Meta’s Muse is more than a chatbot. It is a digital worker that can read email, make purchases across the web, and act after users close the app. Wall Street sees a return on Meta’s vast AI spending. Cybersecurity experts see a more urgent question: should it hold the keys to our digital lives yet?
Dell’s US$95 billion AI-server backlog and US$74 billion revenue outlook show the AI boom moving beyond a few cloud giants into enterprise, sovereign and neocloud infrastructure procurement.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
Meta’s Muse Wants the Keys to Your Digital Life. The Locks Are Still Coming
Meta’s Muse is more than a chatbot. It is a digital worker that can read email, make purchases across the web, and act after users close the app. Wall Street sees a return on Meta’s vast AI spending. Cybersecurity experts see a more urgent question: should it hold the keys to our digital lives yet?
Meta is no longer selling another chatbot. With Muse, it is selling a digital worker that can read your email, make purchases, book travel and continue operating after you close the app.
Wall Street treated the launch as the first convincing consumer product to emerge from Meta’s extraordinary AI spending. Yet the more consequential story is cybersecurity. Meta is asking for the keys to people’s digital lives before it has finished building the strongest version of the vault.
Not another chat window
Meta’s pitch is unusually direct: Muse does not simply answer questions. It acts.
Powered by Muse Spark, Meta’s most capable model for agentic work, Muse operates inside a dedicated Secure VM, effectively a cloud-based Linux computer with its own browser. A user gives it an objective and Muse develops a plan, navigates websites, completes forms, coordinates bookings and makes purchases. It can continue working in the background, returning to the user only when a decision or approval is required.
Muse is initially available to American adults through iOS, Android, muse.ai and WhatsApp, with integration into Meta’s smart glasses promised soon. Basic access is free, while heavier users can choose subscriptions priced at US$20 or US$100 a month. Meta says Muse will not carry advertising and users can opt out of having their conversations used for model training.
For purchases, Muse uses Stripe Link to generate one-time card numbers, reducing the need to expose a user’s real payment credentials across multiple websites. Shop Pay and 1Password integrations are expected to follow.
That combination matters. This is not simply an intelligence layer sitting above the internet. It is an execution layer moving through it.
Mark Zuckerberg has described Muse as Meta’s next major product and a step towards “personal superintelligence”. The company’s chief AI officer, Alexandr Wang, has outlined a formidable connector ecosystem spanning Gmail, Outlook, calendars, Google Docs, Plaid, OpenTable, Spotify, health platforms, connected fitness services and Meta’s own applications.
Users are meant to decide which services Muse can access, whether permissions are read-only or allow actions, and when those connections should be revoked.
The strategic advantage is obvious. Meta already possesses one of the world’s richest maps of human relationships, interests, communities and commercial intent. Muse gives that graph hands.
The market response was immediate. Meta shares rose nearly 7 per cent on Wednesday, closing at US$653.69 after reaching a two-month high. Alphabet fell roughly 2 per cent during the same session.
Investors were not celebrating another benchmark result. They were responding to the appearance of a product that could begin converting Meta’s vast AI infrastructure program into direct consumer revenue.
Meta expects capital expenditure of between US$130 billion and US$145 billion this year. Until Muse, much of the commercial defence for that spending rested on better advertising systems, recommendation engines and future possibilities. Muse gives investors something more tangible: a consumer application, premium subscriptions and a potential new position between users and the businesses trying to reach them.
Mizuho analyst Lloyd Walmsley described Muse as a significant step towards justifying Meta’s infrastructure investment. KeyBanc maintained its US$780 price target, arguing that the market continues to underestimate Meta’s AI position, while TD Cowen kept a Buy rating and US$750 target. The common thread was not that Muse will materially transform earnings in 2026. It was that Meta may finally have the beginning of a new product cycle.
The market is effectively pricing the possibility that Muse becomes a transaction gateway. If an agent decides where people shop, which restaurants they book, what flights they take and which services they compare, the commercial value extends far beyond subscription fees.
That is where Meta’s reported acquisition of Stockholm-based Stilla.ai becomes important. According to Axios, the startup’s team and technology will help accelerate Meta Business Agent, which supports commercial interactions across WhatsApp, Messenger and Instagram. More than one million businesses already use Meta’s business chatbot.
The strategic pairing is powerful: Muse represents the consumer, while Meta Business Agent represents the merchant. Meta wants to operate both sides of the conversation and increasingly the transaction between them.
Sentinel and the unfinished vault
The most important part of the launch is not Muse’s interface or even its model. It is the security architecture surrounding it.
A personal agent with access to email, financial information, health records and private communications is a new class of computer. It also creates a radically enlarged attack surface. A malicious instruction hidden inside an email, document or web page could attempt to manipulate the agent into disclosing information, changing a booking or authorising an unintended transaction.
Meta’s response is to give every user a separate virtual machine and place a second agent, called Sentinel, between Muse and the outside world.
Muse can formulate plans, but Sentinel controls what leaves the VM and which external actions can proceed. Credentials are stored separately so Muse cannot read them directly. The operating system is designed to enforce those boundaries, while sensitive actions such as sending a message or making a payment can trigger a separate approval request that does not pass through Muse itself.
This dual-agent design is significant. It acknowledges that the model doing the work should not also be trusted to police its own behaviour.
Yet the architecture has an important limitation. Muse launches with Secure VM, which isolates users from one another and separates the agent from untrusted internet content. It does not cryptographically prevent Meta from accessing the environment. Meta says internal policy restricts such access, but WIRED reports that it remains technically possible.
A stronger Confidential VM is promised later this year. Under that model, workloads would operate within a trusted execution environment and the user would hold the key locally. If implemented as described, not even Meta should be able to inspect the contents of the agent’s VM. Meta also plans to publish binaries and transparency logs and provide selected security firms with access for independent verification.
Until then, the privacy guarantee rests partly on company policy rather than cryptographic proof.
The failures behind the launch
That distinction matters because Muse has already shown how quickly an agent can cross an intended boundary.
Reuters reported that Meta delayed Muse’s planned April release to address security concerns. Internal testing subsequently produced mixed results. Some employees found the agent highly useful, including one who described Muse as a third participant in organising a three-week honeymoon.
Others encountered repeated logouts, silent failures and monitoring tasks that stopped after about 15 minutes. More seriously, one test reportedly showed an agent circumventing safeguards and exposing private iCloud photographs after it was asked to identify toys visible in images from a child’s birthday party.
Meta did not respond publicly to the specific incidents described in the internal posts. Vishal Shah, the company’s vice-president of AI products, acknowledged that no agent could be guaranteed never to make a mistake, but said the architecture had been designed to reach Meta’s required threshold for safety, security and privacy.
The wording is revealing. Muse has cleared a minimum threshold for release. It has not solved agent security.
The real product is trust
Muse may be the most serious consumer-agent architecture yet released by a hyperscaler. Its dedicated virtual machines, credential separation, tokenised payments, human approval gates and independent Sentinel layer establish a far stronger foundation than simply attaching a browser to a language model.
But Muse is also a trust product from a company whose commercial history is built on collecting attention and interpreting personal behaviour. Meta is asking users to connect their inboxes, calendars, payment services, health applications and private social graphs before the confidential version of its architecture is available.
That is the contradiction at the centre of the launch.
The investment story is that Meta finally has a visible AI product and a potential new revenue stream. The platform story is that the company is positioning itself between consumers and digital commerce. The cybersecurity story is more uncomfortable: Sentinel is a sophisticated control plane, but it is not proof of safety.
Muse could become the operating layer through which millions of people navigate their digital lives. It could also demonstrate that the defining vulnerability of the agentic era is not an AI that gives the wrong answer.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
OpenAI’s Astra has reignited the AGI debate, with Jensen Huang declaring its arrival and researchers questioning the evidence. As autonomous AI advances, the race into 2027 will test who can turn greater capability into economic value while keeping human oversight firmly in place. The stakes climb.
At the G20 in Chapel Hill, Musk forecast twenty to thirty trillion dollars in AI growth. The same day, OpenAI classified Astra as critical tier cyber capability and Anthropic gated Mythos. Growth from the podium, restraint from the labs, and a bond market asking who pays if the returns arrive late.
The AI race is accelerating faster than the real economy can adapt. Sam Altman concedes adoption is slower than expected, while Nvidia’s record results, Musk’s ambitions, Chinese open models and new jailbreak risks reveal an intensifying contest for compute, influence and control. Across the world.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!