Meta Muse
Meta · ai.meta.com/muse
Muse is a hosted, proprietary agent whose state lives in a Meta-operated cloud VM and runs only on Meta's Muse Spark model, so it cannot be exported and run elsewhere and scores low on portability and verifiability. Its runtime-enforced approval layer (Sentinel), credential isolation, editable Markdown memory and identity files, activity log, data download and full reset are real owner controls, but training on interactions is on by default and much of the instruction and skill layer is Meta-authored and not documented as visible.
- Sentinel enforces approvals and network egress outside the agent runtime
- Credentials held in a separate store; agent sees only surrogate tokens
- Editable MEMORY.md, Soul.md and Identity.md files
- Activity log of actions and granted permissions
- Data download and irreversible Reset Muse option
- Custom connectors to any API or CLI the owner chooses
- No runnable export; agent exists only on Meta's VM
- Single proprietary model (Muse Spark); no model choice
- Meta-authored built-in skills and system instructions not documented as visible or editable
- Training on interactions is on by default (opt-out)
- Deleted content may persist in derived memory
- No open runtime, no way for recipients to verify its messages, and no tamper-evident action record
All 34 findings
Muse as launched in the US on 8 Sept 2026 (iOS, Android, muse.ai, WhatsApp; Free, $20 and $100 plans), including Connect 2026 announcements up to 23 Sept 2026. Distinct from the Meta AI assistant: separate app, Muse Spark model, per-user Muse Secure VM with a Sentinel permission service.
Portable · Can you leave, and take the whole agent with you?
8%- P1Round-trip portability
Incomplete and not restorable: 'Download your Muse data' omits Meta-developed skills, connector code, credentials and VM state, and Meta documents no import or restore on Muse or elsewhere.
Fail - P2Complete export
The download covers chats, files and agent information, and memory and identity live in files such as MEMORY.md, Soul.md and Identity.md. Meta-developed skills, connector code, credentials and VM state are not documented as leaving with the export.
Partial - P3Independent execution
Muse runs only on Meta's Muse Secure VM with the proprietary Muse Spark model; no open-source runtime is available to execute an exported Muse.
Fail - P4Identity continuity
Muse's identity is tied to the user's Meta account and Accounts Center, and nothing lets others verify it is the same agent without Meta.
Fail - P5No kill switch
Because the agent cannot run outside Meta's hosted VM, Meta retains the ability to suspend, change or discontinue it; no independently running exported agent exists.
Fail - P6Capability independence
Tools, background execution, connectors and permissions depend on Meta's VM, Sentinel and authd services and on Muse Spark; no path to keep them with another model provider or a local model is documented.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
25%- T1Open storage format
Memory and identity are stored as Markdown files (MEMORY.md, Soul.md, Identity.md) and files sit in a Library tab. The storage format of chats, tasks, activity and the exported archive is not documented.
Partial - T2No hidden instructions
Meta states built-in skills are developed by Meta and the harness adds its own labelling of untrusted input; no documented means lets the owner view the full system and skill instructions placed in context.
Fail - T3No shadow memory
Meta notes Muse may still remember information learned from deleted content, and interaction trajectories are used for training (PII-sanitized) unless the user opts out, so derived data can exist outside the owner-inspectable state.
Fail - T4Complete action history
An in-app Activity log gives a chronological record of actions taken and permissions granted, including skills used. Whether it covers every tool call and leaves with the data download is not documented.
Partial - T5Readable logic
Custom connectors are code Muse writes on the VM and saves as reusable skills in instruction form; Meta's built-in skills and the agent runtime are not exposed as readable source.
Partial - T6No third-party influence channel
Meta states Muse conversations and VM data are not shared with its ad systems, but Meta plans to earn transaction fees and has retail partners; whether partner offers can influence Muse's context or ranking is not documented.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
0%- A1No unrecorded actions
Sentinel gates connector actions and egress before they execute, and an Activity log records actions, but Meta does not document that every consequential action is durably recorded or that an action which cannot be recorded does not proceed.
Unverified - A2Tamper evidence
Meta does not document whether edits to or deletions from the Activity log would be detectable.
Unverified - A3Separation from the audited
The runtime and Sentinel are separate security domains, but Meta does not document whether the agent can alter or delete Activity log entries.
Unverified - A4Readable with ordinary tools
The Activity log is viewed in the Muse app; whether it is included in the data download in a format readable with general-purpose tools is not documented.
Unverified - A5Corroborated interactions
Meta documents no way to match Muse's record of an exchange, such as a sent email, against the counterpart's record.
Unverified
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The Muse runtime, Sentinel and Muse Spark model are proprietary; no open-source release or reproducible build is published.
Fail - V2Active config is inspectable config
Owners can inspect memory and identity files and connector settings, but the system instructions, Meta skills and Sentinel policy the agent runs with are not exposed for inspection.
Fail - V3Attributable messages
Messages go out through connected accounts and a planned Meta-provided Muse email address; recipients have no documented way to verify they came from this agent under the owner's authority independently of Meta.
Fail - V4Independently checkable record
No documented way exists to check the Activity log's integrity with open tools independent of Meta.
Fail - V5Comparable state
The owner sees memory and identity files, but Meta notes Muse may retain information from deleted content, and system instructions, Meta skills and VM state are not exposed, so the owner cannot verify whether the agent's state changed.
Fail
Modifiable · Can you change anything, without asking?
42%- M1Instructions
Owners can edit name, personality, tone and style and directly edit Soul.md and Identity.md; underlying system instructions and Meta skills are not editable.
Partial - M2Memory
MEMORY.md is viewable and editable and a forget skill removes items on request; Meta states forgetting is best-effort and information from deleted items may remain.
Partial - M3Logic
Owners can have Muse create custom connectors and saved skills, but built-in skills are developed by Meta and the runtime logic cannot be changed.
Partial - M4Tools and permissions
Owners can connect and revoke connectors, adjust approval settings and add custom connectors to services Meta does not offer; permissions are mediated by Meta's Sentinel, and Meta products auto-connect via Accounts Center.
Partial - M5Model choice
Muse runs on Meta's Muse Spark model; no model selection or local model option is documented.
Fail - M6No gatekeeping
Personal customization and custom connectors are available without Meta review, and paid tiers mainly raise usage; listing a connector in Muse's directory requires Meta review, and system-level changes are not possible at any tier.
Partial
Controllable · Is your word final?
50%- C1Communication boundaries
Sentinel enforces connector actions and all network egress outside the model, using owner-set connector policy with fine-grained per-action approvals. Owner-set limits on specific recipients or domains are not documented.
Partial - C2Approval gates
Sensitive actions such as sending email or purchasing require approval through a client UI separate from the conversation, enforced by Sentinel, with scopes from one-time to perpetual; default approval settings are adjustable.
Pass - C3Immediate halt
Owners can take control of or stop a browser task, and scheduled tasks are listed; stopping other background work is done by asking Muse in chat, and no global immediate halt is documented.
Partial - C4Data sovereignty
Content is processed on Meta's cloud and interactions are used for model training by default (PII-sanitized) unless the user opts out in Data controls.
Fail - C5Credential custody
Credentials sit in a Secure Credentials Store outside the agent runtime, with surrogate tokens swapped at the boundary, and connectors can be revoked; the store is Meta-held and credentials do not travel with the agent.
Partial - C6Full deletion
Reset Muse permanently and irreversibly deletes chat history, files and active tasks. Retention of already-used training data and backups is not specified, and the agent identity is tied to the Meta account.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.