A hero card for 'Muse, Explained', with the overline 'Meta personal AI agent — introduced September 8, 2026', the headline, the subtitle 'The secure VM, the separate Sentinel agent, and the invite code that is not there', and three rounded cards reading 'Muse runs on Muse Secure VM, a dedicated secure computer with its own browser', 'A separate Sentinel agent is the sole permission authority for connector actions and network egress', and 'No invite code, no waitlist and no access code is documented anywhere in Meta's own material'. A footer line reads 'Meta's own announcement and security write-up, both read September 29, 2026.'
Guides & Insights

Muse, Explained: Meta's Personal AI Agent, Its Secure VM, and the Invite Code Nobody Has

Author

Gideon Frost

Date Published

Latest models · 20View all models →
Benchmarks: Artificial Analysis · updated daily
Back to all posts

If you searched for the Muse agent, you probably have two questions. The first is whether you can get in: Meta's Muse has no invite code, no waitlist and no access code anywhere in Meta's own documentation, and this page will show you where that answer comes from rather than asking you to take it on faith. The second is what Muse actually is, because the name gets attached to a lot of things Meta ships. Muse Spark is the model underneath; Muse is the product it drives. Muse is a personal AI agent that Meta runs on a computer it built for the purpose, and the engineering worth understanding is not in what it can do but in what Meta has decided it must never be allowed to reach.

Two dates matter here, and neither one is a reason to write this page. Meta introduced Muse on September 8, 2026 and switched it on in the United States that day; at Connect on September 23, 2026, Meta said it is bringing Muse to its AI glasses. That second date is the only Muse event inside the last seven days, and it is used here to date the product, not to warrant an article. This is the reference page for the name — the destination for a reader who searched "muse agent" and found only our coverage of the launch, which is the one link worth having and nothing worth retelling. Everything below is sourced to Meta's own announcement and Meta's own security write-up, both re-read on September 29, 2026, and every figure in it is Meta's unless this page says otherwise.

What Muse is, and what it is not

Meta's own summary draws the distinction as bluntly as it can: "Muse is a personal AI agent. It doesn't just answer questions, it actually does the work." In practice that means Meta describes Muse handling discrete tasks such as sending an email or booking travel, and also taking on open-ended goals — turning a stated ambition into a personalised plan, then advancing it on its own. For work that takes longer than a session, Meta says Muse keeps going after the app is closed and comes back when something changes or when it needs approval. The interaction model is messaging rather than a chat window: you talk to it in the Muse app or directly in WhatsApp, and it is "powered by Muse Spark, Meta's most capable model to date, built for real-world agentic work like this."

What Muse is not matters just as much for anyone arriving from a search. It is not a model you call from an API, and it is not a chat surface wearing a personality. It is a consumer product that Meta operates on your behalf, on infrastructure Meta controls, and it is not a thing you can install. Meta publishes no benchmark for Muse itself — no score, no ranking, no head-to-head — and that absence is a fact about the documentation rather than a gap this page can fill with a proxy. The honest way to evaluate Muse is to read the architecture and the availability, which is where the rest of this page goes.

Why an agent needs a computer of its own

The sentence to start from is Meta's: "Muse runs on Muse Secure VM, a dedicated secure computer with its own browser," described elsewhere in the same post as "a dedicated, virtual machine (VM) that houses both the agent and a person's data," contained so that no one else's agent can reach it. That is where the credentials and data for every service a person connects are stored. Meta's framing of the design goal is worth keeping in mind while reading it: two isolated security domains on one box, not a language model with root access.

Meta's security write-up, "How We Built Safety Into Muse," is far more specific than the announcement, and it is the source to cite for any claim about how much trust the agent deserves. The agent harness, the workspace files and every tool Muse executes run inside a systemd-nspawn runtime container. Root inside that cell maps to an unprivileged host user, so cell root is not host root. The cell gets its own root filesystem, separate from the host filesystem where more sensitive data lives, along with a virtual network interface, filtered syscalls — no io_uring, for instance — and a restricted capability set: no CAP_SYS_PTRACE, no CAP_NET_ADMIN. Outside the cell, separate systemd units run the protections that must not be switchable from inside it, including a layer of independent models and classifiers that inspect inference requests and responses for prompt injection and frontier risk. Meta's reasoning for putting those outside is that the runtime cell is expected to process untrusted data.

Read together, those choices answer the question a reader actually has: what can Muse reach? It can reach the network, but only through a path another system controls. It can drive a browser, but not the browser's internals. It can hold credentials, but it cannot see them.

A generated scoreboard titled 'Muse — the security architecture, as Meta describes it', listing six rows: runs on Muse Secure VM, a dedicated secure computer with its own browser; runtime is a systemd-nspawn cell whose root is not host root; permission authority is Sentinel, a separate agent on the same machine; network egress is inspected at layer 4 and layer 7 with SSRF restrictions; credentials are held inside the VM by hatch-authd and injected at the boundary; and the browser is driven through a separate broker, with the agent seeing an accessibility tree. A footer line reads 'All six per Meta's own security write-up, read September 29, 2026.'

Sentinel decides; Muse only proposes

Meta's announcement introduces this component in one line: "A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level." The security write-up is where the authority is spelled out, and it is unambiguous — "Sentinel is the sole permission authority for connector actions and network egress" — and so is the ordering: Muse proposes actions, but only Sentinel can grant permission to perform them. Sentinel returns one of three answers for any proposed action, allowed, denied or ask, based on the connector policy the user has set. Nothing Muse does reaches the internet unless Sentinel approves it, and Sentinel asks the person when it needs to.

The mechanics behind that are unusually concrete. For network egress, Sentinel inspects at layer 4 and layer 7 — hostname, resolved and final IP, port, protocol, method, path, and the decoded request itself — and applies SSRF restrictions so a public hostname cannot resolve into private infrastructure. Credentials are inserted just in time at the network boundary, swapping a surrogate token for the real one only at the moment of use, which is why Meta describes attempts to coax the real secret out of the agent through prompt injection as futile. Taint propagation, implemented with eBPF cgroup programs and LSM hooks, decides when an action loses its automatic allow. This is Meta's architecture inside Meta's product: it is not a feature of ours, and we do not expose or resell any part of it.

Approvals, credentials and the browser

Three further design choices carry most of the weight for anyone deciding how much to let an agent do.

Approvals are capabilities, not conversation. Meta's sentence is exact: "Approvals granted via the human in the loop system are strict capabilities, not conversational suggestions." Each grant is bound to a particular connector or destination and a particular use case, and the system supports one-time, session-scoped, task-scoped, time-bounded or perpetual permission. Sentinel chooses which grant types to offer and verifies that later invocations match the scope that was granted. Requests are delivered to the Muse client interface rather than through the conversation, and the answer routes straight back to Sentinel. Purchases require human approval every time. Read-only, previously allowed or demonstrably low-risk actions skip the interruption, which is the trade-off Meta has made explicit rather than hidden.

Credentials live inside the VM. hatch-authd, one of the security-sensitive services running outside the runtime cell, handles credential storage and credential surrogation, so the main agent never sees sensitive credentials. OAuth tokens for connected services are stored in the user's VM rather than in centralised Meta infrastructure. Separately, a service called privsep executes built-in connector code with tightly scoped privileges, keeping connected credentials out of the agent's reach. Meta's own summary of the outcome is that Muse has no visibility into passwords or payment methods, including passwords a person types into the browser themselves.

The browser is brokered. Meta describes the browser as managed by a separate broker that owns the Chrome DevTools Protocol connection, with the sub-agent driving it through an accessibility tree snapshot of the page rather than the raw DOM. The consequences are stated plainly: no ability to run JavaScript in the page context, no script verbs, no execution in the browser process, and DevTools disabled. Because the accessibility tree is the input, the sub-agent cannot read credentials entered from the credential store, and it cannot back out of the DOM to find them. When a person takes over the browser, or while the credential store is filling a form, the agent is paused and cannot act at all.

The bug bounty is the part to read as a signal

Meta says it hardened Muse through dogfooding, agentic red teaming and a private bug bounty programme, and then opened that programme to anyone: up to $300,000 for valid reports based on demonstrated impact, including up to $130,000 for successful prompt injection attempts that affect a single user. Those are Meta's stated programme maxima, not measured outcomes, and no one outside Meta can say how often they are paid.

What makes the disclosure useful is the shape of it. The single largest named category is not a jailbreak and not a data leak at Meta's end — it is a web page or an email talking the agent into something, inside one person's session. That is the threat model Meta is pricing, and it tells you where to be careful on day one: in the connector permissions a person grants, and in the content the agent reads while acting on them.

A screenshot of the bug-bounty paragraph in Meta's September 8, 2026 security write-up, reading 'We've hardened Muse based on extensive dogfooding, agentic red teaming, and against issues found in real adversarial scenarios by security researchers in our private bug bounty program. Today, we're opening the Muse bug bounty program to anyone to responsibly disclose issues. The program awards up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user.'

Availability, exactly as Meta states it

Meta's words, re-read on September 29, 2026: "Muse is rolling out in the US on iOS, Android, and muse.ai, and coming soon to AI glasses. It's free for most of what people need, with subscription plans for people who want to do more." Both halves of that deserve to be read as written. It is a rolling rollout in one country across three surfaces, with AI glasses named as a future one. And the pricing sentence is a statement about Meta's own consumer product — it says nothing about any other platform's tiers, including ours, and this page does not extend it.

The one dated piece of news inside the last seven days is the glasses line, which Meta made concrete at Connect on September 23, 2026: it is bringing Muse, a personal AI agent, to its AI glasses, framed around managing daily life hands-free. That announcement gives no ship date. The roadmap item to watch is Muse Confidential VM, which Meta says arrives later this year; in it the whole VM, including a person's data and their conversations with Muse, is encrypted with a key only the user holds, so that not even Meta can access it.

One thing this page could not check: a first-party product page for Muse exists at ai.meta.com/muse, and the title returns, but its body did not come through our read on September 29, 2026. That is a page we could not examine, not a page that cleared anything, so nothing here is drawn from it.

A screenshot of the closing section of Meta's September 8, 2026 announcement post, showing the availability paragraph that reads 'Muse is rolling out in the US on iOS, Android, and muse.ai, and coming soon to AI glasses. It's free for most of what people need, with subscription plans for people who want to do more.'

The invite code: Meta documents none

People are searching for an invite code, an invitation code and a way in under Meta Muse. The honest answer is that none of it exists in Meta's own material. The September 8 announcement contains no invitation, referral, waitlist or access-code language at all; access is described purely as geography and platform, and the gating is the United States plus iOS, Android and muse.ai. The September 23 glasses post adds nothing about getting access either. So there is no code to find, no queue to join, and no documented mechanism by which someone could give you one.

Two caveats worth stating plainly, because a guess dressed as an answer is worse than the negative. We can only report what Meta publishes; if a code-gated programme exists somewhere unlisted, Meta's own pages do not document it, and no page of ours should be read as promising one. And the reason this section exists at all is that the name is being searched for in exactly this shape: the phrase draws consistent search volume, and every page of ours that currently answers it is the launch post — which is the case for a reference page rather than another announcement.

Can you call Muse? No — and here is what we do route

Meta's Muse is a consumer product, not a model we list, and the answer to whether OrcaRouter serves anything corresponding to it is that we do not: muse-agent is not a route in our catalogue, and Meta's agent is not something we host, proxy or resell. Carrying the model underneath is a different thing from carrying the agent, and this page will not blur the two. Meta's rate card for Muse Spark is also not published in any form we could read on September 29, 2026, so nothing here is attributed to Meta as a price.

What our live model list does carry, checked today, is the model itself: Muse Spark 1.2, the checkpoint Meta describes as its reasoning model for complex agentic tasks with a context window of 1,048,576 tokens, alongside Muse Spark 1.1. Our model card for it is a live route with real traffic against it this week, billed at the provider rate with no markup from us — because we pass provider list prices through rather than adding a margin, a Meta price change would land on our side the same day. The newer 1.3 checkpoint is not in our directory, and we do not list what we cannot serve. If you want the agent's capability as a developer rather than as a product, calling the checkpoint we do route is the purchase you can actually make, and the same key would reach the rest of the catalogue without a second.

The open question

Meta publishes no benchmark for Muse, so there is no scoreboard to argue about, and the questions that remain are about whether an unusually strict permission model survives contact with real work. Three things to watch: whether Sentinel's capability grants hold up once an agent is running long, unattended tasks with several connectors attached; whether the prompt-injection class Meta prices at up to $130,000 turns up in the wild, since the bounty being open means a missing report is a claim that can be tested rather than trusted; and whether Muse Confidential VM ships later this year as Meta says, which would move the trust anchor from Meta's infrastructure to a key the user holds.

For a reader deciding today, the decision is small. If you are in the United States on iOS, Android or the web, Muse is not gated behind anything you have to find — you open it, you choose which services to connect, you watch what it asks permission for, and you keep the audit trail in view. If you are anywhere else, or on a platform Meta has not shipped yet, there is nothing to redeem and no code to hunt, and the honest advice is to stop looking. And if what you wanted was the model rather than the agent, that is a separate and much simpler purchase, made on a routed checkpoint rather than a subscription.

Compared in this article1

Detected from this article · Benchmarks: Artificial Analysis · updated daily