News

Meta Launches Muse AI Agent, But Trust Questions Remain After $18B Settlement

Meta introduced Muse, a personal AI agent that can act on a user’s behalf. The company describes it as a step toward CEO Mark Zuckerberg’s vision of a “personal superintelligence” available to everyone. Not everyone trusts this vision though.

Meta Launches Muse AI Agent, But Trust Questions Remain After $18B Settlement

Introduced on September 8, Meta Muse can be linked to the company’s proprietary social media engines Facebook and Instagram, as well as other third-party services, e.g. WhatsApp, Gmail, and Spotify. 

Users can personalize their ‘Muse’ as they please, too. They might name their agent, give it an avatar, and adjust how it communicates with them.

According to Meta, once a person shares a goal with Muse, the agent develops a plan, coordinates time and resources needed to fulfill it, and then carries out the work on its own. It can open a browser, fill out forms, book travel, negotiate bills, etc. One notable feature is that the agent is always-on, i.e. it continues working after the app is closed, returning only when it needs approval for a sensitive step. Frankly, the latter is a function some people might find disturbing, given its safety setup and recent cases when other firms’ AI as well as Meta’s agent went a bit rogue and created serious cybersecurity incidents

Each Muse user gets a dedicated virtual machine in Meta’s cloud. In there, the company claims, the agent, its browser and connected credentials are isolated from the rest of the system. Meta AI chief Alexandr Wang said the setup means Muse “never sees your actual passwords or payment details,” while a separate internal “Sentinel” system reviews connector actions and network requests before they execute. 

At the same time, Meta separately advertises the upcoming function, Muse Confidential VM, “intended to cryptographically and verifiably prevent Meta from accessing data in your VM.” Hence, at least some of the data in a dedicated virtual machine are seen and potentially used by Meta. In fact, the company does say that current Muse architecture “does not prevent Meta from accessing data when necessary to support, secure or operate the service.” All those statements are quite vague to understand exactly which data can be accessed and how the tech giant would use it. Some of the comments under Alexandr Wang’s X post on the topic explicitly suggested that Meta might train its AI on user data. 

Muse runs on Muse Spark 1.3, a multimodal reasoning model built for long-running agentic tasks such as zero-shot tool calling and multi-step workflows across messy data sources. Meta says the model needs roughly 20% fewer tool calls and 25% fewer tokens than its predecessor, and is designed to resist prompt-injection attacks. Developers can access Muse Spark separately through Meta’s Model API, independent of the consumer app.

Muse itself is not yet available to all Facebook and Instagram users. The rollout is currently limited to people 18 and older in the United States, on iOS, Android and muse.ai, with a free tier and two paid subscription options priced at $20 and $100 a month depending on usage. Meta representatives said the free tier should cover most users’ needs.

The launch has raised some excitement in tech circles, but also questions that reveal grave trust issues. To use Muse, consumers effectively have to give Meta broader access to email, calendars, payment methods and other connected apps than any previous Meta product has required. Linking an AI agent this deeply into personal accounts widens the potential blast radius of any single security failure or misjudged action. Clearly, the product has been tested before launch, but there’s limited public track record for how the isolation and approval safeguards perform outside controlled demos.

Furthermore, public trust towards Meta is not in its best place right now. Muse arrived less than two weeks after Meta agreed to an $18 billion multistate settlement tied to social media’s harms to users. As separate US states’ youth-safety trials have earlier estimated potential penalties as high as $200 billion, as PaySpace Magazine reported, now a few states, including Florida, have refused to join the federal settlement and intend to continue litigating their individual cases independently. When one sees social media apparently designed to exploit engagement patterns in ways that might be harmful to users, who can trust the company to not employ similar tactics when a technology as powerful as AI is added to the stack?

Separately, we have previously covered internal Meta plans to revisit facial recognition in its smart glasses, another sign of the company’s appetite for identity-linked AI features even as its consent and data-handling practices remain under scrutiny. Together, these episodes suggest that Muse’s biggest adoption hurdle may not be technical capability but user willingness to hand Meta more control over their digital lives.

Nina Bobro

Nina Bobro

2201 Posts

https://payspacemagazine.com/author/nb/

Nina is passionate about financial technologies and environmental issues, reporting on the industry news and the most exciting projects that build their offerings around the intersection of fintech and sustainability.