Release2026-09-08

Meta launched Muse, a personal agent that reads mail, runs tasks and browses the web. Each user gets a dedicated cloud machine that stores their files and login tokens. The agent runs inside an isolated compartment and never sees real credentials. A separate component called Sentinel approves every outside action and network request. Real tokens are swapped in only at the network edge. Approval prompts appear in the app itself, not in the chat with the agent. The email connector strips one-time codes, password resets and login links. Purchases use single-use card numbers tied to one merchant and amount. Meta says its model resists hidden instructions planted in data it reads. Classifiers outside the agent check for such attempts and cannot be switched off.

What changed

Meta ran the Muse bug bounty privately with invited researchers.

What it unlocks

Anyone can now submit Muse security findings for a paid bounty.

  • up to $300,000 per valid report
  • up to $130,000 for prompt injection

What you need to act on it

  • a Muse account to use the agent
  • responsible disclosure for bounty payouts

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.