In this article
Meta has launched Muse, an artificial intelligence agent that performs tasks like booking travel and shopping directly through WhatsApp.
How it works
The system operates on a dedicated virtual machine that Meta describes as a walled garden. This isolation keeps passwords and payment details hidden from the main application. A separate oversight agent, which Meta calls Sentinel, monitors all actions. Nothing leaves this secure environment unless Sentinel explicitly approves it.
Users control the agent via WhatsApp. They can ask for simple actions, such as sending an email, or request complex planning. For the latter, Muse breaks down the goal, schedules the steps, and coordinates resources. It opens a browser, fills out forms, and negotiates prices on the user’s behalf. Meta claims the agent can sell a car for a higher price or lower a utility bill.
For long-term tasks, the agent remains active even when the app is closed. It checks in only when a change occurs or when approval is needed before executing a purchase or sending a message. The system also retains user preferences. It can convert a recipe video saved on Instagram into a shopping list or suggest a dinner menu while accounting for dietary restrictions.
Direct payments and security
Muse processes payments through Stripe’s Link service. Meta states this is the first AI agent covered by Link’s purchase protection policy, which handles damaged items, price drops, and returns. Each transaction uses a one-time card number to keep the real card details secure. Support for Shop Pay and 1Password integrations is scheduled for later.
This approach contrasts with OpenAI. The company removed direct payment features from ChatGPT and left checkout to merchants. Users could research products in the chat but could not buy them there. Connecting merchants required manual work.
Meta does not publish specific figures on system robustness. Security researchers have demonstrated how agentic systems can be hijacked via manipulated content. A doctored calendar invite was recently shown to take over a password manager account using Perplexity’s Comet browser.
Ad data and privacy
Users can opt out of having their interactions used to train AI models. Meta states that Muse does not share conversation data from the secure virtual machine with its advertising systems. The agent is designed to forget learned information if requested. Later this year, a version called Muse Confidential VM will encrypt the entire machine with a key held only by the user.
This privacy setting does not apply to Meta AI. Since December, the company has used assistant interactions for personalised ads and content on Facebook and Instagram in most regions. Sensitive topics such as religion, health, and political views are excluded from this data usage.
Performance and pricing
Meta refers to the technology as “personal superintelligence,” a central theme in a recent essay by Mark Zuckerberg. The model has improved sharply in five months. Muse Spark, released in April, scored 31 points on the Artificial Analysis Intelligence Index v4.3. Version 1.3, available since early September, reached 44 points on the xhigh tier and 48 on the max tier.
For comparison, GPT-5.6 Sol (Max) sits at 47, while GPT-6 Astra (Max) and Claude Fable 5.1 land at 53. In May, reports emerged that Meta was training an agent called Hatch. This system learns in walled-off environments using simulations of real sites like DoorDash, Etsy, and Reddit. Muse is likely based on this work. There have been discussions of a paid product costing up to $200 a month.
Muse launches first in the US for iOS and Android. A connection to Meta’s AI glasses will follow. Users receive a free usage limit that refills regularly. Additional access requires a subscription.
What it means
The shift to a secure, isolated virtual machine changes the risk profile for these tools. By keeping credentials and payment data out of the main application, Meta attempts to solve the trust issues that plagued earlier chatbot integrations. However, the reliance on a separate approval layer means users must still monitor the agent’s progress, as it cannot act autonomously without Sentinel’s clearance.




