Meta launches AI agent that can access other apps to send emails, make payments
NEW YORK, Sept 8 (Reuters) - On Tuesday, Meta launched its much-anticipated AI assistant, which can independently send emails, sell a car, and book travel on a user's behalf, even as internal unease persists that the system mishandles its access to sensitive personal data.
The agent, called Muse and known internally as Hatch, serves as the centerpiece of CEO Mark Zuckerberg's ambition to deliver 'personal superintelligence' to the billions who rely on Meta's services each day.
Meta said in its announcement that the product is initially confined to the United States, offered either through a dedicated Muse app or the WhatsApp messaging service. It added that the agent would be incorporated into its smart glasses lineup 'soon,' without offering further detail.
Muse, which is modeled on the open-source AI agent OpenClaw, is designed to reach into a user's applications across email, calendars, payments, health, shopping, and smart-home systems, Meta explained. Consumers select which apps Muse can connect to and may revoke access at any time.
Each Muse instance operates in its own virtual machine—essentially a cloud-based emulation of a personal computer—enabling it to keep fulfilling requests in the background even when a person is not actively using it.
By syncing with apps that contain authentic personal data, the agent becomes more useful, but it also amplifies the risks around safety and dependability—for the people who trust it with their information and for others who might be affected when the agent misbehaves.
Vishal Shah, Meta's vice president of AI products, said the company initially delayed the product's release in April to make it more secure. Meta determined that work allowed it to 'cross the threshold' and meet its minimum requirements for product safety, security, privacy, model performance, and other metrics.
"It is impossible to say that there is never going to be a mistake, but every single part of the architecture has been designed to make this as safe, as secure, as private as we can possibly make it," Shah said.
Internal tests reveal mixed results
Internal posts reviewed by Reuters show that, as recently as this week, Meta employees testing the tool reported cases in which Muse successfully arranged vacation logistics, disconnected without explanation, and uploaded sensitive information without permission.
One person wrote that the product proved so useful at arranging itineraries and ground transportation that they described it as 'the third participant' on their recent three-week honeymoon in Indonesia.
In another post, an employee who had prompted Muse to monitor for tickets and other items that sell out quickly reported encountering 'many failure modes that made it unreliable.' The product stopped refreshing the page after about 15 minutes, silently ignored other errors, and at times disabled monitoring 'for no apparent reason,' the person said.
Andrew Bosworth, Meta's chief technology officer, posted that he kept getting logged out and needing to log back in, sometimes several times within the span of a few minutes.
Others flagged serious security flaws, including an agent that routed around guardrails to expose a person's personal iCloud photos after being prompted to identify toys visible in pictures from a child's birthday party.
Meta did not immediately respond to a request for comment on the specific incidents.