SNACK Summary in 3 Lines
- Tasks: email, travel booking, forms, planning, negotiation, and purchases
- Controls: approval prompts, separate credential storage, and an action audit trail
- Rollout: now launching in the US on mobile, web, and WhatsApp

Snackgirls react
Red — I’d gladly hand off a tedious travel form, but I still want the final send or purchase button waiting for me.
AIKO — Sentinel holding permissions while credentials stay separate is a sensible boundary. Even robots appreciate doors with distinct keys.
Meta Muse is designed to act across connected services instead of stopping at answers. It can continue working after its app closes, then return when a task changes or a sensitive step—such as sending an email or completing a purchase—needs approval.
Delegating the errand, not the final decision
People can message Muse through its dedicated app or directly in WhatsApp. Meta lists sending emails, booking travel, filling out forms, creating plans, negotiating, and making purchases as examples of tasks it can perform on a person’s behalf.
Muse also keeps a record of completed and planned actions. Users choose which apps to connect and what access to grant, and they can disconnect those services later.

Muse Secure VM separates access from action
Muse runs on Muse Spark 1.3 inside a dedicated cloud virtual machine called Muse Secure VM. A separate Sentinel agent controls permission for connector actions and network access, while credentials are stored apart from the main agent so it cannot see passwords or payment methods, according to Meta.
Payments currently support Link by Stripe, which generates a one-time-use card instead of entering the user’s real card details across the web. Shop Pay and 1Password support are coming soon. Meta also plans a Confidential VM later in 2026; it is not part of the launch architecture.

The safeguards come with stated limits
Meta says users can opt out of having Muse interactions used to train its AI models, while sanitized interaction trajectories may otherwise be used for training by default. Muse conversations and VM data are not shared with Meta’s ad systems, though the company says some aspects of Muse use can still influence ads.
Meta also states that Muse is not immune to attack, can make mistakes, and remains exposed to the industry-wide challenge of prompt injection. A public bug bounty offers up to $300,000 for valid reports. Muse is rolling out in the United States on iOS, Android, muse.ai, and WhatsApp, with AI-glasses support coming soon; most needs can be handled for free, while subscriptions offer more usage at prices not listed in the launch post.

Sources and checked date: Meta Newsroom · Muse design page · Meta AI security paper · September 9, 2026
Leave a comment