Meta Launches Personal Agent Muse to Automate Tasks in the Background
Original title:扎克伯格推进“个人超级智能”:Meta 发布其首款个人智能体 Muse,内部测试喜忧参半
On September 9, Beijing time, Reuters reported that Meta on Tuesday officially launched its long-promoted AI assistant, which can autonomously carry out tasks on behalf of users such as sending emails, selling cars, and booking travel. However, internal concerns have emerged at Meta over whether the technology mismanages permissions when accessing sensitive personal data. Named Muse and known internally at Meta as Hatch, the AI agent is the centerpiece of CEO Mark Zuckerberg's plan to deliver "personal superintelligence" to the billions of people who use Meta's services daily.
The initiative represents Meta's latest effort to diversify its revenue and reduce its dependence on advertising, while aiming to build a sustainable business off its massive investments in AI chips and other infrastructure. Meta expects to spend more than $130 billion in this area this year.
In its announcement, Meta said Muse will initially launch only in the United States, accessible via a dedicated Muse app or through Meta's WhatsApp messaging service. Meta said it will add the agent to its smart glasses lineup "soon," without providing specific details.
A Meta spokesperson said the agent will offer a free basic tier alongside monthly subscriptions of $20 and $100 to meet the needs of more frequent use. Meta stated that users can opt out of having their interaction data used to train Meta's AI models, and the company plans to release an encrypted version of Muse later this year.
Security Concerns
Meta said Muse is modeled on the open-source AI agent OpenClaw and is designed to access user data across various applications, including email, calendars, payments, health, shopping, and smart home systems. Users can choose which applications Muse connects to and have the right to revoke its access at any time.
Each Muse agent runs in an isolated virtual machine—a cloud-based PC emulation environment—allowing it to continuously execute tasks in the background even when users are not actively using it. Synchronizing with apps that store users' real-world data enhances the agent's utility, but it also dramatically increases security risks—not only for users who hand over their personal information to the agent, but also for others who could be affected by the agent's erroneous actions.
Vishal Shah, Meta's Vice President of AI Product, told Reuters that the company had delayed the product's release in April this year to further enhance security. He said Meta believes the additional preparation allowed it to "cross the threshold" and reach "the minimum standard needed to put this in people's hands."
"It's not that things will never go wrong, but every part of the architecture is designed to maximize security, reliability, and privacy to the best of our ability," Shah said.
In its announcement, Meta said the multiple safeguards built into the Muse system include an independent watchdog agent that reviews planned actions and, under specific circumstances, requires Muse to obtain user authorization before proceeding.
Mixed Results in Internal Testing
However, internal posts viewed by Reuters show that as recently as this week, Meta employees' testing of the tool yielded mixed results.
One employee wrote that the product was so useful for planning vacations that Muse became the "third participant" on their recent three-week honeymoon in Indonesia.
Other employees, however, reported serious security vulnerabilities. For example, after being instructed to "find toys that appeared in photos from a child's birthday party," the agent bypassed security restrictions and exposed photos from a user's personal iCloud.
Meta Chief Technology Officer Andrew Bosworth posted that he was repeatedly forced to log out and had to continually log back in, sometimes multiple times within a matter of minutes.
In another post, an employee who used Muse to monitor tickets and other high-demand, quick-to-sell-out items said they encountered "many failure modes that prevent it from operating reliably." The employee said the product stopped refreshing pages after about 15 minutes, silently ignored other errors, and sometimes shut down its monitoring feature "for no apparent reason."
As of press time, Meta had not responded to requests for comment regarding the specific incidents described in the internal posts.
Why it's worth reading
It represents a significant deployment of persistent, cloud-based personal agents into ubiquitous consumer messaging, testing the boundary of how much sensitive data users are willing to delegate to autonomous software.