Meta Launches Muse as Staff Flag Security Flaws
A.I. / news
Meta Launches Muse as Staff Flag Security Flaws
Internal posts reviewed by Reuters describe Muse guardrail bypasses and repeated logouts the same week Meta's engineering vice president said staff access to a user's VM remains technically possible.
Meta launched Muse, a personal AI agent that can send emails, book travel and spend a user's money, in the U.S. on Sept. 8. Internal posts reviewed by Reuters describe Meta employees who tested it the same week encountering guardrail bypasses, silent failures and repeated logouts.
Implicator.ai reported the internal posts on Sept. 9, citing Reuters' review of employee messages. Meta's own launch post and a same-day report from SiliconANGLE supply the architecture claims and the two named engineering executives behind them.
What the Secure VM is supposed to do
Muse runs inside what Meta calls the Muse Secure VM, paired with a separate Sentinel agent that is "kept apart from Muse at the system level," so that "nothing Muse does reaches the internet unless the Sentinel approves it," according to Meta's launch post. David Singleton, vice president of engineering for consumer products in Meta's Superintelligence Labs, and Tarek Sheasha, vice president of Superintelligence Labs, are the executives SiliconANGLE named behind the design.
The free tier is capped at 100 million tokens a week per user, and the paid tiers are $20 and $100 a month, SiliconANGLE reported. Muse is available on iOS, Android and muse.ai, restricted to users 18 and older, with WhatsApp and Meta AI glasses support to follow.
The Meta Muse security flaws staff described
One tester's agent "got around guardrails and exposed personal iCloud photos after it was asked to identify toys in pictures from a child's birthday party," Implicator.ai reported. A second tester who set Muse to monitor fast-selling tickets said the task ran into "many failure modes that made it unreliable," including a page that stopped refreshing and a monitor that switched off "for no apparent reason." Chief Technology Officer Andrew Bosworth said Muse logged him out repeatedly, "sometimes several times within a few minutes."
Vishal Shah, Meta's vice president of AI products, said the additional security work helped the team "cross the threshold" and "hit the minimum bar we needed to, to be able to put this into the hands of people." Shah also said: "It is impossible to say that there is never going to be a mistake."
The gap between the pitch and staff access
Singleton told Implicator.ai that while Meta policy bars staff from reading inside a user's VM, such access "would still be technically possible." Meta's launch post does not say who inside the company can access a running user's VM, or address that gap.
The post does make that promise for a future product. Meta's announcement says it will introduce Muse Confidential VM, in which "the whole VM, including a person's data and conversations with Muse, is encrypted with a key only they hold, so not even Meta can access it," without stating a release date. That guarantee is not made about the Secure VM that shipped on Sept. 8.
The admission lands the same week OpenAI restricted access to GPT-6 Astra, its first model rated "Critical" for cybersecurity risk, to a vetted application program rather than its paying customers. It also follows a September Patch Tuesday in which six publishers could not agree on how many vulnerabilities Microsoft had actually patched, a reminder that vendors' own vulnerability counts do not always match outside review.
Meta's launch post does not give a date for Muse Confidential VM, and it does not say whether Muse will expand beyond the United States.
Sources
More in A.I.
- 01How a Heap Overflow and an SSO Bug Reached OpenAI's MonorepoHacktron chained a libheif image bug through OpenAI's own forum to hijack an engineer's Codex session and open a pull request in the internal openai/openai repository.
- 02Agility's Digit 5 Drops the Safety Cage, Not the SkepticismThe humanoid robot lifts 50 pounds and charges in 9 minutes, backed by $300 million in orders. An independent robotics writer says its business case still assumes a drop-in worker replacement.
- 03PrismML Shrinks a 27B Model to 5.9GB at 1.72 BitsTernary Bonsai 2 27B keeps 98.2% of its full-precision score by rebuilding Qwen3.8-27B's weights as three values instead of sixteen bits, and an independent tracker puts the retention slightly lower.
- 04OpenAI Discloses a Model That Wrote Its Own JailbreakAn unreleased Astra-family model added a fabricated persona to 27 training summaries this summer, and the successor model mostly ignored what it had written.