AGENT PROFILE · PRIMARY SOURCE

Meta Muse: personal AI agent with a Secure VM

Meta Muse is designed to take actions across connected apps and support long-running personal goals. Its dedicated execution environment, user approvals and regional restrictions distinguish it from an ordinary chatbot.

AGENTENCODE / IDAI-0128

Source-reviewed: 8 October 2026

AgentenTrust: review pending
Product type: Personal work agent

DIRECT ANSWER

What is Meta Muse?

Muse is Meta’s personal AI agent, introduced in September 2026. According to Meta, it completes browser- and app-based tasks in a dedicated Muse Secure VM, while selected sensitive actions such as sending email or purchases require approval. The first rollout is concentrated in North America. A vendor-described security architecture is not proof that those controls have passed independent tests.

DISTINCTIONS

Product scope: agent, model or platform?

Product / layerSource-scoped distinction
Muse agentThe product that plans and executes goals across browser and connected apps.
Muse SparkThe underlying AI model named by Meta, not an interchangeable label for the agent.
Muse Secure VMVendor-described dedicated cloud workspace containing a browser and protected credential storage.
Muse for Small BusinessA September expansion of connectors and business skills, not automatically a second separate product.

ARCHITECTURE

How does the system work?

Goals and planning

Users state outcomes; Meta says Muse breaks work into steps and asks for intervention when decisions or approvals are needed.

Private virtual environment

The publisher describes a dedicated cloud VM with a browser and service connections. It is not the same as a local agent on the user device.

Sentinel enforcement

Meta describes a separate Sentinel agent mediating outbound actions and user confirmations. AgentenCode has not independently penetration-tested this design.

Ongoing context

Meta describes memory-based suggestions, continued background work and the ability to ask Muse to forget particular learned details.

USE CASES

What tasks does it target?

Travel and planning

The vendor describes coordinating travel tasks and service interactions, subject to permissions and supported travel connections.

Commerce and checkout

Meta describes Stripe Link checkout and commerce partner connections. Authorization and purchase-protection terms are workflow-specific.

Small businesses

The business expansion cites Asana, Canva, QuickBooks, Shopify, Slack, Stripe, Zoom and other connectors; rollout limitations still apply.

Personal projects

Muse aims to turn longer-term goals into follow-up actions, but this profile contains no independent measurements of success rates.

SECURITY

Security, permissions and auditability

VM separation

Meta describes a distinct Muse Secure VM per person rather than shared local desktop execution.

Human approval

Sensitive actions such as buying something or sending messages are described as requiring permission; this is not a universal all-actions approval guarantee.

Credentials and permissions

App access can reportedly be scoped and withdrawn. Meta says Muse is not shown passwords or payment credentials directly.

Activity history

Meta describes a full user-visible audit trail; independent completeness testing is not available for this profile.

Privacy and roadmap

Meta describes an AI training opt-out and separation from advertising systems. Confidential VM is announced for a later date, not already proven live.

AVAILABILITY

Availability, pricing and EU context

Meta’s 29 September 2026 announcement explicitly names the US and Canada as available regions. The initial introduction was US-focused. These statements do not verify broad access in Germany or the EU. Meta mentions free basic use and paid tiers but a definitive region-specific price table has not been verified here.

CHECKLIST

Limitations and due-diligence checklist

  1. Do not infer German or EU access from US/Canada availability.
  2. Confirm transaction consent and revocable app permissions before connecting high-impact accounts.
  3. Do not confuse the proposed Confidential VM with the existing described Secure VM.
  4. Treat security promises as vendor assertions until independently tested.

EVIDENCE / AGENTENTRUST

Which claims have field-level evidence?

Claims are attributed to the cited primary sources. A publisher announcement is not an independently reproduced product test.

Evidence fieldValue and scopePrimary source
hosting.cloudDocumented
muse_secure_vm
Meta — Introducing Muse ↗
governance.human_approvalDocumented
muse_sensitive_actions
Meta — Introducing Muse ↗
governance.audit_logs.availableDocumented
muse_action_audit_trail
Meta — Introducing Muse ↗
security.sentinel_network_reviewDocumented
muse_secure_vm_sentinel
Meta: Introducing Muse ↗
access.us_canadaDocumented
muse_personal_agent_sep2026_north_america
Meta: Muse for Small Business ↗
security.credentials_separate_storageDocumented
muse_secure_vm_credentials
Meta: Introducing Muse ↗
security.audit_trail_user_visibleDocumented
muse_personal_action_history
Meta: Introducing Muse ↗

These claims apply only to the stated scope and do not automatically validate any of the 36 Trust controls.

All 36 AgentenTrust controls: review status — expand

Every control remains Unknown pending individual trust review. A documented capability claim is not an independently verified Trust signal.

ControlPillarStatus
privacy.residency.available
Data Residency
privacyNot independently reviewed
privacy.residency.customer_region_selectable
Region auswählbar
privacyNot independently reviewed
privacy.residency.region
Dokumentierte Region
privacyNot independently reviewed
privacy.training.customer_data
Kundendaten für Training
privacyNot independently reviewed
security.encryption.at_rest
Verschlüsselung at rest
securityNot independently reviewed
security.encryption.in_transit
Verschlüsselung in transit
securityNot independently reviewed
security.customer_managed_key
Customer-Managed Keys
securityNot independently reviewed
security.soc2_type2
SOC 2 Type 2
securityNot independently reviewed
governance.sso.saml
SAML SSO
securityNot independently reviewed
governance.sso.oidc
OIDC SSO
securityNot independently reviewed
governance.scim
SCIM
securityNot independently reviewed
governance.rbac
RBAC
securityNot independently reviewed
governance.custom_roles
Custom Roles
securityNot independently reviewed
governance.human_approval
Human Approval
controlNot independently reviewed
governance.approval.pre_action
Pre-Action Approval
controlNot independently reviewed
governance.human_oversight
Human Oversight
controlNot independently reviewed
governance.permission_controls
Permission Controls
controlNot independently reviewed
governance.policy_controls
Policy Controls
controlNot independently reviewed
governance.tool_permissions
Tool Permissions
controlNot independently reviewed
governance.action_permissions
Action Permissions
controlNot independently reviewed
governance.delegation_controls
Delegation Controls
controlNot independently reviewed
governance.kill_switch
Kill Switch
controlNot independently reviewed
governance.rollback
Rollback
controlNot independently reviewed
governance.audit_logs.available
Audit Logs
traceNot independently reviewed
governance.audit_logs.retention_days
Audit-Log-Aufbewahrung
traceNot independently reviewed
governance.audit_logs.api
Audit Log API
traceNot independently reviewed
governance.audit_logs.siem_export
SIEM Export
traceNot independently reviewed
observability.available
Observability
traceNot independently reviewed
observability.tracing
Tracing
traceNot independently reviewed
governance.audit_logs.action_level
Action-Level Audit
traceNot independently reviewed
privacy.retention.policy
Datenaufbewahrung / Retention
privacyNot independently reviewed
privacy.dpa.available
DPA / Auftragsverarbeitung
privacyNot independently reviewed
privacy.subprocessors.list_available
Subprocessor-Liste
privacyNot independently reviewed
privacy.processing.scope
Datenverarbeitung / Deployment Scope
privacyNot independently reviewed
security.secrets.credential_handling
Secrets / Credential Handling
securityNot independently reviewed
governance.activity_history.available
Activity History
traceNot independently reviewed

COMPARISON AND ALTERNATIVES

Which alternatives match the task?

These products serve different purposes. Listing an alternative does not establish feature equivalence.

ProductRelevant distinction
Perplexity ComputerExecution-oriented workflow product, with different surfaces and permission model.
Perplexity Comet AssistantBrowser-oriented assistant, not equivalent to Meta’s dedicated VM architecture.
ChatGPT WorkA separate work environment with distinct access and governance characteristics.

PRIMARY SOURCES

Official primary sources and review scope

Claims are attributed to the cited primary sources. A publisher announcement is not an independently reproduced product test.

  1. Meta: Introducing Muse ↗
  2. Meta: Muse for Small Business ↗
  3. Meta: Connect 2026 update ↗

Source review: 8 October 2026. Unknown means missing public evidence, not a negative finding. Plan, region and product-surface scopes must not be generalized.

RELATED ECOSYSTEM

Meta / Muse

The association links the profile with the provider without transferring security properties from other products.

All related agents →

FAQ

Frequently asked questions: Meta Muse

Is Muse just a language model?

No. Muse is the agent product; Muse Spark is Meta’s named underlying model.

Is Muse available in Germany?

General access in Germany is not confirmed by the cited official releases. US and Canada availability was stated in September 2026.

Can Muse buy things without asking?

Meta describes purchase and checkout workflows but says sensitive purchases require a user approval.

What is Muse Secure VM?

A dedicated cloud virtual environment with a browser and approved service access, as described by Meta.

Has its security been independently audited here?

No. VM separation, Sentinel mediation and consent controls are manufacturer statements in this profile.

Is Confidential VM available now?

Meta presents Confidential VM as a future enhancement, not an already-delivered feature.