Right now, Meta has launched Muse, a private AI agent that takes actions relatively than simply answering questions. Muse can ship emails, e book journey, negotiate payments, and pursue long run objectives. It retains working after you shut the app and returns solely when it wants approval. The larger story for AI devs is architectural. Every consumer will get a devoted cloud digital machine, known as Muse Safe VM, the place the agent, its browser, and all credentials stay in isolation. Is it deployable? Muse itself is a shopper service, rolling out now within the US on iOS, Android, and muse.ai, with a free tier and paid plans. Builders can’t self host Muse, however its underlying mannequin, Muse Spark 1.3, is obtainable at this time via Meta Mannequin API and Muse Code, with an open weights launch on Meta’s said roadmap.
What Muse Truly Does
Muse is constructed round messaging. Customers describe a process or a aim, and the agent plans and executes. It will probably open its browser, fill kinds, and negotiate on an individual’s behalf. Meta’s examples embrace promoting a automotive for extra, reducing a invoice, and adapting a coaching plan. Muse additionally remembers context throughout conversations. It will probably flip a saved Instagram recipe reel right into a grocery record and recall buddies’ dietary restrictions. Delicate steps, similar to sending an e mail or finishing a purchase order, all the time pause for consumer approval. A full audit path exhibits every little thing the agent has performed and plans to do.
The Mannequin: Muse Spark 1.3
Muse runs on Muse Spark 1.3, launched final week by Meta Superintelligence Labs. The mannequin targets lengthy horizon agentic work: zero shot CLI instrument calling, multi workflow threads, and self correction throughout messy sources. In inside comparisons by Meta engineers, it used roughly 20% fewer instrument calls and 25% fewer tokens than Muse Spark 1.2. Meta says the mannequin is near cutting-edge at resisting immediate injection. Builders can use it now in Muse Code and the Meta Mannequin API at dev.meta.ai.
Muse Safe VM and the Sentinel
The safety design is essentially the most technically fascinating a part of this launch. The agent harness runs inside a systemd-nspawn runtime cell with filtered syscalls and restricted kernel capabilities. Safety important companies sit outdoors that cell, on the identical VM. A separate Sentinel agent approves each connector motion and each community request, at each layer 4 and layer 7. Muse proposes; solely Sentinel permits. Credentials are dealt with via surrogation. The agent solely ever sees placeholder tokens, and Sentinel injects actual secrets and techniques on the community boundary. That makes credential exfiltration through immediate injection structurally futile, since there may be nothing actual to steal. Kernel stage eBPF taint monitoring distinguishes clear requests from those who touched consumer knowledge, gating approvals accordingly. The browser sub agent sees an accessibility tree, not the uncooked DOM, and can’t execute JavaScript. The e-mail connector even filters out one time passcodes and password reset hyperlinks by default.
Interactive Explainer: How 1 Muse Motion Will get Accepted
The embed under walks via the approval pipeline in 5 levels, in Meta’s blue theme. It consists of 2 eventualities: a standard buy and a blocked immediate injection try.









