Skip to content
Predictive Systems
PSI Daily

Meta’s Muse Wants Your Inbox

PrivacyRobert Voltaire L. Javier

Personal agents turn privacy from a policy page into a systems problem. Muse’s bet is isolation now, and cryptography later.

glass cube

On 8 September, Meta launched Muse in the United States. It is not only a chatbot. It is a personal agent that can email, book travel, shop, and connect to the apps people already use, including WhatsApp. The pitch is simple: tell Muse what you need, and it keeps working after you close the app. The hard part is trust. An agent that can act across real accounts turns privacy into a systems problem, not a checkbox.

A private computer for each user

Meta says every person gets a Muse Secure VM, a dedicated cloud computer where the agent and that person’s data live. A separate Sentinel process must approve network access and connector actions before anything leaves. Muse, Meta says, cannot see real passwords or payment methods. Credentials sit in secure storage and are injected only when needed. Sensitive steps such as sending mail or buying something need the user’s okay, and Muse shows an audit trail of what it has done and what it plans to do. People choose which apps to connect, can disconnect them, can opt out of training use, and can tell Muse to forget specifics. Meta also says Muse conversations and VM data are not shared with its ad systems, though browsing or bookings made through Muse can still shape ads elsewhere in the usual way.

The gap that still matters

That architecture is policy and isolation. Meta is clear that today’s Secure VM still lets the company access data when needed to run and secure the service. Later this year it plans Muse Confidential VM, where the whole machine is encrypted with a key only the user holds, so even Meta cannot open it. Until that ships, the strongest promise is still a promise. Reuters also reported that internal tests raised concerns about stalling and unauthorized exposure of sensitive data. Meta’s own safety write-up is frank that Muse will make mistakes and that prompt injection remains an open industry problem. The company is opening a bug bounty of up to $300,000 to pressure-test the system in public.

Bottom line

Muse is Meta’s bet that people will hand an agent their calendar and inbox if the wrapper looks serious enough. Secure VM plus Sentinel is a real design choice. Confidential VM is the harder standard. Until the second one ships, the fair question for any board or household is simple: are you comfortable with an agent that can act, while the operator can still unlock the room?

Sources

Source: Introducing Muse: The World’s First Personal AI Agent Built for Everyone