Meta Muse can act across connected services, and it passed 2.5 million downloads by September 23 after launching on September 8. Muse interactions are used for AI training by default, although users can turn that setting off.
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What does Meta’s Muse AI agent do, how widely was it adopted after its September 8 launch, and what have reports revealed about the rushed f. Article summary: Meta’s Muse is an AI agent that works across connected apps on a user’s behalf—handling tasks such as email, shopping and travel booking from a dedicated cloud virtual machine. Launched on September 8, it quickly topped . Topic tags: general, news, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
Meta Muse is a personal AI agent that can work across connected services to handle tasks such as sending email, shopping and booking travel. It launched in the U.S. on September 8, 2026, and passed 2.5 million downloads by September 23, according to Sensor Tower data cited by CNN. That figure measures downloads—not how many people continued using Muse. 1
2
The early interest came alongside reports about security flaws, the agent’s collection of information about people in users’ lives, and how Meta handles Muse data. Here’s what the available reporting says—and what it does not establish.
Muse can work on a user’s behalf across connected apps and services, including tasks like sending emails and booking travel. Meta says each user’s agent runs in a dedicated cloud virtual machine, and users choose which services to connect. 1
2
7
Meta says it built in safeguards, including an isolated environment and a separate process that checks the agent’s interactions with the outside world. Those protections are part of Meta’s design claims; they do not mean that the system has been free of reported vulnerabilities. 4
6
Before launch, The Verge reported that Meta engineers rushed fixes for a flaw that could have allowed Muse to escape its virtual machine and reach Meta systems. The account was based on reporting by 404 Media and a source familiar with the issue.
After launch, Reuters reported on a separate vulnerability found by an outside researcher. The flaw could have allowed an attacker to access a user’s dedicated virtual machine, where connected emails and files were stored; Meta responded by strengthening an in-app safety warning.
Researchers also disclosed a flaw in the Muse macOS app that could let malware already running on a user’s Mac redirect the app’s dictation traffic and potentially take control of the agent. Meta issued a hotfix, according to security coverage.
These reports describe vulnerabilities and potential access—not proof that every Muse user’s information was accessed. They nevertheless show why a dedicated virtual machine should be understood as a security measure, not a guarantee that no flaw can occur.
Reporting on Muse’s internal instructions described a process that creates and updates a page for each person in a user’s life. That raises privacy questions for friends, relatives and colleagues who may not use Muse themselves.
Separately, Hunterbrook reported that its researchers were able to prompt Muse to compile dossiers on social-media accounts, including accounts belonging to people in vulnerable groups. These reports document researchers’ findings; they do not establish that every user’s Muse creates the same profiles or that every person mentioned is exposed in the same way.
Meta’s help information says the setting that allows Muse interactions to be used to train and improve its AI models is on when a person first uses Muse. Users can switch it off, and Meta says the change also applies to previous interactions. Meta says it removes certain categories of personally identifiable information from data used for training.
Training controls and the agent’s memory are separate issues. PCWorld reports that Meta warns Muse may still remember information it learned from material a user deleted. In other words, removing a conversation should not be assumed to erase everything the agent may have learned from it. 5
Meta presents Muse as a system with user-controlled connections and security protections, including isolated virtual machines. It has also disputed a journalist’s claim that Muse read private messages on his Mac without permission, saying that the Messages integration requires opt-in. 4
7
19
The concerns also sit within wider scrutiny of Meta’s use of customer data. Axios described Muse as part of a privacy push by a company long associated with extensive use of customer data; Muse makes that question particularly tangible because users can connect sensitive services such as email. 18
Meta has said it wants to offer a Confidential VM that would keep a user’s information private even from Meta. Meta’s help information describes that option as a future choice, and the cited coverage did not give a firm public release date. It should therefore be treated as a planned protection, not a feature users can assume is already available. 18
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Meta Muse can act across connected services, and it passed 2.5 million downloads by September 23 after launching on September 8.
Meta Muse can act across connected services, and it passed 2.5 million downloads by September 23 after launching on September 8. Muse interactions are used for AI training by default, although users can turn that setting off.
Meta has described a future Confidential VM intended to keep even the company from accessing a user’s agent data, but the cited coverage gave no firm public release date.
Meta Muse can act across connected services, and it passed 2.5 million downloads by September 23 after launching on September 8. Muse interactions are used for AI training by default, although users can turn that setting off.
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What does Meta’s Muse AI agent do, how widely was it adopted after its September 8 launch, and what have reports revealed about the rushed f. Article summary: Meta’s Muse is an AI agent that works across connected apps on a user’s behalf—handling tasks such as email, shopping and travel booking from a dedicated cloud virtual machine. Launched on September 8, it quickly topped . Topic tags: general, news, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
Meta Muse is a personal AI agent that can work across connected services to handle tasks such as sending email, shopping and booking travel. It launched in the U.S. on September 8, 2026, and passed 2.5 million downloads by September 23, according to Sensor Tower data cited by CNN. That figure measures downloads—not how many people continued using Muse. 1
2
The early interest came alongside reports about security flaws, the agent’s collection of information about people in users’ lives, and how Meta handles Muse data. Here’s what the available reporting says—and what it does not establish.
Muse can work on a user’s behalf across connected apps and services, including tasks like sending emails and booking travel. Meta says each user’s agent runs in a dedicated cloud virtual machine, and users choose which services to connect. 1
2
7
Meta says it built in safeguards, including an isolated environment and a separate process that checks the agent’s interactions with the outside world. Those protections are part of Meta’s design claims; they do not mean that the system has been free of reported vulnerabilities. 4
6
Before launch, The Verge reported that Meta engineers rushed fixes for a flaw that could have allowed Muse to escape its virtual machine and reach Meta systems. The account was based on reporting by 404 Media and a source familiar with the issue.
After launch, Reuters reported on a separate vulnerability found by an outside researcher. The flaw could have allowed an attacker to access a user’s dedicated virtual machine, where connected emails and files were stored; Meta responded by strengthening an in-app safety warning.
Researchers also disclosed a flaw in the Muse macOS app that could let malware already running on a user’s Mac redirect the app’s dictation traffic and potentially take control of the agent. Meta issued a hotfix, according to security coverage.
These reports describe vulnerabilities and potential access—not proof that every Muse user’s information was accessed. They nevertheless show why a dedicated virtual machine should be understood as a security measure, not a guarantee that no flaw can occur.
Reporting on Muse’s internal instructions described a process that creates and updates a page for each person in a user’s life. That raises privacy questions for friends, relatives and colleagues who may not use Muse themselves.
Separately, Hunterbrook reported that its researchers were able to prompt Muse to compile dossiers on social-media accounts, including accounts belonging to people in vulnerable groups. These reports document researchers’ findings; they do not establish that every user’s Muse creates the same profiles or that every person mentioned is exposed in the same way.
Meta’s help information says the setting that allows Muse interactions to be used to train and improve its AI models is on when a person first uses Muse. Users can switch it off, and Meta says the change also applies to previous interactions. Meta says it removes certain categories of personally identifiable information from data used for training.
Training controls and the agent’s memory are separate issues. PCWorld reports that Meta warns Muse may still remember information it learned from material a user deleted. In other words, removing a conversation should not be assumed to erase everything the agent may have learned from it. 5
Meta presents Muse as a system with user-controlled connections and security protections, including isolated virtual machines. It has also disputed a journalist’s claim that Muse read private messages on his Mac without permission, saying that the Messages integration requires opt-in. 4
7
19
The concerns also sit within wider scrutiny of Meta’s use of customer data. Axios described Muse as part of a privacy push by a company long associated with extensive use of customer data; Muse makes that question particularly tangible because users can connect sensitive services such as email. 18
Meta has said it wants to offer a Confidential VM that would keep a user’s information private even from Meta. Meta’s help information describes that option as a future choice, and the cited coverage did not give a firm public release date. It should therefore be treated as a planned protection, not a feature users can assume is already available. 18
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Meta Muse can act across connected services, and it passed 2.5 million downloads by September 23 after launching on September 8.
Meta Muse can act across connected services, and it passed 2.5 million downloads by September 23 after launching on September 8. Muse interactions are used for AI training by default, although users can turn that setting off.
Meta has described a future Confidential VM intended to keep even the company from accessing a user’s agent data, but the cited coverage gave no firm public release date.