HomeArticle

Muse tops the list, Meta makes a comeback with its agent.

字母AI2026-09-22 09:39
After stopping its obsession with chasing SOTA, Meta has reaped fruitful achievements in the personal Agent field.

Launched roughly 10 days ago, Muse topped the free app chart on the US App Store, surpassing ChatGPT.

Around the same time, Manus, another representative product on the personal Agent track, also announced a new round of financing plans, targeting $500 million in funding at an estimated valuation of $4 billion.

Agents are paving a "curve overtaking" path for cutting-edge AI giants. While foundational models are critical, the Agent track has expanded the battlefield to cover product design, tool invocation, task execution, permission management and user entry points. Latecomers do not necessarily need to beat OpenAI and Anthropic on model leaderboards first, and they still have the opportunity to deliver tangible results at the application layer.

Meta has clearly embarked on this "shortcut".

Over the past year, it has not had an easy time catching up in the model competition. It poured in massive funds, recruited top talent, and deployed huge computing power, but its outputs were often overhyped and underdelivered, with only limited achievements perceptible to ordinary users.

Until the launch of Muse, Meta finally had a truly self-owned AI hit product.

01

Why did Muse become a breakout hit?

When Muse was first released, its functions were not particularly outstanding on paper.

It can browse web pages, invoke tools, process files, and help users book hotels, send emails, and make purchases. All these capabilities have already been demonstrated by ChatGPT, Claude, and even Manus before it.

Theoretically, these functions easily touch the boundaries of privacy and permissions, making it almost impossible for users not to worry about the security risks of Agents.

If you let it organize your schedule, you have to grant access to your calendar; if you let it read your emails, it needs to enter your mailbox; if you let it help you shop, it not only needs to know your address and preferences, but also access your account and payment information.

Prompt injection is also a risk that requires caution. When Agents browse web pages, read emails and process files, they are constantly exposed to external information. If someone hides a malicious instruction in a web page to trick the model into sending out user data, an Agent with high permissions may pass the attack all the way to the user's real account.

When developing Muse, Meta acknowledged that no matter how well a model is trained, Agents will make mistakes and may be attacked.

Its uniqueness lies in that it does not pin all security guarantees on the model being sufficiently compliant, but builds a complete permission system outside the model.

In simple terms, Muse equips each user with an independent cloud computer.

You can think of it as a dedicated remote computer (virtual machine) that stays on permanently and belongs exclusively to you, with a built-in browser, and the ability to store files and run programs. Almost all the work Muse does for you, including information retrieval, file processing and task execution, is completed on this dedicated computer.

Your files, web page login status, mailbox and calendar connections will not be mixed with those of other users. Even if Muse needs to work for you for a long time, it operates within this independent computer, and will not roam across the entire system with your permissions.

It is worth noting that the Muse running on this dedicated computer is not the actual "administrator" of the device.

Meta split the entire system into two mutually isolated security zones. Muse resides in one zone, while the other stores truly sensitive assets, including user login credentials, security services, and an independent security Agent named Sentinel.

This Sentinel is dedicated to approving network access and third-party services. Muse can submit requests to send emails or access accounts, but Sentinel is the one that actually approves the actions. It can check which website and address Muse intends to access, what request method it uses, and what content it is about to send out.

The same logic applies to passwords and payment information. Login credentials are stored in independent secure storage; Muse can use them but cannot view the specific content. Sensitive operations such as sending emails and making purchases will be confirmed with users again. Users can also separately specify the permissions of each connector, for example, whether the mailbox is only allowed to read content, or also granted permission to send emails.

An extra layer of isolation is added to the payment process. After Muse integrates Stripe's Link, it can generate a one-time payment card, so that the user's real bank card information will not be directly exposed to the Agent or merchants.

These multi-layered safeguards limit the potential damage Muse could cause.

Users are willing to trust it — or rather, believe that even if something goes wrong, it will not cause major harm — which gives Muse the opportunity to truly enter the lives of ordinary users.

Of course, security alone is far from enough.

The model behind Muse is Meta's self-developed Muse Spark. Alexandr Wang later revealed that from Muse Spark 1 to the latest version 1.3, this entire model series has been built for the personal Agent Muse from the very beginning, with every iteration focusing on enhancing Agent and multimodal capabilities.

Beyond the model, Muse is backed by Meta's complete product ecosystem.

It can integrate with platforms including Instagram and Facebook, and can also be used directly within WhatsApp.

The official use case shared by Meta shows that if you plan to invite friends over for dinner, Muse can go through the short video recipes you saved on Instagram, help you select dishes, make a shopping list, note down any dietary restrictions of your friends, and finally send out the invitations for you.

Axios specifically mentioned that Muse's rapid rise to popularity relies not only on the model itself, but also on several things Meta has long excelled at — turning complex technologies into products accessible to ordinary users, rapidly scaling products to a large user base, and understanding exactly what users like and need.

Roughly 10 days after its launch, Muse reached No.1 on the free iPhone app chart of the US App Store, surpassing ChatGPT.

Meta's massive AI reconstruction initiative over the past year has finally delivered a tangible achievement that ordinary users can directly perceive.

02

No longer clinging to SOTA competition,

Meta sets its sights on personal Agents

Over the past year, Meta has been in an awkward position among cutting-edge AI companies.

It has spent huge sums, recruited massive top talents, and deployed increasingly large computing power. But compared with OpenAI, Anthropic and Google, Meta has always fallen slightly behind — not to mention the first two, Google at least has cloud services and the TPU ecosystem to support its AI landscape.

In contrast, Meta has long failed to deliver a sufficiently convincing major result.

In 2025, Llama 4 underperformed expectations, and the highly anticipated Behemoth was repeatedly delayed. Meta, which once sparked an industry wave with open source models, gradually fell behind in the SOTA model competition.

As a result, Meta launched its reconstruction initiative.

In June 2025, it spent $14.3 billion to acquire a 49% stake in Scale AI, bringing Alexandr Wang on board to lead its new AI system. It then established Meta Superintelligence Labs (hereinafter referred to as MSL), offering top annual compensation of over $100 million to recruit talent on a large scale from OpenAI, Anthropic and Google DeepMind, and its AI organization was restructured multiple times within half a year.

Its computing power investment also expanded simultaneously. Meta's capital expenditure in 2025 reached $72.2 billion, and its 2026 guidance was further raised to $130-145 billion, with the construction of gigawatt-level AI data centers including Prometheus and Hyperion.

By April this year, Muse Spark was released. Meta itself stated that this was the first model deliverable after 9 months of MSL's "rebuilding the AI technology stack from scratch".

We can regard Manus as a key source of inspiration for Meta's pivot to Agents.

Last December, Meta once planned to fully acquire Manus, which is best known for combining models, browsers, tools and execution environments into a general-purpose Agent that can independently complete complex tasks. Later, this $2 billion+ transaction was required to be divested by regulators, but the fact that Meta was willing to pay such a high price for Manus already shows that it at least considers this track worth exploring.

Meta did not keep Manus, but retained the Agent logic represented by Manus.

Coincidentally, Manus itself later also shifted its focus to personal Agents. In February, it integrated its product into Telegram, and explicitly wrote in its official documentation: "Your personal Agent, anytime, anywhere".

Agents are the entry point for tasks. Under ideal conditions, users only need to put forward their requirements, and the Agent can complete the tasks — users do not need to know which model or third-party tool is used in the process.

Meta has not stopped model training, but it no longer waits for the model to take the top spot before thinking about product development. Models have become the underlying foundation, while Agents have become a more direct breakthrough point.

The Muse Spark series of models is specifically targeted at personal Agents; and the Muse product has proved that this path can indeed deliver very impressive results.

This path is not niche, and is full of opportunities.

Beyond Muse, a personal Agent called Instinct has not even been fully launched to the public, but it is already being chased for investments by capital.

It is currently in the invite-only testing phase, with access to mailboxes, messages, calendars and location data, allowing it to help users make purchases, book restaurants, and cancel subscriptions. It has recently started testing new capabilities including independent mailbox management and making calls on behalf of users. At the end of August, it completed a new round of financing at a valuation of roughly $2.5 billion; in September, according to The Information, the company is in discussions to raise another $1 billion, pushing its valuation directly to around $10 billion.

03

"Choice matters more than effort"

If we take a broader perspective, we will find that the established tech giants that were once chasing large models together have now embarked on different development paths.

Google is one of the few companies that still adheres to the full-stack strategy: it strives for top-tier models, develops Agents, sells cloud services, and self-develops chips.

There were previous rumors that Google might withdraw from the top model competition, but just in recent days, a model named "gemini-3.8-flash" with obviously abnormal capabilities appeared on Arena, which is widely speculated by the community to be the unreleased Gemini 4 Pro. On the other hand, the Flash series is updated almost every three weeks, and Google successively released Gemini 3.8 Live and 3.8 Live Extended Thinking in September.

At this year's I/O conference, Google directly announced that it has entered the "Search Agent era", allowing Agents to track information for users in the background 24/7; Google Cloud also launched the Gemini Enterprise Agent Platform. At the more fundamental level, it has the 8th generation TPU, Google Cloud and a complete AI infrastructure system.

Microsoft and Amazon have made different choices, as they are focusing their advantages on enterprise services and AI infrastructure.

Although Microsoft is still developing the MAI series and Amazon has its Nova model, models are no longer the top priority for the two companies.

Microsoft is now placing more emphasis on multi-model platforms. Azure AI Foundry provides models from OpenAI, Anthropic, xAI and Microsoft's own MAI series at the same time, allowing enterprises to freely choose solutions based on quality, cost and task requirements. Microsoft's latest financial report reveals that since the beginning of this year, the number of customers using models from multiple vendors has increased 5 times; Foundry and Agent 365 are responsible for integrating these models into enterprise data, permission systems and Agent architectures.

Rather than making its own model the strongest in the industry, Microsoft prefers to ensure that no matter which vendor ends up with the better model, enterprises will run their workloads on Azure.

Amazon's pivot is even more obvious.

In July this year, Amazon directly cut some positions in its AGI team. Previously, this relatively independent AGI organization had been merged into a larger technology department, grouped together with the chip and quantum computing teams; multiple core leaders including Rohit Prasad and David Luan have also left the company one after another. Amazon explained that it is streamlining priorities and concentrating resources on the areas that can create the most value for customers.

At the same time, AWS is placing increasing emphasis on Bedrock and AgentCore. Bedrock provides direct access to OpenAI models, Codex and hosted Agents; AgentCore is explicitly built to be "model-agnostic", allowing developers to freely switch models while AWS takes charge of the operating environment, permissions, security and monitoring.

Its logic is similar to Microsoft's: instead of putting huge efforts into catching up with SOTA models, it is better to ensure that all the models and Agents developed by other players eventually run on AWS.

Meta has taken the