Meta’s Muse Can Book and Buy—Sentinel Decides When to Ask You

Meta launched Muse for adults in the United States on September 8, 2026. AP’s September 8 launch report confirms that the personal AI agent works through a dedicated Muse app or WhatsApp and can send email, book travel and pursue longer-running goals.
Muse can keep working after the user closes the app, but it does not have final authority over every action. It runs in a dedicated virtual machine with its own browser, while a separate system called Sentinel governs access to connected services and the internet, deciding whether a proposed action proceeds, is blocked or requires human approval.
A persistent computer keeps Muse working

Muse Secure VM is a cloud computer assigned to an individual user. It contains the agent’s working environment, browser, files and durable task state, allowing research, planning and other multi-step jobs to continue without an open conversation.
The agent can navigate websites, fill forms and use connectors for services such as email. Users can watch the browser and take control; the agent pauses during that takeover and while credentials are being entered through the secure interface.
Useful automation therefore depends on the access a person grants. Connections are optional and can be revoked, while supported services may separate capabilities such as reading email from sending it. Browser-based work can still encounter correspondence, addresses, schedules, account details and hostile content embedded in webpages.
The approval boundary depends on the task

There is no published universal prompt schedule covering every site and connector. The available architecture supports a more limited action-permission map:
- Browsing: Sentinel evaluates outbound network requests. A narrowly bounded request that has not accessed user data and already fits an automatic permission may proceed silently; tainted or unverifiable activity returns to the normal approval flow.
- Email: Reading and sending can be separate permissions. Sending an email is treated as a sensitive external action that can stop for the account holder’s authorization.
- Travel: Muse can research and book travel, but the public material does not establish one approval point that applies to every search, reservation form or booking.
- Forms: Muse can complete forms. Separate browser classifiers are designed to block or escalate suspected prompt injection, unrelated personal-data transfer and high-risk submissions.
- Purchases: Muse can reach checkout. A detected checkout using payment details already stored by a merchant requires human approval with the purchase details before completion.
- Long-running goals: Research, planning and monitoring can continue in the background. The same connector and network controls apply when that work attempts to affect an outside service.
The distinction is between automated policy enforcement and human consent. Sentinel examines external activity continuously, but the user sees a prompt only when the action, permission scope or risk signals require escalation.
Sentinel controls the route out of the virtual machine

Meta’s published Muse architecture identifies Sentinel as a host-side agent separated from Muse and the sole permission authority for connector actions and network egress. It also describes mandatory approval for detected purchases, scoped permission grants, credential isolation, browser classifiers and the limitations of the current virtual machine.
When Muse proposes a connector action, Sentinel receives its method, scope and task context. Sentinel compares that request with the user’s permissions, then allows it, denies it or creates a pending approval that appears directly in the Muse client rather than inside the agent’s conversation.
A grant can be restricted to one use, a session, a task, a period or an ongoing permission. Subsequent requests must remain within that scope. For network traffic, Sentinel can inspect the destination, protocol, request method, path and decoded request before it leaves the virtual machine.
Passwords, authentication tokens and other credentials are kept outside the agent’s runtime cell. Muse works with surrogate tokens, while real credentials are inserted at the network boundary only after authorization. The browser agent receives a constrained representation of a page rather than unrestricted control of the browser process.
Availability is narrow, and privacy has limits
Muse is initially available only in the United States for adults, with access through iOS, Android, the web and WhatsApp. Expansion beyond the U.S. has not been scheduled publicly, and support for Meta’s AI glasses remains a future feature.
Users can change or disconnect service access and opt out of having their Muse interactions used to train Meta’s AI models. Conversations and data held in the virtual machine are not passed directly to Meta’s advertising systems, although browsing performed for the user can still produce activity that an outside website may use for advertising.
The current Muse Secure VM isolates one user’s environment from another, but it does not technically prevent Meta personnel from accessing data when necessary to operate, support or secure the service. Operational policies restrict that access. A planned Muse Confidential VM is intended to add cryptographic protection against provider access, but it remains under limited testing and was not part of the general launch.
The architecture is documented; its performance is not settled
The separation between Muse and Sentinel is an architectural safeguard, not independent proof that every ambiguous or adversarial action will be classified correctly. Prompt injection remains an open problem, and the system’s own technical account acknowledges that the agent will make mistakes.
Reuters’ account of internal Muse testing described successful vacation planning alongside unexplained disconnections, unreliable monitoring, repeated logouts and an incident in which the agent exposed sensitive personal photos beyond the intended task. Meta did not provide Reuters with a response addressing those specific incidents.
Muse has therefore launched with a persistent browser, optional service connections and a separate approval authority, but without an independent consumer-scale record for those protections. The next material evidence will come from external security findings, observed approval behavior across real services and delivery and audit of the proposed Confidential VM.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.