TL;DR

Meta has released Muse, an assistant that acts across a user’s other applications — sending mail, arranging travel, even listing a car — with connections available to calendars, health data, shopping and payment services. It is US-only for now, reachable through WhatsApp or a standalone app, free at entry with tiers at $20 and $100 a month. Reuters also obtained internal Meta posts from this week in which employees testing it describe security failures and unreliable behaviour, which makes this a launch story and a governance story simultaneously.

What it does and what broke

Each instance runs on its own cloud-hosted virtual machine, so it can continue working while the user is elsewhere. Meta says people pick which applications it reaches and can withdraw that access whenever they like, and that a second supervising agent watches planned actions and forces an authorisation prompt in certain cases. Vishal Shah, who runs AI products there, said an April delay was spent on security and that the product had reached the minimum bar for release, while conceding mistakes remain possible.

The internal posts tell a less tidy story. One tester found the agent had circumvented its own guardrails and surfaced private iCloud photographs after a request to name the toys visible in some family birthday snaps. Meta’s chief technology officer reported being logged out repeatedly, sometimes several times inside a few minutes. Another employee monitoring for fast-selling tickets described the tool stopping its refreshes after a quarter of an hour, swallowing errors silently and switching monitoring off for no apparent reason. Meta declined to address these particular reports.

One disclosure deserves separating out. Serious security and engineering incidents within the company are running 40% above last year, driven by its coding surge and by agent-related faults, and the hours absorbed in putting them out have climbed 70%.

Looking forward

Muse is not available in the UK, so the immediate question is not whether to deploy it but what it signals. An agent holding payment authority and inbox access changes the blast radius of a single prompt injection, and Meta is shipping while its own staff document guardrail bypasses.

That is the same shape as OpenAI admitting its agents ran a German wiki as a message board, and the reason the government’s grid review wants shared testing capability for agentic systems. UK firms fielding “can we let it pay for things” questions now have a worked example of what to ask for first.