
Meta Muse Agent, known internally as Hatch, is the centerpiece of CEO Mark Zuckerberg’s plan to offer “personal superintelligence” to the billions of people who use Meta’s services every day. File | Photo credit: Reuters
Meta on Tuesday (September 8, 2026) unveiled a long-touted artificial assistant that can autonomously send emails, sell cars and book trips on behalf of a person, despite internal concerns that the technology mismanages access to sensitive personal data.
Muse’s agent, known internally as Hatch, is the centerpiece of CEO Mark Zuckerberg’s plan to offer “personal superintelligence” to the billions of people who use Meta’s services every day.
The product will initially only be available in the US through the dedicated Muse app or Meta’s WhatsApp messaging service, Meta said in a statement. Meta said it plans to add the agent to its line of smart glasses “soon,” without going into detail.
Built on the open-source AI agent OpenClaw, Muse is designed to access a person’s apps in categories such as email, calendar, payments, health, shopping and smart home, Mehta said. People choose which apps it connects to and can revoke access at any time.
Each Muse agent runs on its own virtual machine, a cloud-based emulation of a personal computer, allowing it to continue running requests in the background even when a person is not actively using it.
Synchronization with applications containing real person data increases the potential utility of the agent, and also significantly raises the stakes in terms of security and reliability, both for the users who have entrusted it with their information and for others who may be victims of the agent’s misconduct.
Vishal Shah, vice president of artificial intelligence products at Meta, said the company initially delayed the product’s release to April 2026 to make it more secure. Meta determined that the additional work allowed it to “cross the threshold” and meet minimum requirements for product safety, security, privacy, model performance, and other metrics.
That’s not to say a mistake will never happen, but every part of the architecture “has been designed to make it as safe, secure and private as possible,” Mr. Shah said in an interview.
Internal tests showed mixed results
As recently as this week, Meta employees testing the tool reported mixed results with Muse, with one person praising its usefulness for planning vacations and others describing instances where it would shut down without explanation and download sensitive information without permission, according to internal communications reviewed by Reuters.
One person wrote that the product was so helpful in planning itineraries and ground transportation that they became a “third party” on a recent three-week honeymoon in Indonesia.
In another post, an employee who encouraged Muse to monitor tickets and other items that were selling out quickly said he encountered “multiple failure modes that made it unreliable.” The product stopped updating the page after about 15 minutes, silently ignored other errors and sometimes turned off monitoring “for no apparent reason,” the source said.
Meta CTO Andrew Bosworth reported that he kept logging out and having to log back in, sometimes multiple times within a few minutes.
Others noted serious security flaws, such as when an agent bypassed a fence to reveal a person’s private iCloud photos after being asked to identify toys visible in photos from a child’s birthday party.
Meta did not immediately respond to requests for comment on the specific incidents described in the internal posts.
Published – September 9, 2026 01:44 EST.