training plan. Muse also remembers context across conversations. It can turn a saved Instagram recipe reel into a grocery list and recall friends’ dietary restrictions. Sensitive steps, such as sending an email or completing a purchase, always pause for user approval. A full audit trail shows everything the agent has done and plans to do.
Muse runs on Muse Spark 1.3:https://research.meta.ai/blog/introducing-muse-spark-1-3, released last week by Meta Superintelligence Labs. The model targets long horizon agentic work: zero shot CLI tool calling, multi workflow threads, and self correction across messy sources. In internal comparisons by Meta engineers, it used roughly 20% fewer tool calls and 25% fewer tokens than Muse Spark 1.2. Meta says the model is close to state of the art at resisting prompt injection. Developers can use it now in Muse Code and the Meta Model API at dev.meta.ai:https://dev.meta.ai/.
The security design is the most technically interesting part of this launch. The agent harness runs inside a systemd-nspawn runtime cell with filtered syscalls and limited kernel capabilities. Security critical services sit outside that cell, on the same VM. A separate Sentinel agent approves every connector action and every network request, at both layer 4 and layer 7. Muse proposes; only Sentinel permits. Credentials are handled through surrogation. The agent only ever sees placeholder tokens, and Sentinel injects real secrets at the network boundary. That makes credential exfiltration via prompt injection structurally futile, since there is nothing real to steal. Kernel level eBPF taint tracking distinguishes clean requests from those that touched user data, gating approvals accordingly. The browser sub agent sees an accessibility tree, not the raw DOM, and cannot execute JavaScript. The email connector even filters out one time passcodes and password reset links by default.
The embed below walks through the approval pipeline in 5 stages, in Meta’s blue theme. It includes 2 scenarios: a normal purchase and a blocked prompt injection attempt.
Need to partner with us for promoting your GitHub Repo OR Hugging Face Page OR Product Release OR Webinar etc.? Connect with us :https://forms.gle/wbash1wF6efRj8G58
Michal Sutter is a data science professional with a Master of Science in Data Science from the University of Padova. With a solid foundation in statistical analysis, machine learning, and data engineering, Michal excels at transforming complex datasets into actionable insights.
Practitioner-first AI/ML news and analysis, read by 1M+ developers and researchers every month.
情报判断
Aioga 编辑摘要
Meta 发布个人 AI 智能体 Muse,主打代用户执行任务,而不仅是回答问题。来源称,Muse 可发送邮件、预订旅行、协商账单并推进长期目标,已在美国面向 iOS、Android 和 muse.ai 推出,提供免费档与付费档。
可能影响:个人智能体从对话走向代办时,用户审批、凭证保护和操作追踪会成为重要评估项。需要注意,来源所述安全设计和模型对比主要是 Meta 的公开说明,不足以单独证明所有真实场景都能达到相同效果,也不代表用户可自行部署完整服务。 后续观察:应关注 Muse 在美国推出后的实际可用范围、审批流程和审计记录表现,以及 Muse Spark 1.3 通过 Meta Model API、Muse Code 和开放权重路线提供的具体进展。