
What happened
Meta launched Muse, an AI agent controlled through WhatsApp that books travel, shops, sends emails, and negotiates prices. It runs on its own virtual machine and is the first AI agent covered by Stripe's Link purchase protection.
Why it matters
OpenAI stopped its direct payment feature in ChatGPT and handed checkout back to merchants, but Meta built the payment feature OpenAI walked away from. Link creates a one-time card per transaction, hiding real card details.
What to watch
Muse's claim of negotiating lower bills or higher car sale prices is unverified, and security researchers have shown agentic systems can be hijacked through manipulated content. Meta hasn't shared robustness numbers.
WHO IT HITSConsumers using WhatsApp for shopping and travel bookings gain an AI assistant that can transact on their behalf, while merchants and payment processors face a new checkout channel. Security teams evaluating agentic AI deployments will scrutinize Meta's isolation architecture.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
Meta's Muse arrives as the company pushes what it calls "personal superintelligence," a theme Zuckerberg made central to a recent essay. The agent's model, Muse Spark, has improved sharply: released in April at 31 points on Artificial Analysis Intelligence Index v4.3, version 1.3 now reaches 44 points on the xhigh tier and 48 on the max tier.
Muse is likely based on Hatch, an agent Meta was reportedly training in May on simulations of real sites like DoorDash, Etsy, and Reddit. The launch puts Meta ahead of OpenAI on payments; OpenAI stopped its direct checkout feature in ChatGPT after users researched products but didn't buy there.
Success hinges on two things: whether Muse's isolation architecture — a Secure VM and a separate Sentinel agent that clears every internet action — holds up against hijacking, and whether users trust an agent that can negotiate and transact on their behalf. Meta plans Muse Confidential VM later this year, which would encrypt the entire VM with a user-held key.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Michael Burry, famous for The Big Short, is short Nvidia, Palantir and Tesla, and in his Substack newsletter s…

Investors have three creative routes to Anthropic exposure before its expected IPO: buying Alphabet, Amazon, o…

DeepSeek launched V4.1-Flash, a 763B-parameter open-weight model with a causal encoder-decoder architecture

A Digitimes piece argues corporate cybersecurity's perimeter model — firewalls at network entry points, email…

Much of the attention on AI infrastructure buildouts is now tied to sheer compute power, with dominance define…

Barron's reported September 10 that Kepler Computing emerged from stealth with a memory architecture using fer…
