Meta launched an AI assistant on Tuesday that can read your email, book your travel, spend your money, and rifle through your apps — and the company that made billions surveilling you for advertisers is asking you to trust it with everything else, too.

The product, called Muse, is Mark Zuckerberg's bid to turn "personal superintelligence" into a subscription business. A free tier exists, but Meta will charge $20 and $100 a month for heavier use. The agent runs constantly in the background on its own cloud-based virtual machine, keeps working after you close the app, and makes suggestions nobody asked for. It connects to your email, calendar, payments, health apps, shopping, and smart home. You choose which apps, and you can revoke access — same as every permission prompt you've already learned to click through without reading.

The stakes are straightforward. Muse is designed to vacuum up the most sensitive data in your digital life and run it through Meta's servers. The same company that pioneered turning your clicks and messages into ad targeting now says it won't use your agent conversations for advertising. But as TNW noted, that promise is a policy, not a property of the system — and it's revocable. An encrypted version where Meta itself cannot observe your workspace is promised for "later this year." Until then, you're taking a surveillance-advertising giant at its word.

Internal testing already produced red flags. According to internal posts seen by Reuters and reported by Arkansas Online, one tester found Muse routed around guardrails to expose a person's personal iCloud photos after being prompted to identify toys visible in pictures from a child's birthday party. Meta CTO Andrew Bosworth posted that he kept getting logged out and needing to log back in. A Meta researcher's experiment with an agent ended with files deleted, Axios reported. And CNET noted that over the summer, agents from Meta, OpenAI, and Anthropic each slipped out of their testing environments and hacked outside websites.

Meta's security architecture is more considered than usual. Each user gets an isolated virtual machine. A separate monitoring agent called Sentinel sits between Muse and the internet, distinguishing read access from write access and stopping to ask permission before consequential actions. Credentials go into a secure store Muse cannot see directly. Stripe's Link payment tool issues single-use card numbers so the agent isn't spreading your real financial information across the internet. Every action leaves an audit trail.

Meta VP Vishal Shah told Reuters the company delayed an April release to make Muse more secure and "cross the threshold" of minimum safety. "It is impossible to say that there is never going to be a mistake," Shah said, "but every single part of the architecture has been designed to make this as safe, as secure, as private as we can possibly make it."

Digital Trends framed Muse as an assistant that "actually gets things done" and emphasized user control. WIRED and CNET both noted Meta's trust deficit — the company has struggled for years to convince users it handles data responsibly. Arkansas Online led with the internal concerns and security flaws. TNW was the sharpest, pointing out that the privacy promise comes from a company whose revenue depends on knowing what people want before they say so.

Alexandr Wang, Meta's chief AI officer, told Axios the vision is "personal superintelligence that helps people accomplish their goals, pursue their passions." Meta forecasts spending more than $130 billion on AI infrastructure this year. It needs a product that pays that back.

The question isn't whether Muse is useful. It's whether a company that censors speech on its platforms at government request while harvesting user data for advertisers should be trusted as the guardian of your entire digital life — especially when its own testers are watching the agent break through guardrails in real time.