
The version where Meta cannot read your data has no date
Meta released Muse on Tuesday, a personal agent you message to send email, book travel, buy things and sell your car. WIRED has the details. It runs in the Muse app on iOS and Android, on Muse.ai and inside WhatsApp, with the AI glasses to follow, and it lands opposite OpenClaw and Instinct. The free tier covers light use; heavy automation needs a paid plan.
The company put privacy in the announcement. Two architectures sit behind that word, and one of them shipped.
What ships today
Secure VM gives every user an isolated virtual machine, so untrusted data pulled off the web stays away from the part of the agent that can act. A component Meta calls Sentinel watches everything leaving the machine and either matches it to a permission you already granted or stops and asks you.
Those questions reach you without passing through the model. That routing is deliberate: an attacker who plants instructions in a web page cannot rewrite the dialogue asking whether you meant to send the money.
Payments run through Stripe's Link, which issues a single-use card number so the agent never types your real one. Meta says Muse is the first agent covered by Link's purchase protections, with no-fee returns.
“We know it's really important, if we're going to build a product like this that can access a lot of sources of personal data, that we're really responsible with that, so we've designed this system very deliberately.”
— David Singleton, WIRED, 8 September 2026
David Singleton, vice president of engineering for consumer products at Meta Superintelligence Labs. Source: WIRED, 8 September 2026
The sentence under the claim
WIRED reports that Singleton acknowledged the limit: Meta is barred by policy from reaching user Muse data, and reaching it would remain technically possible. Users can opt out of having their data used for training.
Meta writes that policy and can rewrite it. Architecture does not bend the same way, and today Muse rests on the policy.
What would make the label true
Confidential VM, announced in the same breath, runs each virtual machine in a trusted execution environment with the access keys held on your own device. Meta says nobody, itself included, could reach your agent then.
The company will hand select security firms the source, publish the binaries and run a transparency log so you can verify what you connected to. Moxie Marlinspike, who built Signal, worked on it. WIRED saw a draft of the white paper.
Meta describes all of that in the future tense, and the word it used was eventually.
What Meta will pay to be wrong
Muse enters the public bug bounty with payouts up to $300,000, and up to $130,000 for a prompt injection that hits a single user.
That second figure is 43% of the maximum for one attack class against one victim. Firms set their biggest bounties where they expect the most pressure, and Meta has priced a single hijacked agent at the level others reserve for a full breach.
We counted 17 occasions on which AI agents hacked real companies, so the pricing reads as arithmetic.
Where the trust goes
Meta Muse touches your email, your calendar, your travel and a payment card. Meta ran it internally under the codename Hatch, which we wrote about last week when the company stopped grading staff on AI usage and Hatch token spend kept climbing.
The isolation is real engineering and it does useful work. What the label promises is a system Meta itself cannot open, and Meta has not said when that one arrives.
None of this should be read as personalized investment advice.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
286AI





