Meta Muse Surprise Launch: Everyone Gets an AI Virtual Machine That Works 24/7, Mark Zuckerberg Wants AI to "Earn Its Own Keep" on Its Own
Meta launches personal Agent Muse, focusing on security and privacy
On September 8 local time, Meta officially released its personal AI assistant Muse.
Different from traditional chatbots that are mainly responsible for answering questions and generating content, Meta positions Muse as a "personal AI Agent": users do not need to tell it step by step how to operate, just state the goal, and Muse can break down tasks on its own, open web pages, fill out forms, and call external applications to complete work.
It can send and receive emails, arrange schedules, book trips, purchase goods for users, even participate in bill negotiations and assist in selling cars. For tasks that cannot be completed immediately, even if the user closes the application, Muse can continue running in the cloud until there is a change in the task or user approval is required, then send a reminder.
From the perspective of product form, Muse is more like a continuously online digital assistant.
Meta CEO Mark Zuckerberg also introduced Muse on social platforms. He defined it as a "personal Agent that can understand users' goals and complete tasks for users around the clock".
Zuckerberg emphasized that this personal assistant can "work 24/7", which is precisely thanks to Muse's ability to run continuously in the background — even if the user closes the application, it can still continue to search for information, monitor status or wait for the right execution opportunity in an independent cloud virtual machine, until the task is completed, or sensitive operations requiring user approval are encountered.
Currently, Muse is first launched for US users, who can use it through the standalone Muse App, web terminal and WhatsApp, and it will be available on Meta's AI glasses later.
Alexandr Wang, head of Meta Superintelligence Labs, said in an interview with CNBC that the company designed the application to be "very approachable, friendly and easy to understand, and not overly complicated".
Wang said: "Behind the scenes, Muse may be running very advanced coding workflows, or building complex integrations, or doing a lot of heavy lifting, while remaining very simple and easy to use for users."
In addition, he also said that the Muse personal agent will provide a free version, or subscription plans of $20 or $100 per month depending on usage.
Meta claims that the most important feature of this personal assistant is security and privacy. Each user will get an independently running Muse Secure VM, which is a virtual computer located in Meta's cloud. This virtual machine has its own browser, which can save user-authorized data and service connections, and continue to run tasks after the user leaves.
For example, users can ask Muse to plan a trip. Muse not only gives destination suggestions, but also determines the time by combining calendar and emails, searches for flights and hotels, fills in booking information, and requests user confirmation before payment is required.
If users want to reduce the bill of a certain service, Muse can also browse websites, fill out forms, and even negotiate with service providers on behalf of users. Facing long-term goals, it can first make a plan and then continuously track the progress. Examples given by Meta include adjusting training plans according to changes in personal life, converting recipe videos users have favorited on Instagram into shopping lists, and remembering the dietary restrictions of party participants.
Muse also has the "initiative" that traditional chat assistants are relatively lacking. It can remember information that users have mentioned and give suggestions when not directly asked. Users can also name their own Muse, create avatars, and adjust its communication style.
In other words, the working mode of traditional assistants is usually "one question, one answer", and Muse hopes to form a more complete execution chain:
Users give goals, Muse makes plans, calls tools and executes continuously, and finally returns the right of decision to users only on sensitive operations and key nodes.
What makes Muse different?
Similar personal assistants have emerged in endlessly in the market. Apart from the always-emphasized security and privacy, what differences does Meta's newly launched product have in product design and function usage compared with similar products?
It is claimed that Muse's differences are not mainly reflected in model parameters or benchmark scores, but in product entry, operation mode and permission system.
First of all, it is designed as a long-running personal Agent from the very beginning. Ordinary chatbots mainly stay in one session. Although some products can also call browsers and tools, they often still require users to stay on the current task interface. Muse has an independent cloud virtual machine. After users exit the application, it can still refresh pages in the background, wait for product or ticket information and continue to advance tasks.
Secondly, Muse tries to lower the threshold for using Agent. Previously popular personal Agents such as OpenClaw have proved that users are willing to let AI connect to emails, browsers and local tools, but such products usually require certain capabilities for installation, configuration and security management. Muse encapsulates similar capabilities into App and WhatsApp, hoping that ordinary consumers can schedule the Agent just like sending messages to contacts.
Third, Meta has consumer-level entrants that other model companies can hardly replicate. Muse can not only connect to third-party services, but also may directly use the social relations and content context formed by Facebook, Instagram and WhatsApp. For example, it can read information authorized by users, understand favorited content, and assist in organizing parties or maintaining interpersonal connections.
After entering AI glasses in the future, Muse may also change from a pure software assistant to a portable interaction entry.
However, this difference is also Muse's biggest risk: the more an assistant understands the user and the more actions it can take on behalf of the user, the greater the permissions it obtains and the greater the potential losses it may cause.
How to protect security and privacy?
In order to limit Muse's behavior, Meta has deployed another independent system Sentinel in the virtual machine.
According to Meta's explanation, Muse is responsible for understanding goals and proposing actions, and Sentinel is responsible for reviewing these actions. Before Muse accesses the Internet or sends information outward, it needs to go through Sentinel's judgment: whether the operation can be executed directly, should be blocked, or must be submitted to the user for approval.
For sensitive operations such as sending emails and making payments, Muse will take the initiative to ask users; users can also grant application read and write permissions separately, and restrict authorization to a certain task, a certain transaction or a certain period of time. All completed and pending actions will be kept in the audit records.
Meta also said that Muse cannot directly see users' passwords and payment information. The Link payment function in cooperation with Stripe will generate a one-time bank card number, so that the Agent does not need to enter the user's real card number on different websites. 1Password and Shop Pay support will also be added later. Users can disconnect third-party services at any time and choose not to let Meta use Muse interaction data to train models.
Meta claims that the data and conversations in the Muse virtual machine will not be provided to its advertising system.
However, the current Secure VM is not a "black box" that is completely invisible to Meta. Meta executives admitted that although the company's policy prohibits access to users' Muse data, technically there is still a possibility of access.
Meta plans to launch Confidential VM later this year, allowing the virtual machine to run in a trusted execution environment, with users holding the keys on their local devices. According to its design, other entities including Meta will not be able to enter the user's Agent environment by then.
This means that part of Muse's currently highlighted privacy capabilities have been launched, while the other part remains in future plans.
Review of Muse's R&D process from internal project Hatch
In fact, Muse is not a sudden independent product launched by Meta. Behind it is a months-long R&D clue, and it is also the first time that Meta has implemented "personal superintelligence" into consumer-grade products after restructuring its AI business.
In 2025, Meta established Meta Superintelligence Labs, with Alexandr Wang in charge of promoting the R&D of a new generation of models and products. After that, the team spent about 9 months rebuilding the AI technology stack, including model architecture, training infrastructure and data pipeline.
In April 2026, Meta released its first model Muse Spark after restructuring, which supports multimodal reasoning, tool calling and multi-Agent collaboration, and has become the underlying model of the later Muse personal assistant.
But from the very beginning, what Meta wanted to do was not just a chat model with stronger performance.
As early as around the release of Muse Spark, the company has launched an internal personal Agent project codenamed "Hatch".
According to previously disclosed information, Hatch's product idea was inspired by the open source personal Agent OpenClaw: it not only answers questions, but also has its own computing environment and long-term memory, can access browsers and third-party applications, and continuously complete tasks with less human intervention.
In May 2026, news about Hatch's R&D began to spread. The plan at that time was to complete internal testing by the end of June.
Meta later opened it up for employees to try, allowing employees to use it to book restaurants, find pet sitters, order meals, fill out online forms, conduct in-depth research, and operate services such as Instagram, Spotify and OpenTable.
This internal test actually determined the final product form of Muse.
Meta found that for personal Agent to work continuously, a large model with stronger capabilities is not enough: it must have an independent computing environment, persistent memory, application connectors and background running capabilities, and at the same time solve risks such as out-of-control permissions, prompt injection and sensitive information leakage.
Security issues also made Muse's release rhythm slower than originally planned.
According to Reuters, Vishal Shah, Vice President of Meta AI Products, revealed to it that the company originally considered launching the product in April, but postponed the release to strengthen security protection. After additional development, Meta believes that Muse has reached the "minimum threshold" that can be opened to consumers. However, he also admitted that Meta cannot guarantee that the Agent will never make mistakes.
To this end, Meta did not let Muse run directly on users' mobile phones or personal computers, but established an independent Muse Secure VM for each user, and additionally designed the Sentinel supervision system. Muse is responsible for understanding goals and executing tasks, while Sentinel is responsible for checking the information sent by Muse to the Internet and the actions it is going to take, and requiring user confirmation when necessary.
This dual-system architecture is one of the most critical changes in the process of Muse moving from an internal experimental project to a consumer product.
Zuckerberg talks about Muse commercialization: help users earn back the money spent on the tool
It is worth mentioning that on the occasion of Muse's release, Zuckerberg was interviewed by tech journalist Alex Heath, discussing topics such as personal AI Agent, business model, privacy and security, and Meta's rebuilding of the AI team.
Interview video link: https://www.youtube.com/watch?v=Lx8lrn-cytc&t=1s((https://www.youtube.com/watch?v=Lx8lrn-cytc&t=1s()https://www.youtube.com/watch?v=Lx8lrn-cytc&t=1s)(https://www.youtube.com/watch?v=Lx8lrn-cytc&t=1s)
The biggest signal released in this interview is that Zuckerberg believes Muse can recover its own cost by creating benefits for users.
This means that Meta's vision for the business model of personal Agent may not only be traditional software subscriptions, but hope to take a cut from transactions in the long run.
In terms of commercialization, Zuckerberg said that although Muse provides paid subscriptions, Meta hopes that the vast majority of users can use it for free. According to him, Muse will provide a free quota of about 100 million Tokens per week in the initial stage of launch, and equip users with independent virtual machines.
The reason why Meta is willing to provide such a high free quota is that it has another vision for Muse's long-term business model: when users use Muse to run small businesses, purchase goods or complete other commercial transactions, the Agent can help users make money or save expenses, and Meta will charge a very small percentage of fee from relevant transactions.
This fee may not be paid directly by users, but may come from merchants or service providers that transact with Muse. At present, Muse has launched payment cooperation with Stripe and can connect to Meta's advertising system. Zuckerberg gave an example that users can ask Muse to make products, place advertisements and assist in operating the business, and the whole process can form a continuously running closed loop.
Therefore, Muse's business model may be divided into two layers: heavy users can purchase subscriptions, ordinary users use it for free, and Meta obtains revenue through payment, commercial services and transaction sharing.
Zuckerberg believes that Muse can eventually create enough benefits or save enough money for users, so as to "pay for itself".
However, it should be noted that transaction sharing is a long-term business model described by Zuckerberg, which does not mean that Meta has announced a specific sharing ratio or fully launched relevant mechanisms. At this stage, the more certain source of revenue is still paid subscriptions and connections with payment, e-commerce and advertising services.
In addition to the planning in commercial aspects, Zuckerberg believes that the fundamental difference between Muse