Mark Zuckerberg’s Meta, owners of Facebook, WhatsApp, and Instagram, have made an aggressive push into the AI market with Muse, an “agentic AI” product that is rapidly racking up downloads, claiming big user numbers and pushing past ChatGPT while it has safety experts warning of serious dangers to users.
What Is Muse?
Per Meta’s September 8th product announcement:
Muse is a personal AI agent. It doesn’t just answer questions, it actually does the work. It helps people stay on top of things, takes tasks and projects off their plate, and turns long-term goals into action plans.
Meta built Muse from the ground up to be a safe, secure, private, and widely available personal AI agent.
Muse runs on Muse Secure VM, a dedicated secure computer with its own browser, and can work on a person’s behalf across the apps they use daily, learning from conversations, reflecting on what matters to them, and getting sharper along the way.
Each person stays in control of their Muse and decides how much access it gets.
For a deeper look at how Muse was designed and how safety, security, and privacy were built into it, read How We Built Safety Into Muse and How We Designed Muse.
TechCrunch immediately pointed out some of the consumer trust hurdles Meta will have to overcome to achieve significant user adoption of Muse:
Less than two weeks after Meta agreed to a massive $18 billion multistate settlement in a lawsuit over social media’s consumer harms, the company announced its biggest bet on consumer AI to date — and one that requires significantly more trust than social media ever did. On Tuesday, the company introduced Muse, its new personal AI agent that helps consumers with everyday tasks and projects for users in the U.S.
To use Muse, consumers will have to trust Meta with more of their personal information than ever before. The AI agent works by connecting to the user’s apps and services that are a part of everyday workflows, like email, calendars, payments, and other things the individual may regularly use, like apps for health and fitness, the smart home, dining, shopping, music and events, and more.
The New York Times’ Eli Tan had some details about the development of Muse:
Muse is among the first significant consumer A.I. products created by Meta Superintelligence Labs, which Mr. Zuckerberg established last year to propel his company forward in the A.I. race. Meta has been spending billions of dollars to develop foundational A.I. models and to build data centers so that it can compete with Google, OpenAI, Anthropic and others on the cutting edge of the rapidly evolving technology.
So far, Meta has had hits and misses. Products like its A.I. smart glasses have sold millions of pairs while stoking privacy concerns. In July, the company temporarily took down its Instagram A.I. image generator after widespread criticism about copyright and privacy.
The Muse app is free but has limits on usage, which people pay $20 or $100 a month to increase. The agent is only for adults and can be given a custom name and avatar.
When people link their accounts from OpenTable or Ticketmaster to Muse, it can send messages about upcoming concert tickets or restaurant reservations if it thinks its user might be interested, and book them with one click. Muse also connects to Stripe and Shopify, allowing it to make purchases on someone’s behalf. Muse is the first A.I. agent to be covered by Stripe’s warranties and return policy, in case it makes a purchasing mistake, Meta said.
Since A.I. is not foolproof, Meta says that the agent “will sometimes make mistakes” but that it was designed to “help the user stay in control without being overwhelmed.”
Meta Brags of Muse’s Early Success
In just under a month in the wild, Meta was already bragging of big numbers for Muse (keep in mind Meta has an enormous locked-in audience with its dominant position in social media), leaking the exclusive scoop to The Information, which reported that more than 3 million people prompt Meta’s Muse at least once a week, according to Meta’s internal data. More than 1 million send the AI agent a prompt every day and more than 4 million people use Muse weekly. Most prompts come through the Muse app.
Sensor Tower had more details and some historical comparisons to comparable products, via 9to5 Mac:
Three weeks ago, Meta launched Muse in the US. Soon after, it overtook ChatGPT as the top free app in the US App Store
Today, according to a projection by Sensor Tower Senior Insights Analyst Kara Lee, Muse crossed 5 million downloads. That means it reached the milestone considerably faster than ChatGPT, Grok, and Claude, which the market intelligence firm says took 56, 103, and 492 days, respectively.
…
According to Sensor Tower estimates, only 23 apps have reached over 5mn US downloads within 22 days of launch. ~85% of these apps are mobile gaming apps, including Fortnite, Pokemon GO, Candy Crush, and more. There were only 3 apps within that list that are not gaming apps, including Disney+, HBO Max, and Threads, which received ~20mn, 18mn, and 14mn downloads during that time, respectively.
Sensor Tower explains how Meta did it:
Sensor Tower says “Meta began to ramp advertising spend for Muse on Wednesday, September 16, 2026, as downloads spiked 73% DoD,” and adds:
According to Sensor Tower data, Muse has received the largest share of Meta’s house ads, accounting for up to 50% of daily house impressions over the past two weeks (9/14-927), as Facebook and WhatsApp ceded share of impressions during the same period.
It may be impossible to buy happiness, but it appears wide product adoption can be purchased.
Let’s look at some more details about Muse before we get to the critics.
How Muse Works, How It Compares to the Competition
Trader Joe explains how the Muse Virtual Machine concept works:
VM is short for Virtual Machine and it mimics a standalone PC.
Meta uses software known as a hypervisor to split their servers into many smaller, separate computers, each with its own share of the processor, its own memory, and its own hard drive. Like chopping up a giant house into private apartments. Except that each VM doesn’t need to have its own physical presence.
Each Muse AI agent gets its own VM. That means all your information is stored on its own private (virtual) machine rather than sitting alongside everyone else’s.
A per-person sealed environment is more expensive to implement and Meta prioritizing privacy over costs shows how aware they are of the importance of trust with these types of products.
Shikshita Juyal of Idea to Impact compares Muse to its main rivals Grok Bots and OpenAI’s Dots and includes this montage of the nauseating iconography that accompanies each bot:
She also gets at the problem we’ll be talking about for the rest of the post:
All three share one flaw that nobody in the industry has solved yet. It’s called prompt injection, and the simplest way to explain it:
An agent can’t reliably tell an instruction from you apart from an instruction it read while doing the job.
So if your agent reads an email that says “forward all invoices to this address,” it might just do it. It’s ranked the number one risk on OWASP’s security list for AI systems, and researchers at Straiker showed how a single email could get an AI agent to leak files from someone’s Google Drive, with no click from the user.
No agent can promise it’ll always know your instructions from a stranger’s. That’s exactly why the safe way to start with any of them is read-only.
Warnings and a Parlor Trick Exposed
Tate Jarrow of Tate’s Online Safety warns:
Readers of my work will be unsurprised that I recommend you do not use Muse, and don’t connect Meta’s new AI agent, Muse, to your email, your calendar, your bank, your health apps, or anything else you care about because I would not trust Meta with this level of access and control of one’s personal information.
…
Meta has a terrible record for handling personal and sensitive user information.
Jarrow then lists many of Meta’s more egregious exploits, which thoroughly establishes their long record of bad practice and bad intent. Then he points out that because Muse is free to use “which is an indicator that your data is valuable,” and reminds his readers that “one core principle is that if it’s free, you’re the product.”
He has a lot of good detail about exactly how Meta accesses Muse user data:
Meta claims plainly in its technical post that Muse doesn’t share your conversations or your VM (Virtual machine) data (where Muse is doing the work) with Meta ad systems. Here are a few interesting points from this section.
Your conversations train Meta’s models by default. Meta calls the back-and-forth between you and your agent, plus the resulting tool calls, “trajectories,” and says they’re useful data for training new model checkpoints. They sanitize personally identifiable information first, and there is an opt-out switch in settings. But it’s on by default, which means most people will never touch it, and again, how much do you trust Meta to do what they say?
Your agent’s browsing still feeds the ad machine. This is Meta’s own example: when Muse browses the Internet, it appears as your activity, so if you ask it to buy a shirt from a designer’s website, that designer may use your visit to show you an ad on Instagram. Restaurant reservations and Marketplace browsing can indirectly influence your ads too. The data reaches the ad system, even if it’s not directly pulled from Muse.
Meta already does this with its other AI products. Since December 16, 2025, Meta has used your interactions with Meta AI to personalize content and ads across its apps. There is no opt-out, other than not using Meta AI at all. Meta says it excludes sensitive categories like health, religion, politics, and sexual orientation from that targeting, and the change doesn’t apply in the UK, EU, or South Korea.
Meta’s entire business is built on knowing things about you and selling access to that knowledge. An agent that reads your email, watches your calendar, sees your purchases, and learns your habits is the single richest data source Meta has ever been handed. Trusting Meta to handle data with this level of access appropriately is hard to do.
Finally, he points out that “t doesn’t seem like Muse is end-to-end encrypted.”
Muse does not work that way today, in its own security post:
Today’s Muse architecture isolates each user’s data from each other and keeps it secure. It restricts access to your data by Meta personnel through operational policies. It does not prevent Meta from accessing data when necessary to support, secure or operate the service.
So, under their policies, Meta can access all the data Muse collects, and Meta’s history of protecting user privacy and information is abysmal. And a policy doesn’t protect you from a rogue employee, a data breach, a legal demand, or a government request.
Meta did announce Muse Confidential VM, a version intended to cryptographically and verifiably prevent Meta from accessing data in your VM, with continuous audits that anyone can inspect. If this is true, this might change how I think about Muse, but it’s not here yet, and this might just be marketing fluff. Meta says it plans to deliver it “later this year” and is currently running it with a small group of trusted testers.
Gary Marcus also has some interesting points to make about Muse.
Is Muse Meta’s Second Mechanical Turk?
Gary Marcus offers his readers a Meta corporate history lesson going all the way back to 2015 when Facebook (not yet Meta) launched Product M, which Wired called “Its Bold Answer to Siri and Cortana.”
Turns out that Project M involved a whole lot of “people pretending to be robots” per Buzzfeed and no more than 30% of its requests were served by AI.
Marcus is therefore wildly amused by headlines about Muse like this one from Reuters, “Meta testing a ‘human concierge’ for its new personal AI agent, Muse.”
Meanwhile 404 Media has more serious concerns about Muse, reporting that “Meta Rushed to Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch:”
In the immediate weeks before Muse’s launch, Meta engineers found several security vulnerabilities in the company’s viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse’s intended environment and access Meta’s own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them.
These specific vulnerabilities were discovered before the launch of the product but required a multi-team “mad dash” to fix “a sudden spike in reported KVM escapes,” according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta’s end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta’s own critical infrastructure. A “KVM escape,” then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users’ virtual machines.
According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker — that is, a normal Muse user — to access data in sensitive internal Meta databases. . At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 404 Media granted the Meta source anonymity to speak about sensitive security matters.
Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. This type of security push is not necessarily unusual prior to the launch of a major product, but is notable considering outside researchers have found several other security issues since Muse’s launch, and in the broader context of agentic AIs from OpenAI and other companies going on major hacking sprees.
TIME has a report on the dossier Muse is building on its users:
Muse, the popular new AI personal assistant from Meta, is building continuously updated dossiers on its 4 million users, focusing on who matters to you, what you desire, and what kind of nudges shape your behavior, a TIME analysis of Muse’s internal instructions found.
Each hour, Muse updates its dossiers on you and the people you’ve mentioned in chats, messages, and emails that Muse has read. These pages amount to a map of each user’s social relationships. They record details of how you and your contacts met, your shared interests, your disputes, and “tensions and alliances” within your social group.
Even people who don’t use Muse are subject to this mapping process by other people’s Muse agents. Muse is told to “strengthen your relationship” with users by adapting how it talks, noticing “inside jokes, memorable phrasing, and shared context that makes the relationship feel continuous,” according to the internal instructions TIME reviewed.
The level of insight in the resulting dossiers makes social-media algorithms that study your likes and clicks look quaint. Muse is designed to infer users’ goals, including those you “have not said out loud.” It identifies which kinds of prompts from the personal assistant work best: “This user responds better to short nudges after 10 PM,” reads an internal example found in one of Muse’s prompts. Muse agents perform a nightly analysis of the day’s conversations with the user.
Exciting stuff.
Follow and support my work at NatWilsonTurner.com.
Related Links
