Meta launches Muse, a personal AI agent for iOS, Android, web and WhatsApp, with a security-focused 'Secure VM' architecture and Stripe-powered purchasing
Meta released Muse, a personal AI agent (from Meta Superintelligence Labs, previously tested internally as 'Hatch'), rolling out via a dedicated iOS/Android app, Muse.ai website, and WhatsApp messaging, with AI glasses support coming soon. It can perform tasks like emailing, booking travel, and making purchases using Stripe's Link single-use card payment infrastructure. It launches with a 'Secure VM' architecture isolating user activity and a 'Sentinel' system that flags actions for human approval; a future 'Confidential VM' (with Moxie Marlinspike) will let users hold their own access keys. Meta also expanded its public bug bounty to cover Muse, with payouts up to $300,000 (up to $130,000 for single-user prompt injection attacks). Free to try, with paid AI subscription plans required for heavy use.
Entities: Meta, Muse, Meta Superintelligence Labs, Mark Zuckerberg, David Singleton, Stripe
0 primary
What happened
Meta launched Muse, a personal AI agent available via a dedicated iOS/Android app, a Muse.ai website, and WhatsApp, with AI glasses support promised later. It was previously tested internally as "Hatch" under Meta Superintelligence Labs. Muse can perform tasks like sending emails, booking travel, and making purchases through Stripe's Link single-use card system, and Meta paired the launch with a "Secure VM" isolation architecture, a "Sentinel" approval-flagging system, and an expanded bug bounty (up to $300,000, including $130,000 for single-user prompt injection exploits).
Why it matters
This is Meta's entry into agentic commerce at consumer scale, using WhatsApp's existing reach rather than requiring a new install base, which matters far more than the app itself. If Muse can reliably execute purchases and bookings, it puts Meta directly in competition with OpenAI and Anthropic on agent capability, and with Stripe's own agentic-payments push on the commerce side. The security architecture (Secure VM, Sentinel, bug bounty) signals that Meta expects prompt injection and unauthorized transactions to be the real adoption blocker, not the AI capability itself.
What is noise
The privacy and security framing is largely a promise, not a delivered feature: the "Confidential VM" with user-held keys and third-party audits, the part that would actually change the trust calculus, does not exist yet and has no timeline. Coverage leaning on the Wired headline ("needs you to trust it") frames this as a trust milestone when it is really a beta security posture with a bug bounty as backstop. No pricing details were disclosed beyond "free to try, paid plans for heavy use," which limits any real read on adoption economics.
Watch next
- 01Whether the Confidential VM with user-held keys ships within 2026, or stays vaguely promised
- 02Bug bounty payout activity: any disclosed $100k+ prompt injection findings in the first 90 days would validate real risk exposure
- 03Actual usage/transaction volume through Stripe Link via Muse, reported by either Meta or Stripe, as a proxy for real adoption versus press-cycle interest
Coverage
1 storyMore capability signals
Full feed →- AI systems outperform expert humans in persuasive communication22 Jun 202681
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680
- Google DeepMind launches AlphaGenome Atlas, a free public database of predicted effects for 9 billion possible human genome variants8 Sept 202679
- Hcompany open-sources NeoMME, a from-scratch multimodal-native encoder family, and NeoMME-Retriever for visual document retrieval3 Sept 202679