Your AI Is Getting Its Own Computer
One of the strangest things about Muse is what happens behind the scenes.
Meta gives each user's agent a dedicated virtual computer in the cloud called Muse Secure VM. It has its own browser and can continue working even after you've closed the Muse app.
Imagine asking it to plan a vacation and then going back to whatever you were doing. Muse can keep working through the task and return when something changes or when it needs your permission.
Meta says the system can remember details that matter to you, too.
Its example is surprisingly ordinary: save a recipe Reel on Instagram and Muse could turn it into a grocery list, plan a dinner menu and remember your friends' dietary restrictions when preparing invitations.
That's where this starts feeling less like a search engine and more like a digital assistant that has been given a desk, a computer and a to-do list.
Then You Hand It the Wallet
Muse can also shop.
Meta has integrated Stripe's Link payment system, allowing the agent to complete online purchases after the user approves the transaction.
For participating merchants, Link can use a customer's saved payment method. Elsewhere, it can generate a single-use virtual card specifically for the approved purchase.
That means Muse doesn't need to see the underlying card details.
Meta says the agent will stop and request permission before sensitive actions, including sending an email or making a purchase.
So Muse isn't supposed to quietly wake up at 3 a.m. and order you a television because you once said your living room looked empty.
You still get the final say.
The Bigger Question Is Trust
And that's where Meta's biggest challenge may begin.
An AI that recommends a hotel doesn't need much access.
One that books the room does.
An assistant capable of working across email, calendars, shopping and other connected services becomes far more useful—but the consequences of getting something wrong become considerably larger too.
Meta appears very aware of that problem.
Alongside the main Muse agent, its virtual machine contains a separate system called Sentinel. Meta says nothing Muse does reaches the internet unless Sentinel approves it, and the system can require the user to authorize an action.
Users choose which services Muse can access and can disconnect them later. Meta also says Muse can't see passwords or payment information stored through its protected credential system, and users can review an audit trail showing what the agent has done.
Later this year, Meta plans an even more locked-down Confidential VM option where conversations and data are encrypted using a key held by the user, which Meta says would prevent even Meta from accessing them.
Those are substantial promises for a product asking people to surrender something arguably more valuable than another piece of personal information:
permission to act.
This May Be the Real Beginning of the AI-Agent Race
Muse is initially rolling out in the United States on iOS, Android and the web, and people can also interact with it through WhatsApp. Meta says support for its AI glasses is coming soon.
Most usage will be free, while subscriptions will be available for people who want to automate more work.
But the most important part of today's announcement isn't another AI product appearing on another phone.
It's the changing job description.
Chatbots became popular because they could tell us what to do.
The next generation wants permission to do it for us.
Soon the question may no longer be, “Do you trust AI's answer?”
It may be:
Do you trust AI enough to press Send—and eventually Pay—on your behalf?
