Will it run?
Products

Meta launches Muse with a confidential VM even it can't access

By Marco Vane Clawpit staff
Meta launches Muse with a confidential VM even it can't access

Mark Zuckerberg unveiled the architecture behind Muse yesterday — Meta's new personal-task assistant. Every user gets a confidential virtual machine in the cloud. It holds sensitive personal data: emails, calendars, payment details. The system is designed so Meta itself cannot see inside.

How it works under the hood

The idea, Zuckerberg said, was to spare users the hassle of running their own computer or VM while giving them the same level of secrecy they'd have if the box sat under their desk at home. The VM lives in the cloud, but encryption and attestation block access from the cloud provider — in this case, Meta. Zuckerberg added he doesn't know of another agent product with a comparable setup.

Spark 1.3 and a longer horizon

Muse runs on Muse Spark 1.3, Meta's new agentic model built for longer-horizon work. The assistant can hook into email, calendar, shopping, and payment services, and it keeps running after the app closes. Each user gets a dedicated Muse instance inside their own secure VM.

What's missing from the picture

Meta hasn't published benchmarks for Spark 1.3 against rivals. It hasn't detailed how the VM attestation works or which encryption standard it uses. It's also unclear how the system handles requests that need outside access — placing an order, say — without leaking data to a third party. Zuckerberg claims uniqueness. But without technical details or peer review, that's a vendor claim, not proof.