Perspective
Meta Muse: When AI Stops Answering and Starts Acting
Meta launched Muse on 8 September 2026 as a personal AI agent designed not only to answer questions, but to act: browsing the web, filling in forms, sending emails, handling longer-running tasks and returning to the user when approval is required.

A2Z COMMUNICATIONS | INSIGHTS & MEDIA | TECH PERSPECTIVE
Meta Muse: When AI Stops Answering and Starts Acting
What Meta's new personal AI agent tells South African businesses about Agentic AI, POPIA, Shadow Agentic AI and the coming shift from AI assistants to AI operators.
By Loyiso Skweyiya
9 September 2026 • A2Z Communications
Meta launched Muse on 8 September 2026 as a personal AI agent designed not only to answer questions, but to act: browsing the web, filling in forms, sending emails, handling longer-running tasks and returning to the user when approval is required. Muse is currently rolling out only in the United States. For South African businesses, however, its significance is immediate: it offers an early view of what changes when AI moves from a conversational assistant to an authorised digital operator.
South Africa availability: Muse is not yet available in South Africa. Meta says the initial rollout is in the United States on iOS, Android and muse.ai, with WhatsApp as a way to interact with Muse and AI-glasses support coming later. |
We are leaving the chatbot era
In my recent perspective on Astra, I focused heavily on computer use because I believe this is where the AI story becomes significantly more consequential for business. There is a fundamental difference between an AI that tells me what to do and an AI that can actually do it.
Meta's newly launched Muse reinforces that view. Meta describes Muse as a personal AI agent. The practical distinction is important: instead of simply producing an answer, Muse can take a goal, develop a plan and begin executing the work. Meta says it can open a browser, fill in forms, send emails, make purchases and negotiate on a user's behalf. For longer tasks, it can keep working after the user closes the application and return when something changes or when approval is required.
For the past several years, the public conversation around AI has concentrated on model intelligence: which model writes better, reasons better, codes better or performs best on a benchmark. Those questions still matter. But I increasingly think a more consequential question is emerging: what can the AI actually do once it has finished thinking?
That is the transition from Generative AI into Operational AI and Agentic AI. Instead of asking an AI to draft an email and then copying it into an email client ourselves, the agent can potentially understand the situation, prepare the response and send it - subject to the permissions we have given it. Instead of explaining how to book a trip, it can research options, navigate websites, fill in forms and bring the transaction back for approval. Instead of producing a to-do list, it can work through parts of the to-do list.
Meta has effectively given the AI its own computer
The part of Muse that interests me most is the architecture. Muse runs inside what Meta calls a Muse Secure VM: a dedicated virtual computer in the cloud where the agent operates, stores its working data and uses a browser to complete tasks.
Meta's technical description goes much further than the marketing headline. The Muse environment is an isolated Linux virtual machine with enough compute and storage for the agent to do real work, including writing code, using tools, managing sub-agents and executing longer-running tasks. A browser-specific sub-agent navigates websites and completes forms, while credentials are kept outside the agent's direct view.
This matters because much of modern business still happens through software interfaces built for people rather than clean APIs built for automation. An agent that can safely use those interfaces could automate thousands of workflows that organisations have never formally integrated.
But the same capability creates the central risk: if an AI can use a browser, access email, work with documents, communicate externally and potentially spend money, what prevents it from doing the wrong thing?
The most interesting Muse technology may be the security boundary around it
Meta's answer includes a separate system-level agent called Sentinel. Sentinel is kept apart from Muse and acts as the permission authority for actions that leave the secure environment. Muse can propose an action, but Sentinel determines whether it is allowed, denied or should be presented to the user for approval.
This is a design principle businesses should pay attention to. Agentic AI risk should not be solved merely by instructing the model to 'be careful'. The model itself should not be the final security boundary.
Meta's launch architecture combines model-level safeguards with isolation, credential separation, network controls, user permissions, audit history and human approval for sensitive actions. Meta also says Muse checks with the user before actions such as sending an email or making a purchase, and that users can decide what access each connected service receives.
Even the payment flow is designed around that principle. Meta says Muse can use Stripe Link to generate a one-time card number so the user's actual card details are not exposed to the agent or merchant in the same way. This is useful engineering, but more importantly it shows what responsible agent design increasingly looks like: intelligence separated from authority.
The risk has not disappeared
Meta is explicit that Muse is not immune to attack and will sometimes make mistakes. Prompt injection - malicious or misleading instructions hidden inside the information an agent reads - remains an open problem across the industry.
Muse's defence is therefore layered. Meta says external content is treated as untrusted, the model is trained to resist prompt injection, multiple classifiers inspect incoming information, the runtime environment restricts what the agent can access, and Sentinel evaluates external actions and network traffic. Meta has also opened Muse to a public bug bounty programme, including rewards for successful prompt-injection attacks with demonstrated impact.
This distinction is important for business. Better Agentic AI should not automatically mean fully autonomous AI. The objective should be appropriate autonomy.
An AI reading a public product catalogue is not the same risk as an AI approving a large supplier payment. An AI suggesting meeting times is not the same risk as an AI making an employment decision. An AI preparing a procurement recommendation is not necessarily the same thing as allowing the AI to approve the purchase. Agentic AI therefore needs an authorisation model, not merely an intelligence model.
The Meta privacy question cannot be ignored
A genuinely useful personal agent needs context. It becomes more useful if it knows a user's calendar, email, preferences, relationships, purchases and goals. The more useful it becomes, however, the more sensitive the information around it becomes.
Meta says Muse conversations and data in the Muse VM are not shared directly with Meta's advertising systems. It also gives users an option to opt out of having their Muse interactions used to train Meta's AI models. Meta explains that training trajectories are sanitised to remove key personally identifiable information before use when a user has not opted out.
There is an important qualification. Meta says the Secure VM available at launch restricts access through technical and operational controls, but does not cryptographically prevent Meta from accessing the environment when necessary to support, secure or operate the service. A stronger Muse Confidential VM is planned for later in 2026, designed so that the user's encryption key prevents even Meta from accessing the content of that environment.
That distinction matters. Privacy marketing and privacy architecture are not always the same thing. Businesses evaluating agentic platforms will need to look beyond slogans and understand where data is stored, how credentials are handled, what the provider can technically access, what gets used for model improvement, and which controls are enforceable rather than merely promised.
What Muse means for South Africa
South Africans cannot yet simply download Muse and start using it. The initial rollout is restricted to the United States, and Meta has not announced a South African launch date.
I do not think South African businesses should wait for availability before thinking about what Muse represents. One reason is Meta's decision to make WhatsApp part of the interaction model. If personal agents eventually become accessible through an interface millions of South Africans already understand, Agentic AI stops looking like specialist technology for developers and early adopters. It starts becoming ordinary behaviour.
That is potentially the inflection point. The arrival of consumer-grade agents would mean organisations need to plan not only for employees using AI, but for employees authorising AI to access business systems and perform actions. A person could eventually ask an agent to read an inbox, compare supplier quotations, update a diary, negotiate a booking and prepare a purchase - all within one delegated task.
The AI would no longer be simply processing information. It would be reading, deciding, communicating and transacting.
POPIA meets the autonomous agent
South African organisations therefore need to think beyond traditional AI privacy policies. POPIA already establishes conditions for lawful processing of personal information, security safeguards and accountability. Section 72 governs transfers of personal information outside South Africa, while section 71 places limits and safeguards around certain decisions based solely on automated processing where those decisions have legal consequences or affect a data subject to a substantial degree.
An agent makes these questions operational. Consider an AI agent with access to corporate email, customer documents, CRM records and calendars. The organisation now has to consider far more than whether the model 'trains on our data'. Who is the responsible party? Which provider is processing the data? Where is that processing taking place? What information is being transferred? What is retained? What can the agent do without approval? Which decisions should never be delegated entirely to a machine? What audit evidence exists to show who authorised an action?
These are board, risk, legal, HR, procurement and cybersecurity questions - not merely IT questions.
South Africa's wider AI-policy process also illustrates how unsettled the governance environment remains. Cabinet approved a draft national AI policy for public comment earlier in 2026, but the draft was formally withdrawn in June so that it could be reworked. Government said the rework should establish credible national standards for the ethical use of AI. That means businesses should not wait for a final national AI policy before building responsible internal controls. POPIA, contractual obligations, cybersecurity duties and good governance already apply today.
The next problem may be Shadow Agentic AI
Businesses have spent years dealing with Shadow IT. More recently, they have started confronting Shadow AI: employees using unapproved AI services with company information.
Muse points toward another category altogether: Shadow Agentic AI.
An employee pasting text into an unapproved chatbot is one level of risk. An employee giving an autonomous agent access to corporate email, calendars, browsers, cloud applications and business information - and allowing it to act independently - is fundamentally different.
The question 'Which AI tools are our people using?' will not be enough. Organisations will increasingly need to know which agents have access to which systems; what information they can read; what they can change; what they can communicate externally; what they can spend; which actions require human approval; and where the audit trail lives.
This is why I believe AI governance cannot remain a policy document sitting somewhere in SharePoint. It has to become part of the technology architecture itself.
Muse also changes the customer
There is another side to Muse that businesses should not miss. Today, organisations optimise websites, ecommerce experiences and digital processes primarily for human visitors. Tomorrow, some of those visitors may be AI agents acting for humans.
If agents can research products, compare offers, negotiate, fill in forms and complete purchases, businesses will increasingly interact with agentic customers. That has implications for ecommerce, banking, insurance, travel, telecommunications, professional services and almost every digital industry.
Websites will need accurate structured information. Pricing and availability need to be machine-understandable. Terms need to be clear. Identity, authentication and payment flows will need to accommodate authorised agents without weakening fraud controls. Customer-service systems may increasingly find themselves interacting agent-to-agent.
I believe this could eventually become as significant as the move from desktop websites to mobile. The companies that prepare early will not simply have an AI chatbot on their website; they will have systems that are safe for humans and agents to transact with.
What businesses should learn from Muse now
My takeaway is not that every company needs Muse. It is that every company should begin becoming agent-ready.
At A2Z Communications, this is increasingly how I think about the future of digital transformation. Generative AI helps people create. Operational AI connects intelligence to the processes of the business. Agentic AI gives that intelligence the ability to pursue objectives and take controlled actions.
But the architecture around the agent - identity, permissions, data boundaries, integrations, audit trails, human approval and governance - will determine whether these technologies create sustainable business value or simply introduce a new category of operational risk.
Muse is interesting because Meta appears to recognise that the future of AI requires much more than a powerful model. It requires an operating environment for delegation.
My perspective
I do not think the winner of the next stage of AI will necessarily be the company with the chatbot that produces the cleverest answer.
The bigger competition is becoming: which AI can I trust with responsibility? Which one can work while I am away? Which one understands what it is permitted to do? Which one knows when it must come back to me? Which one can interact with the messy digital systems businesses already use? Which one leaves enough evidence for me to understand what happened afterwards?
Muse is Meta's answer to those questions. Whether Meta can overcome the trust challenge that comes with asking users to hand over this much personal context remains to be seen. Independent coverage of the launch has rightly focused on that tension as much as on the technology itself.
But the direction of travel is becoming difficult to ignore. The transition from AI that communicates to AI that operates is underway.
For South African businesses, the opportunity is not to wait until these agents arrive and then write a policy. It is to start designing organisations, systems and governance that are ready for them.
That, to me, is the real significance of Meta Muse.
Research sources
Primary sources and independent reporting used to verify the launch, technical architecture and South African governance context as at 9 September 2026.
2. Meta AI Research - “How We Built Safety Into Muse” (8 September 2026)
3. Meta AI Research - “Introducing Muse Spark 1.3” (2 September 2026)
5. WIRED - “Muse, Meta’s New Personal AI Agent, Needs You to Trust It” (8 September 2026)
© 2026 A2Z Communications. Written by Loyiso Skweyiya for A2Z Communications Insights & Media.