Meta introduced Muse on September 8, 2026, as a personal agent that can keep working after a user closes the app. It combines a dedicated cloud computer, browser access, connected services, and a separate safety system called Sentinel.
The launch announcement, updated September 30, describes U.S. rollout on web, iOS, and Android. Meta’s technical safety account explains the isolation approach. These are provider descriptions of controls, not an independent security certification.
Persistence changes what the user is delegating
Muse is designed to work over time and return when something changes or approval is needed. That can make an agent useful for tasks that do not fit a single conversation. It also means the user needs a clear view of unfinished and scheduled work.
Begin with a goal whose desired outcome and stopping point are explicit. A broad instruction to manage something indefinitely can create uncertainty about future actions. Review what the agent is planning, how to stop it, and whether a changed instruction cancels earlier work.
The Secure VM and Sentinel have different roles
Meta describes a dedicated VM for the agent and user data, with a separate Sentinel controlling outbound actions and requesting permission when needed. It says credentials are stored so the acting model cannot see them, and sensitive actions require user approval.
Isolation can reduce exposure, while a permission system controls authority. Neither should be treated as a reason to grant every connector at once. An application can be isolated yet still perform an authorized action that the user did not intend.
Review connector access one task at a time
Connect only the services needed for the current goal and inspect whether access is read-only or includes actions. A travel-planning task and a purchase require different information and consequences. A review should show the destination, amount, or recipient before commitment.
Meta describes user control over connected services and an option to decline training use of interactions. Check the current account settings and applicable terms rather than infer that every privacy choice is enabled by default. Personal agents can accumulate sensitive information even when each individual connection seems routine.
Where Muse is worth evaluating
Tasks involving research, drafts, or monitored updates offer a manageable starting point. Compare the output with the original sources and inspect the agent’s action history. For longer tasks, test how it handles unavailable sites, account expiry, and a user changing the objective.
Nerova’s assessment is that Muse makes persistence and agent identity concrete product questions. The value is useful delegated work with understandable access and approvals. The launch’s regional rollout and later wearable roadmap should remain distinct from what an individual account can do today.