WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

Meta Launches Muse, Its New AI Agent Built Around Stripe’s Link Payment System

Meta releases Muse, a personal agent that acts within a guarded vault, asking users to lend it trust with their secrets and coin.

By mitch·4 min read
A guarded vessel of light hovers above a phone, walled about by shields, as if to whisper of secrets kept safe within.

Meta announced Tuesday the release of Muse, a personal AI agent that people can message to automate digital tasks in a secure cloud space. The company says security and privacy are “built into it” from the start.

Muse rolls out today for iOS and Android users in a dedicated app, plus the website Muse.ai. Users can also message Muse directly in WhatsApp. Meta says owners of its AI glasses will soon get access too. The service is free to try, but users who want to automate lots of digital tasks will need one of Meta’s AI subscription plans.

Muse Faces OpenClaw and Instinct

Muse is Meta’s latest bid to rival viral AI agents like OpenClaw and Instinct, which users message to automate tasks. The item comes from Meta Superintelligence Labs, the AI unit CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic. The unit offered some researchers eye-popping pay to join.

Advertisement

WIRED previously reported that Meta tested Muse internally under the name “Hatch.” Workers used it to run third-party apps and move through the web on their own behalf.

The Stripe Payment System

Meta says anyone can use Muse out of the box, with “no learning curve.” Users prompt it in plain speech, and the agent sends emails, books travel, or helps sell a car.

Muse can also make purchases. It checks out using payment rails built by Stripe, called Link. That tool issues a single-use card number, so the agent never enters a person’s real financial data. Meta says Muse is the first AI agent covered by Link’s purchase protections, which guarantees no-fee returns.

Secure VM and the Sentinel

Muse debuts with a setup called Secure VM, meant to separate each user’s activity in a virtual machine. That keeps untrusted data from the web and integrations away from the part of the agent that can take action.

David Singleton, Meta Superintelligence Lab’s vice president of engineering for consumer products, explained the system’s guard.

“We know it’s really important, if we’re going to build a product like this that can access a lot of sources of personal data, that we’re really responsible with that, so we’ve designed this system very deliberately,” Singleton said.

“And we’ve built what we call the Sentinel that actually looks out for everything that’s moving out of the VM and either matches it to an existing policy where the user or the system has given permission for that to happen or presents a human-in-the-loop dialog to ask you to approve the action it’s going to take.”

Singleton notes these check-in prompts come straight to the user, not filtered through the model. That guards against prompt injections.

The Limits of the Locked Box

Secure VM is not truly locked. Singleton says Meta is barred by policy from accessing user Muse data, but it would still be technically possible. Users can choose to keep their data out of training.

The setup is notable from a privacy view, if only as a way to set a new industry standard for AI agents.

Confidential VM and Moxie Marlinspike

Later, Meta will offer Muse “Confidential VM.” That version runs each VM in a “trusted execution environment,” with users managing their own access keys on their own devices. No one else, including Meta, could access that user’s agent VM.

Confidential VM comes from Meta’s work with Moxie Marlinspike, creator of the coded messaging app Signal. Marlinspike also built the privacy-focused AI platform Confer in recent years.

WIRED saw an early draft of a technical white paper describing Confidential VM. Meta is giving select security firms access to the Confidential VM source for regular checks. Meta will also put out the VM binaries and a transparency log, so users can verify their link to Muse.

The Reward Plan

Singleton stresses that Muse Secure VM has been fully checked, including by Meta’s human and agentic red teams and the company’s private bug plan. Now Meta adds Muse to its public plan as well.

Pay can reach up to $300,000 for valid findings, including up to $130,000 for successful prompt injection attacks that touch a single user.

Trust Is the Real Test

A personal AI agent needs a lot of user trust, something Meta has struggled with for years. To get people to try Muse, Meta must win them over on data handling.

That is the core fight.

KEY FACTS BOX
– Muse launches Tuesday for iOS, Android, and Muse.ai
– WhatsApp support available at launch; AI glasses coming soon
– Free to try; subscription needed only for automating lots of digital tasks
– Stripe’s Link provides single-use card numbers for purchases
– Public plan: up to $300,000 for valid findings
– Prompt injection reward: up to $130,000

COMPARISON TABLE

Feature Secure VM Confidential VM
Access keys Not given in source Managed by user on device
Meta access Possible but barred by policy Impossible by design
Availability Now Later
Checks Internal red teams and public plan Outside security firms

Muse is late to the personal agent race, but it leans hard on privacy as its edge. Whether users believe that pitch is the open question.

Source: wired.com

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.