Meta launches Muse, a WhatsApp-controlled AI agent that browses, shops and pays via Stripe Link
Meta launched Muse, an autonomous AI agent accessible via WhatsApp that runs in an isolated cloud virtual machine ("Muse Secure VM") overseen by a separate "Sentinel" agent. It can browse the web, fill out forms, negotiate on the user's behalf, and complete purchases after user approval using one-time virtual cards via Stripe's Link payment service. It launches first in the US on iOS and Android, with free usage limits and paid subscription tiers; a link to Meta's AI glasses and a "Muse Confidential VM" (full VM encryption) are planned for later.
Entities: Meta, Muse, WhatsApp, Stripe, Stripe Link, Sentinel
0 primary
What happened
Meta launched Muse, an AI agent controlled through WhatsApp that can browse the web, fill in forms, negotiate, and complete purchases with user approval. Purchases use one-time virtual cards via Stripe Link, and the agent runs in an isolated cloud VM ("Muse Secure VM") supervised by a separate "Sentinel" agent. It launches first in the US on iOS and Android with a free tier and paid subscription options; a fully encrypted "Confidential VM" and integration with Meta's AI glasses are planned but not yet shipped.
Why it matters
This puts agentic checkout in front of WhatsApp's userbase, which dwarfs any single AI chat app, at the exact moment OpenAI pulled back from in-chat checkout in ChatGPT. If it works reliably, it gives Meta a foothold in commerce and payments flows that previously ran through browsers or merchant apps, which matters to retailers, payment processors and competitors like Perplexity. For now the real-world impact is mostly potential: no user numbers, transaction volumes, or error rates have been published, so it is too early to say how many people will actually trust an AI agent with a payment card.
What is noise
Almost every substantive claim here is Meta's own framing, not independently verified: "personal superintelligence" is marketing language, and the comparison to OpenAI's checkout retreat is a self-serving contrast dressed up as an industry milestone. Several named features, including the Confidential VM, glasses integration, Shop Pay and 1Password support, are not live yet. The security architecture is unproven against the same prompt-injection risks the source article itself flags for Perplexity's Comet, so "isolated" and "protected" should be read as claims, not tested facts.
Watch next
- 01First independent security researcher writeups or red-team results on Muse Secure VM and Sentinel, specifically whether prompt injection can trigger unauthorised purchases
- 02Actual US adoption numbers or Meta-reported transaction volume within the first 60-90 days, not just feature announcements
- 03Whether the promised Confidential VM, AI glasses integration, Shop Pay and 1Password support ship on a stated timeline or quietly slip
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- AI systems outperform expert humans in persuasive communication22 Jun 202681
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680
- Google DeepMind launches AlphaGenome Atlas, a free public database of predicted effects for 9 billion possible human genome variants8 Sept 202679