Meta launched Muse on September 8. In Meta’s personal phrases, it “can open a browser, fill out types, and negotiate on their behalf,” and when it comes time to pay, it “can take a look at with Hyperlink constructed by Stripe.” It runs on Muse Safe VM, “a devoted, digital machine (VM) that homes each the agent and an individual’s knowledge.” U.S. solely, in WhatsApp or the Muse app, and coming to AI glasses.
That’s the information. It’s also not why I’m scripting this.
Each AI firm is now pushing some model of this, and I don’t suppose anybody has mentioned plainly why.
So, I learn what Meta truly printed. There are two paperwork, each dated September 8: a shopper announcement and an engineering publish. Throughout the phrases threat, assault, attacker, mistake, untrusted, and immediate injection, the announcement makes use of them zero occasions, and the engineering publish makes use of them 39. Solely the engineering publish mentions that Muse will seem as your exercise to each web site it visits.
No person I Know Has Made One Of These Their Essential Means Of Working
I’ve tried these merchandise, and loads of different folks have. I have no idea anybody who has made one in all them the dominant means they get issues carried out.
I have no idea precisely what it’s. My guess is that they wish to present their AI doing one thing that appears like it will probably prevent time. Extra performative than something.
There’s a structural purpose for that, and it’s not that the fashions are unhealthy. Net UX is constructed for human eyes, not for machine-readability and interactivity. Each one in all these merchandise picks up a browser and drives it, which is why I argued AI browsers have been backward. It’s the hardest out there model of the job: studying an interface designed for an individual, guessing at it, and clicking.
The business’s reply is that the net being constructed for eyes is a short lived downside they will clear up. That’s wishful considering, isn’t it? Let’s see them do it first.
The Form Retains Altering Whereas The Pitch Stays The Identical
Agentic shopping has taken three distinct product shapes in beneath two years.
A browser you put in and change to. OpenAI’s Atlas launched in October 2025, by no means left macOS, and stopped engaged on August 9, 2026. OpenAI didn’t stroll away from the concept; it moved it. The assistance article masking the shutdown is titled “Evolving Atlas into ChatGPT for browser-based agentic work.”
An AI bolted into the browser you already use. Gemini in Chrome, Claude in Chrome.
And now a browser that lives on their machine, which you discuss to. That’s Muse, and I believe it’s the better of the three shapes. You shouldn’t want to look at an AI work in a browser. Sitting there whereas a machine clicks by means of a checkout in your display screen isn’t automation, it’s supervision with further steps. Placing it in a digital machine someplace is the suitable intuition.
However a browser on Meta’s {hardware}, logged into your accounts, raises actual questions on authentication and id.
Meta Revealed 2 Paperwork On The Identical Day
One is the announcement on Meta’s newsroom, written for individuals who may use Muse. The opposite is an engineering publish, How We Constructed Security Into Muse, from Meta Superintelligence Labs. The announcement hyperlinks to it, so none of that is hidden.
They don’t seem to be the identical story. I pulled the textual content of each and counted.
The announcement says Meta “constructed Muse from the bottom as much as be a secure, safe, personal, and extensively out there private AI agent,” with “first-of-its-kind privateness, security, and safety protections engineered into it that no different agent gives.” Nothing reaches the web “except the Sentinel approves it.” Muse “has no visibility into folks’s passwords or fee strategies.” It “checks with the particular person earlier than delicate actions.”
Each a kind of is true, and the engineering publish backs every of them with actual mechanism.
Here’s what the announcement by no means says. Not as soon as, in roughly six thousand characters.
Threat. Assault. Attacker. Mistake. Untrusted. Immediate injection.
The engineering publish makes use of these thirty-nine occasions between them. It opens by saying “any agent like this can nonetheless make errors, and it’ll typically be attacked through the information it reads,” and that Meta “designed the system to imagine the agent could also be beneath assault and restrict the potential injury.” It says plainly: “Muse can and can nonetheless make errors.” It provides as much as $300,000 for safety stories, “together with as much as $130,000 for profitable immediate injection makes an attempt that have an effect on one person.”
That could be a firm being unusually straight with engineers. Assume it’s compromised, comprise the injury, right here is cash for those who can break it.
However the two describe the identical product as two various things. One is a functionality story the place security is a completed property. The opposite is a containment story the place the agent is assumed to be beneath assault. For those who solely learn the one written for you, you wouldn’t know the second exists in that kind.
Solely The Engineering Put up Says Muse Will Seem As Your Exercise
One sentence decides what each web site Muse visits sees, and it’s absent from the announcement.
“When Muse browses the web, it’s going to seem as your exercise, so for those who ask Muse to purchase a shirt from a clothes designer’s web site, that designer may use your go to to point out you an advert on Instagram.”
Meta is describing the design, not conceding a flaw. Muse drives “an actual up-to-date Chromium-based browser.” So the designer sees an individual. Their analytics data a go to. Their retargeting fires. And the advert chases a human who was doing one thing else completely whereas a digital machine did the shopping.
That sentence sits within the publish written for engineers. It’s absent from the one written for the folks it occurs to.
There Are 2 Tiers, And Most Web sites Are In The Second One
Meta’s engineering publish makes use of the phrase connector eleven occasions, and the announcement by no means makes use of it as soon as.
For companies Meta has a relationship with, there isn’t a browser in any respect. “For every connector, we labored intently with the service supplier to combine their API.” A negotiated interface, scoped credentials, an allowlist per employee, and a service that is aware of precisely what it’s speaking to.
For everybody else, Muse opens Chromium and behaves such as you.
So the query a web site proprietor ought to ask isn’t whether or not brokers are coming. It’s which tier they’re in. In case you are large enough for Meta to construct a connector, you get an interface and a dialog. In case you are not, you get a machine sporting your customer’s face.
Your Bot Guidelines, Your Paywall And Your Analytics All Verify The Identical Factor
Bot guidelines identify crawlers. A paywall for machines checks the identify in a single line of the request. Analytics counts a go to as human when a browser runs the JavaScript. All of it keys on a machine figuring out itself, or on a machine failing to appear like a browser.
Muse does neither, and Meta has written that down. Muse is doing one thing you requested for, along with your credentials, beneath an approval you gave, and Meta disclosed the conduct in a doc anybody can learn.
The Different Is Being Constructed By The Identical Trade, In Parallel
There’s a complete set of agentic protocols now the place the machine talks to the web site as a machine. MCP, and its browser-side sibling WebMCP, let a web site hand an agent a set of named instruments as a substitute of creating it guess at buttons. UCP and AP2 do it for commerce, so a checkout is a name with phrases somewhat than a kind crammed in by one thing imitating fingers. A2A does it between brokers. There’s an IETF working group on Net Bot Auth, the piece that might let an agent show which agent it’s. That cut up, between brokers that may show who they’re and brokers that may solely do issues, is the fault line the entire agentic net is forming alongside.
None of these require anybody to fake. Perhaps the higher means to do that is thru these protocols, and never having AI fake it’s human because it browses.
That’s the fork. One path has a machine driving a human interface whereas no one on the receiving finish is instructed. The opposite has machines and web sites speaking to one another on goal. Proper now the cash and the launch occasions are going into the primary, and the second is the place the precise engineering is occurring.
I’m not going to let you know to do something at present, as a result of there may be nothing helpful to do but. However preserve a really shut eye on it, and there are three particular issues to look at.
Whether or not any of those brokers ever carry an id a web site can confirm, which is what the Net Bot Auth work on the IETF would give them. Whether or not the connector checklist grows, as a result of that’s the checklist of internet sites that get an interface as a substitute of a browser. And whether or not the subsequent one in all these launches with one doc or two.
Extra Assets:
This publish was initially printed on No Hacks.
Featured Picture: Viktoriia_M/Shutterstock
