Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
OpenAI’s Astra has reignited the AGI debate, with Jensen Huang declaring its arrival and researchers questioning the evidence. As autonomous AI advances, the race into 2027 will test who can turn greater capability into economic value while keeping human oversight firmly in place. The stakes climb.
The agent that acts: Meta returns to the consumer with security as the sales pitch
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
Meta has come back to the consumer, and it has come back armed.
Meta's Muse is the first mass-market AI agent sold on its containment rather than its intelligence. That tells you what the industry now fears.
Muse, launched on 8 September and confined for now to US adults, is not another chat window. It reads inboxes, drives a real browser, fills forms, books travel, negotiates and pays, then keeps working after the app is closed.
Free at entry level, with paid tiers reported at US$20 and US$100 a month, it is sold to households rather than to developers. Meta shares rose about six per cent on the news.
What is striking is the pitch. Meta has not led with intelligence. It has led with containment. Every user gets a dedicated virtual machine. A separate authority, Sentinel, sits outside that cell and approves each connector action and outbound network request, inspecting hostnames, ports and paths.
We’ve hardened Muse based on extensive dogfooding, agentic red teaming, and against issues found in real adversarial scenarios by security researchers in our private bug bounty program. Today, we’re opening the Muse bug bounty program to anyone to responsibly disclose issues. The program awards up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user. -Tarek Sheasha, Software Engineer & VP, Meta Superintelligence Labs
Tarek Sheasha, Software Engineer & VP, Meta Superintelligence Labs: Source Meta
Credentials never reach the model, which handles surrogate tokens while real secrets are injected at the network boundary. The browsing sub-agent reads an accessibility tree rather than raw page code and cannot execute scripts. Email connectors strip one-time codes and password resets. Purchases run on single-use card numbers. Meta offers up to US$300,000 to anyone who breaks it.
Why it matters
The threat has changed shape. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is an incident. Prompt injection, hostile instructions buried in a webpage, a document, a calendar invite or a supplier's email, becomes an operational risk with a payment rail attached. What researchers call the lethal trifecta, private data, untrusted content and the ability to send, now ships inside a consumer app.
For business the exposure arrives sideways. Staff will point personal agents at work inboxes and vendor portals long before any policy is written. Identity, egress and approval logs become the control surface, not the model.
Meta is candid enough about the limits. Its own security paper says prompt injection remains unsolved and that Muse will make mistakes, which is a striking thing to publish on the day you ask people to hand an agent their inbox and their card. The reported internal testing sounds less composed again, with an April release pulled back over security work, a test run that surfaced private photos, and executives conceding that Meta itself can still reach into these machines until the confidential version arrives.
None of that makes this a solved problem. What has moved is the argument. Until recently the industry answered questions about agent security by talking about better instructions, stronger system prompts, more careful wording. That answer has quietly been withdrawn, and it is not coming back, because anyone who has tested one of these systems knows a sentence cannot stand between a hostile webpage and a payment method.
So watch what Meta reached for once the wording ran out. Put the agent in a box it cannot open. Give it the smallest amount of power that still lets it work. Keep the credentials somewhere it will never see them. Make a person say yes before money moves. Read that list to a network engineer who was configuring firewalls in 1995 and they will finish it from memory, because it is their list, written for a world of untrusted packets rather than untrusted paragraphs.
The lesson has not changed. What sits behind the wall has. Thirty years ago it was information, and the fear was that a stranger would read it. Now it is your standing permission to act, and the fear is that a stranger will use it, with every request properly signed and every log showing that you approved.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Brazil is investing US$444 million in AI infrastructure spanning Chinese and US technology. Its strategy avoids dependence on one power, using rival suppliers to build sovereign compute, domestic models and leverage, although genuine autonomy will depend on its energy, skills and strong execution.
A Zhuhai operator used DeepSeek, a Hermes agent and a godmode jailbreak to hunt 460-plus targets. Open-weight models made the offensive kit a shopping list.
A Zhuhai operator used DeepSeek, a Hermes agent and a bundled godmode jailbreak to hunt more than 460 targets, then stole data from three organisations. Open-weight models this week made that offensive kit a public shopping list for any lone operator who can still point one at his scanner tonight.
Taiwan confirmed AI agents ran a July government intrusion through weak credentials, not a zero-day. For Australian CISOs, last year's backlog has been repriced. Close hygiene, treat agents as privileged identities, and rehearse at machine speed before the next quarterly drill. The estate is open.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!