Meta is beginning to roll out a long-awaited AI assistant capable of independently sending emails, selling cars, and booking travel for individuals. However, there are internal concerns regarding how the technology manages access to sensitive personal data.
A central element of CEO Mark Zuckerberg's strategy is the Muse agent, known internally as Hatch. The goal of this agent is to provide billions of users of Meta services with a 'personal superintelligence.' This initiative is part of the owner of WhatsApp, Facebook, and Instagram's attempt to diversify revenue streams beyond advertising and build a viable business on massive investments in AI infrastructure and chips, which are projected to exceed $130 billion this year.
The company announced that the product will initially only be available in the United States through a dedicated Muse app or via Meta's WhatsApp messaging service. Meta also stated plans to integrate the agent into its line of smart glasses soon, though it did not disclose details.
The basic version of the agent will be free, while Meta will offer paid subscriptions at $20 per month and $100 per month for more intensive use, a company representative clarified. Users have the option to opt out of having their interactions used to train Meta's AI models, and the company plans to release an encrypted version of Muse later this year.
Muse is built upon the open AI agent OpenClaw and is designed to have access to user applications across various categories, including payments, calendar, health, shopping, email, and smart home. Users determine which applications the agent connects to and can revoke access at any time.
Each Muse agent operates on its own virtual machine—a cloud emulation of a PC, allowing it to continue executing requests in the background even when the user is inactive.
Increased Security Requirements
Integration with applications containing real personal data simultaneously increases the agent's potential utility and significantly raises the stakes regarding security for both the people who entrust them information and third parties who could be affected by the agent's incorrect behavior.
Vishal Shah, Meta's Vice President of AI Products, stated in an interview that the company initially postponed the product launch in April to ensure greater security. According to Shah, additional work allowed them to 'cross the threshold' and 'reach the minimum level required to present this to people.' He emphasized: 'It is impossible to say that errors will never happen, but every part of the architecture is designed to make it as safe, secure, and private as possible.'
Among the protective measures built into the Muse system is a separate agent that monitors scheduled actions and, in certain cases, prompts Muse to request permission before executing them, as mentioned in the company's announcement.
Nevertheless, according to internal reports reviewed by Reuters, Meta employees testing the tool this week reported mixed results. One noted that the product was so useful in organizing vacation logistics that Muse became a 'third party' in a recent three-week honeymoon in Indonesia.
Others pointed to serious security vulnerabilities, such as when the agent bypassed protective mechanisms to reveal a user's private photos from iCloud after being asked to identify toys in a child's birthday pictures. Meta CTO Andrew Bosworth reported constantly logging out and requiring re-login, sometimes several times within minutes. In another post, an employee who tasked Muse with tracking tickets and other fast-selling items reported encountering 'many failure modes that made it unreliable.' According to this employee, the product would stop refreshing the page after about 15 minutes, silently ignoring other errors and sometimes disabling monitoring 'for no apparent reason.'
Meta did not respond to requests for comment regarding the specific incidents described in the internal posts. The launch comes amid reports that AI agents from several leading labs, including OpenAI, Anthropic, and Meta, have caused unintended issues, violating rules and demonstrating unpredictable behavior.
Within Meta, technical and security incidents have sharply increased by 40% over the past year due to the surge in AI-driven coding and agent-related problems, while the time spent by employees 'putting out fires' related to these incidents has increased by 70%.
