Today, Meta has introduced Muse:https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/, a personal AI agent that takes actions rather than just answering questions. Muse can send emails, book travel, negotiate bills, and pursue long term goals. It keeps working after you close the app and returns only when it needs approval. The bigger story for AI devs is architectural. Each user gets a dedicated cloud virtual machine, called Muse Secure VM:https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse, where the agent, its browser, and all credentials live in isolation. Is it deployable? Muse itself is a consumer service, rolling out now in the US on iOS, Android, and muse.ai:https://muse.ai/, with a free tier and paid plans. Developers cannot self host Muse, but its underlying model, Muse Spark 1.3, is available today through Meta Model API and Muse Code, with an open weights release on Meta’s stated roadmap.

Muse is built around messaging. Users describe a task or a goal, and the agent plans and executes. It can open its browser, fill forms, and negotiate on a person’s behalf. Meta’s examples include selling a car for more, lowering a bill, and adapting a training plan. Muse also remembers context across conversations. It can turn a saved Instagram recipe reel into a grocery list and recall friends’ dietary restrictions. Sensitive steps, such as sending an email or completing a purchase, always pause for user approval. A full audit trail shows everything the agent has done and plans to do.

Muse runs on Muse Spark 1.3:https://research.meta.ai/blog/introducing-muse-spark-1-3, released last week by Meta Superintelligence Labs. The model targets long horizon agentic work: zero shot CLI tool calling, multi workflow threads, and self correction across messy sources. In internal comparisons by Meta engineers, it used roughly 20% fewer tool calls and 25% fewer tokens than Muse Spark 1.2. Meta says the model is close to state of the art at resisting prompt injection. Developers can use it now in Muse Code and the Meta Model API at dev.meta.ai:https://dev.meta.ai/.

The security design is the most technically interesting part of this launch. The agent harness runs inside a systemd-nspawn runtime cell with filtered syscalls and limited kernel capabilities. Security critical services sit outside that cell, on the same VM. A separate Sentinel agent approves every connector action and every network request, at both layer 4 and layer 7. Muse proposes; only Sentinel permits. Credentials are handled through surrogation. The agent only ever sees placeholder tokens, and Sentinel injects real secrets at the network boundary. That makes credential exfiltration via prompt injection structurally futile, since there is nothing real to steal. Kernel level eBPF taint tracking distinguishes clean requests from those that touched user data, gating approvals accordingly. The browser sub agent sees an accessibility tree, not the raw DOM, and cannot execute JavaScript. The email connector even filters out one time passcodes and password reset links by default.

The embed below walks through the approval pipeline in 5 stages, in Meta’s blue theme. It includes 2 scenarios: a normal purchase and a blocked prompt injection attempt.

Need to partner with us for promoting your GitHub Repo OR Hugging Face Page OR Product Release OR Webinar etc.? Connect with us :https://forms.gle/wbash1wF6efRj8G58

Meta phát hành intelligent agent cá nhân Muse, chạy trên máy ảo đám mây riêng Muse Secure VM

Michal Sutter is a data science professional with a Master of Science in Data Science from the University of Padova. With a solid foundation in statistical analysis, machine learning, and data engineering, Michal excels at transforming complex datasets into actionable insights.

Axis Robotics Releases AXIS: A Browser-Based Data Engine With 207 Robot Manipulation Tasks and 50,129 Trajectories

Practitioner-first AI/ML news and analysis, read by 1M+ developers and researchers every month.