Skip to main content

Morning Overview

Meta’s new Muse AI uses your chats for training by default unless you switch it off

Meta’s Muse personal AI agent trains on user interactions unless the user opts out. Meta’s own launch post says people can “opt out” of having their interactions train the company’s models, which makes training the default, and the setting matters more than usual because Muse is built to connect to email, payments and health services.

The agent debuted on September 8 and has drawn a steady run of privacy scrutiny since, most recently in a September 25 Axios report on the company’s promised protections and a September 28 follow-up quoting Mark Zuckerberg on them.

What Muse can touch, and what Meta says it protects

Muse is a task-doing agent rather than a chatbot. TechCrunch’s launch coverage describes it sending emails, booking travel, cutting bills and making purchases, with connections to a user’s email, calendar, payment systems and health services. It runs on what Meta calls a Muse Secure VM, a dedicated cloud computer with its own browser, and Meta says the agent has no visibility into passwords or payment methods and that conversations are not shared with its advertising systems.

Meta’s launch post adds that a “Sentinel agent” approves internet-bound actions, that users get an audit trail and can ask Muse to forget specific information, and that people choose which apps connect and how much access each gets. Muse launched in the United States for adults on iOS, Android, web and WhatsApp, in three tiers: free, $20 a month and $100 a month, according to Axios’ launch report. Alexandr Wang, Meta’s chief AI officer, told the outlet that “for the vast majority of users, they should be able to do what they need to within the free tier.”

Trust is the obstacle Meta has to clear. TechCrunch’s Sarah Perez notes that the company carries a history that includes a 2011 FTC settlement over privacy deception and a $5 billion penalty in 2019, and ABC News reports that cybersecurity consultant Tate Jarrow said he would not trust Meta with that level of access to a person’s personal information, while researcher Patrick Wardle warned that the access Muse needs to function “can let local malware/attackers invisibly hijack” a user’s digital life. ABC also reports that Amazon blocked Muse as “unauthorized AI” under its terms. Meta has answered with the secure credential store, the Sentinel approvals and the audit trail, none of which changes what happens to chat data under the training default.

The training default

The privacy trade-off sits in a single setting. Axios reported in its September 25 analysis that the default allows Muse data to be used for training and that users can disable it. Meta’s newsroom describes the same arrangement from the other side: users “can explicitly opt out of their interactions being used to train Meta’s AI models.” The September 28 Axios piece repeats the phrasing that users can opt out of having interactions train the models.

The sources read do not spell out where the switch lives, so the practical step for a user is to check Muse’s privacy settings before connecting an inbox or a bank account. One independent review, Superpower Daily, quotes Meta’s terms as saying that “sanitized inference records may be used for training unless users opt out,” which suggests the data goes through a scrubbing step before it reaches training. What sanitizing removes has not been detailed in the sources reviewed.

Private modes that are not here yet

The strongest protection Meta describes has not shipped for everyone. Muse Confidential VM, which encrypts the whole virtual machine with keys held by the user so that Meta cannot see the workspace, is “being used by a small group of trusted testers, with a broader release planned later in 2026,” per the Superpower Daily review, and Axios reports that a related private cloud processing option for Meta’s AI glasses is planned by year-end without a committed date. The same review calls Private Processing “a planned design, not a confirmed safeguard for shipped Muse-on-glasses features,” and notes that the current Secure VM does not stop Meta staff from reaching the environment for service operations.

Zuckerberg, quoted by ABC News, has promised optional enhanced security where “even Meta can’t access the information.” Critics say the safeguard would not change the larger picture. Alan Butler of the Electronic Privacy Information Center told Axios that “confidential processing doesn’t solve the problem of pushing embedded surveillance systems out into the world,” a reference to camera- and microphone-equipped devices.

The gap between what is available now and what is promised is the story to watch. Until the confidential option ships broadly and is audited, the default remains the one Axios and Meta both describe: training use on, unless the user turns it off.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview