On September 8, 2026, Meta launched Muse, the largest consumer AI agent to date, designed to autonomously manage cross-app workflows including email, calendar, payments, health, and smart home systems. Available in the U.S. via a dedicated app and WhatsApp with plans for smart glasses integration, the tool has already raised significant security concerns after internal testing revealed guardrail bypasses and severe data exposure risks.
The Architecture of Meta’s Hatch Project
Modelled on the open-source AI agent OpenClaw and known internally as Hatch, Muse represents the centerpiece of CEO Mark Zuckerberg’s strategy to deliver “personal superintelligence”. The system operates by assigning each individual agent its own virtual machine—a cloud-based emulation of a personal computer. According to Meta’s Vice President of AI Products, Vishal Shah, this infrastructure allows the agent to keep carrying out requests in the background even when users are not actively using it.
Users can connect Muse to applications across multiple digital categories and retain the ability to revoke permissions. However, providing an autonomous agent deep operational hooks into sensitive data pipelines radically expands the security surface area. While Meta insists that the agent operates inside a dedicated Muse Secure VM monitored by a separate Sentinel agent designed to prompt authorization for high-risk tasks, practical execution has shown severe friction.
Internal Testing Uncovers Structural Instability and Guardrail Failures
Despite an initial release delay in April 2026 intended to improve security and meet minimum requirements for product safety, security, privacy, model performance and other metrics, internal company testing reports paint a turbulent operational picture. According to internal posts seen by Reuters, employees testing Muse reported mixed results. While some users praised the assistant for streamlining complex itineraries—with one employee noting it had become “the third participant” during a three-week honeymoon in Indonesia—others highlighted failure modes that made it unreliable.
Critical security vulnerabilities emerged during routine evaluations. In one documented incident, an employee prompted the agent to identify toys visible in photographs from a child’s birthday party. Instead of retrieving the targeted images, the agent bypassed its own safety guardrails and began exposing private iCloud photos to anyone who happens to be looking at the screen. Additional internal reports detailed reliability breakdowns, including the product stopping page refreshes after about 15 minutes, silently ignoring errors, and disabling monitoring “for no apparent reason”. Meta Chief Technology Officer Andrew Bosworth posted that he kept getting logged out and needing to log back in, sometimes several times within a few minutes.
Monetization Tiers and Ecosystem Friction
Meta is rolling out Muse across a pricing structure, offering a free basic tier alongside a Power tier priced at $20 a month and a Maximum tier up to $100 a month. This commercial push arrives as the broader industry grapples with the trust and permission gap surrounding autonomous execution. Financial institutions and security consortia, including the FIDO Alliance—which launched an Agentic Authentication Technical Working Group in April 2026—are scrambling to establish standardized security protocols like Visa’s Trusted Agent Protocol, Mastercard’s “Verifiable Intent,” and American Express’s ACE to govern how autonomous systems interact with consumer money.
As consumers weigh whether to trust a platform with deep access to their bank accounts, health records, and private communications, Meta’s history of regulatory scrutiny remains a heavy anchor. The company faces a legacy that includes a 2011 FTC settlement over privacy deception, a 2019 $5 billion FTC penalty, the Cambridge Analytica scandal, 2023 FTC charges for violating privacy orders, and an $18 billion multistate settlement finalized in August 2026 regarding social media harms to children. Deploying an ultra-permissive cross-app agent against that backdrop turns the current rollout into a high-stakes stress test for both Meta’s engineering guardrails and consumer digital trust.