On September 8, 2026, Meta introduced Muse: a personal AI agent rolling out in the U.S. on iOS, Android, muse.ai, and WhatsApp, with AI glasses “coming soon.” Muse runs on Muse Secure VM with a separate Sentinel permission layer, Stripe Link one-time cards for purchases, free tier plus paid plans, and a promised Muse Confidential VM later. Distinct from AI Shift News’ earlier Muse Spark 1.3 scores brief. Company privacy/safety claims stay labeled as claims; Reuters (and related) internal-concern reporting is attributed, not asserted as proven fact in our voice.

Take the full tour of Muse, Meta's personal AI agent. · Muse

Quick Take

Meta’s September 8 launch of Muse is a U.S. consumer personal AI agent — not another model-score drop. The company says Muse runs in a dedicated Muse Secure VM, routes sensitive actions through a separate Sentinel, can pay with Stripe Link one-time cards, and will add Muse Confidential VM later this year. Rollout surfaces: iOS, Android, muse.ai, and WhatsApp. Soft-re-cover fence: this is distinct from AI Shift News’ Muse Spark 1.3 benchmark brief.

  • Confirmed (Meta): Product launch, surfaces, Secure VM + Sentinel framing, Link checkout, free/paid tiers, Confidential VM roadmap, training opt-out.
  • Attributed: Reuters reported internal concerns that the technology mismanages access to sensitive personal data in testing — outside reporting, not an AISN finding.
  • Not proven: Independent launch-day audit of Secure VM; present availability of Confidential VM; that consumer trust matches Meta’s marketing tone.

What the video shows

Selected embed: “Take the full tour of Muse, Meta's personal AI agent.” (YouTube wHn0hTjvFoo), Muse channel. Product-tour packaging for UI and task demos. Useful for “what Meta wants you to see.” Not a substitute for the safety white paper or for Reuters’ reporting.

What’s new

What is new is the agent product: an always-on helper that Meta says can message like a person, keep working after the app closes, connect to email/calendar/payments, and ask before sensitive sends or purchases. That is a different story from Muse Spark’s Artificial Analysis scores. TechCrunch’s launch coverage centers the trust problem — Muse needs deeper app access than a chatbot — which is the practical reader angle even when Meta leads with Secure VM language.

Evidence

Meta Newsroom post (primary). Describes Secure VM isolation, Sentinel egress/approval, credential storage Muse cannot see, audit trails, connector scoping, no ad-system sharing of conversations/VM data (with browsing-side effects disclosed), free tier plus subscriptions, and Confidential VM later.

Meta AI Research safety post (primary technical narrative). Goes deep on runtime cell isolation, Sentinel as sole permission authority, credential surrogation, tainted egress, browser broker limits, Link single-use cards, and a public bug bounty (up to $300,000 framed, including prompt-injection classes). Read it as Meta’s architecture claim set — unusually detailed, still first-party.

Reuters / TechCrunch secondaries. Reuters pairs the launch with reporting on internal concerns about sensitive-data handling. TechCrunch asks whether consumers will trust Meta with agent-level access after recent social-harm settlements. Attribute those threads; do not launder them into “Meta admitted X” unless quoting a primary admission.

Still missing. Third-party attestation of Secure VM at GA; Confidential VM ship date with audit artifacts; long-run abuse/incident rates in the wild.

What this means for practical readers

If you are deciding whether to connect email and payments to an agent, separate feature demos, company security architecture, and outside risk reporting. Muse’s launch gives you a clear Meta story on the first two. Reuters and peers supply the third. This brief keeps them labeled — and keeps Muse Spark leaderboard coverage in yesterday’s folder where it belongs.

Bottom Line

Muse is a U.S. consumer agent launch with detailed first-party Secure VM/Sentinel packaging — company claims, not independent proof. Distinct from Muse Spark 1.3 score coverage; attribute Reuters concern reporting.

Sources