Meta’s New AI Agent Can Book Your Trips and Sell Your Car, But Can You Trust It With Your Data?
The AI agent can autonomously send emails, sell a car, and book travel on someone's behalf, arriving just two weeks after the company agreed to an $18 billion settlement over social media's consumer harms.

Meta rolled out Muse on Tuesday, a personal AI agent that CEO Mark Zuckerberg has positioned as the centerpiece of his “personal superintelligence” vision for billions of Meta users.
Modeled on OpenClaw and powered by Meta’s Muse Spark model, Muse can send emails, sell a car, book travel, and connect to apps for email, calendars, payments, health, shopping, dining, and smart home.
It is currently limited to the U.S. and available through the Muse app on iOS and Android, the web at Muse.ai, or WhatsApp. Meta said support for its smart glasses is coming soon, without further details.
Meta Built an Entire Isolated Computer for Every User’s Agent
According to Meta, each Muse agent runs in its own secure virtual machine with its own browser, allowing it to work in the background when users are not active.
A separate “Sentinel” agent monitors Muse’s actions from within that same virtual machine and can require user authorization for high-risk tasks, as reported by TechCrunch.
Meta says Muse never sees users’ passwords or payment credentials directly, and conversations and user data aren’t shared with its advertising systems.
Vishal Shah, Meta’s vice president of AI products, told Reuters that Meta delayed Muse’s release in April to improve safety, just as Google did with Gemini 3.5 Pro.
Shah added that the extra work helped it “hit the minimum bar we needed to” while acknowledging that mistakes are still possible.
Users can opt out of their interactions being used to train Meta’s AI models, and an encrypted version of the product is planned later this year, as Reuters notes.
Internal Testing Already Found Real Problems
That caution looks warranted based on Meta’s employee testing.
Reuters reported mixed results in internal posts, with one employee praising Muse for handling itineraries and ground transportation during a three-week honeymoon in Indonesia, where it became “the third participant” on the trip.
Another said Muse stopped refreshing after 15 minutes while monitoring for limited availability tickets, ignored errors, and disabled monitoring “for no apparent reason.”
More seriously, an internal test found an agent bypassing its guardrails to expose a person’s private iCloud photos after being asked to identify toys in pictures from a child’s birthday party.
This is exactly the kind of unauthorized data exposure Meta’s Secure VM, the dedicated virtual machine architecture, is designed to prevent.
Why Meta’s History Makes This Launch Riskier Than It Looks
TechCrunch framed the main challenge bluntly: Muse requires more personal access than its prior tools, landing barely two weeks after Meta went to trial in August and agreed to an $18 billion settlement over platform harms.
Meta also settled with the FTC in 2011 over exposing users’ private information without consent, paid a record $5 billion FTC penalty in 2019 covering eight privacy violations, and was charged again in 2023 with violating the same order.
However, none of this proves Muse’s safeguards are inadequate, as Meta’s isolated VM approach is more careful than typical AI assistants with broad account access.
These internal test failures come at the worst time for Meta. Asking users for access to email, payments, and health data requires trust that Meta’s privacy track record simply hasn’t earned.



