• Latest
  • Trending
  • All
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
Answer card stating that OpenAI published its research acceleration measurements on 6 September 2026, that as of mid August 2026 its research organisation logged 3.1 agent workdays of coding agent runtime for every workday of human labour normalised to a standard eight hour day, and that OpenAI states this should not be read as a 3.1 times productivity gain because it measures runtime rather than delivered output.

OpenAI’s 3.1 agent-workdays per human day is not a 3.1x gain

7 September 2026
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Official Google diagram of a client connection in three numbered steps: a DNS lookup with a query and an address, a TLS ClientHello and ServerHello, then a content exchange with a website. A callout on the DNS step reads 25% of global web traffic is now protected by encrypted DNS, and a callout beside an Android phone on the ClientHello step reads Android 17 supports ECH GREASE by default.

Android 17 hides the SNI, not your DNS or destination

3 September 2026
Still frame from the Claude Fable 5.1 launch video showing model-designed protein binders in orange docked against twelve grey target proteins, rendered as ESMFold2 structure predictions.

Claude Fable 5.1 breaks forced tool use, cuts cache 75%

1 September 2026
Answer card stating that on 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first conversational AI service classified that way, because it answers user prompts and queries including by searching the web, with OpenAI having declared roughly 159.1 million average monthly users in the European Union for ChatGPT search.

The EU now calls ChatGPT a very large search engine

3 September 2026
Answer card stating that on 31 August 2026 the Department of War added OpenAI ChatGPT Mil and Starshield AI Grok for Government to the GenAI.mil portal alongside Google Gemini, all three accredited at Impact Level 5 for Controlled Unclassified Information, with 1.7 million unique users onboarded out of roughly 3 million eligible personnel, and ChatGPT Mil currently serving GPT-5.4 Terra with GPT-5.6 Terra said to be rolling out.

ChatGPT Mil and Grok reached IL5 on GenAI.mil

3 September 2026
Answer card stating that Anthropic opened a research preview of the Model Hardware Standard on 27 August 2026, standardising the driver layer between an operating system and a laboratory instrument with read and write primitives plus discovery and safety limits, reachable through MCP as well as a command line and code files, with no public specification published.

Anthropic’s Model Hardware Standard is gated, and sits under MCP

3 September 2026
Official Cohere key art for the Parse 5 launch: the Cohere mark and the wordmark Parse with a superscript 5 in white, centred on a soft out of focus gradient of deep blue, violet and amber curves.

Cohere Parse 5 is $1.50 per 1,000 pages, on three of five dimensions

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Friday, September 11, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Sysadmin

Does Meta Muse do enough to earn your inbox and a card on file?

by stephane
9 September 2026
in Sysadmin
0
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Meta shipped an agent on Tuesday that reads your mail and puts charges on your card, and the first thing it asked one reviewer for was an Amazon login. Muse went live on 8 September 2026, in the United States, for adults only. It's free up to 100 million tokens a week, then $20 a month for the Power tier and $100 for Maximum. The price isn't the interesting part. Meta built a per user virtual machine and a separate permission daemon to hold this thing, published the design in real detail, and then wrote in the same document that prompt injection remains an open problem. Both of those are true at once.

The short answer

Muse is a personal agent that connects to your mail, your calendar, a payment rail and a pile of consumer services, then acts on your behalf. It runs on Meta's Muse Spark model inside a dedicated virtual machine, with a component called Sentinel approving every connector action and every packet that leaves the box. Real credentials never reach the agent itself, and purchases always come back to you for approval. What Meta hasn't solved is prompt injection, and the version that would stop Meta itself reading your VM is dated later in 2026. Early hands on testing says the setup cost swamps the task for anything small.

8 Sep 2026launch day, United States only, 18 and over
100Mfree tokens a week, then $20 or $100 a month
0 of 3ordinary purchases completed in one launch day test
Answer card stating that Meta launched its Muse personal AI agent on 8 September 2026 in the United States only and for adults only, that it is free up to 100 million tokens a week with a Power tier at $20 a month and a Maximum tier at $100 a month, and that it runs inside a dedicated per user virtual machine while asking for access to your mail and a payment card on file.
A lot of free agent, on the condition that you wire it into the accounts that matter.

What Meta actually shipped

Muse is a separate product from the assistant already living inside Meta's apps. You get it as an iOS app, an Android app, at muse.ai in a browser, or through WhatsApp, with the AI glasses promised later. US only at launch, gated to 18 and over. Alexandr Wang, Meta's chief AI officer, runs the effort, and the model underneath is Muse Spark, the same family we wrote about when the coding tier landed at $1.25 per million tokens.

The job it advertises is errands. Read the inbox, book the trip, argue a bill down, turn a recipe into a shopping list, buy the thing. Connectors cover mail and calendars, payments, health and fitness, smart home, dining, shopping, music and events. Where a service publishes an API, Muse uses it. Where it doesn't, Muse drives a browser with credentials you hand over. Checkout runs through Stripe's Link, and you need a card on file before you can start at all.

The pricing is generous and vague at the same time. 100 million tokens a week for free is a great deal of agent, and Meta says it expects most people to stay there. Power is $20 a month, Maximum is $100, and nothing published so far tells you what a booked flight costs in tokens. No advertising inside the product, conversations kept out of the ad systems, opt out of model training on request. I'd want that in a contract before connecting a work account, but it's at least the stated policy.

The permission layer is the part to read

Here's where it gets interesting for anyone who has tried to sandbox an agent themselves. Each user gets a virtual machine, the Muse Secure VM, holding the agent and the copy of your data it works on. Inside it, code runs in a systemd-nspawn cell with its own root filesystem, its own virtual network interface, filtered system calls and trimmed kernel capabilities. Root in the cell maps to an unprivileged user on the host, so getting out of the agent isn't getting out of the machine.

Beside it, kept apart at the system level, sits Sentinel. It's the sole permission authority for two things: calls to third party connectors, and every byte of network egress. It doesn't just check a hostname. It reads the resolved and final destination address, the port, the protocol, the HTTP method, the path and the decoded request, then answers allow, deny, or ask the user. Anything carrying your data outward needs approval. Purchases always come back to you with the exact details attached.

The credential handling is the part I'd steal outright. The agent never holds a real token. It gets a surrogate minted by a separate daemon, and Sentinel substitutes the genuine secret at the network boundary once the request has already been authorised. Per connector you can grant read without write, and Meta says it narrows OAuth scopes further than the providers themselves offer. There's an audit trail, and you can revoke any of it.

Checklist separating what the Muse security design covers, namely an isolated runtime cell per user, a Sentinel component approving every connector call and every network egress at layer 4 and layer 7, surrogate tokens instead of real credentials in the agent, and mandatory user approval on purchases, from what it does not cover, namely prompt injection which Meta calls an open industry problem, and Meta's own ability to read a user virtual machine until the Confidential VM ships later in 2026.
The outer wall is solid. What Meta says out loud is that the occupant can still be talked into pressing buttons.

Two admissions sit in that same document. Muse will sometimes make mistakes. And prompt injection remains an open problem in the industry, which is Meta telling you the wall holds while the thing inside stays suggestible. Meta can also read your VM today. The Confidential VM meant to stop that is dated later in 2026, a promise rather than a property.

Thirty seconds, by hand

Architecture is one thing. PYMNTS put Muse through three ordinary errands on launch day and it finished none of them. Reordering toilet paper on Amazon failed. A Domino's order failed. A Resy reservation failed. Getting that far meant handing Amazon credentials over through a secure link, then running separate authorisation flows for Gmail and Calendar. The payment routed through Stripe Link, which didn't go through either. That same Amazon reorder, done by hand, took under 30 seconds.

One test on day one isn't a verdict, and I'd expect broken connectors to get patched fast. The shape of the problem won't patch, though. Every capability Muse has is a credential you granted and a scope you approved, followed by a queue of confirmations you'll be tapping through. That's the honest cost of the security model: the design that makes an agent safe to run is the same one that makes it slow to use. Meta chose correctly, and it still leaves a product that needs tasks big enough to earn the ceremony.

So it isn't for the 30 second errand. It's for something long and dull with a lot of steps, where you'd have burned 20 minutes anyway. If that's your week, the free tier costs you nothing except the connectors. And if your interest here is professional rather than personal, watch what happens the first time somebody points this at a work Google Workspace account, because nothing in the product stops them and the OAuth consent screen is the only place it shows up. Different problem entirely from running a 30B Muse model on your own GPU, where the data never leaves the building.

Sources

Meta AI Research, How we built safety into Muse (the Secure VM, the systemd-nspawn cell, Sentinel at layer 4 and layer 7, credential surrogation, per connector scopes, the purchase rule, the Confidential VM timing, and both stated limitations). TechCrunch, Meta debuts its Muse AI agent, 8 September 2026 (channels, connector categories, Stripe Link and the card requirement, the advertising and training positions). The Next Web, Meta launches Muse, 9 September 2026 (tier names and prices, Muse Spark underneath). PYMNTS, Meta's Muse can't order a pizza without help (the three failed transactions and the 30 second comparison).

Frequently asked questions

Can I use Muse outside the United States?

Not at launch. Meta gated it to the US and to users aged 18 and over on 8 September 2026, and hasn't published a date for anywhere else. A VPN isn't the answer either, because the connectors and the payment rail both key off a real account and a real card. If you're outside the US and curious, read Meta's security write up instead. It's public and it doesn't require the product.

Does Muse ever see my passwords or card numbers?

Meta says no, and the mechanism it describes backs that up. The agent works with surrogate tokens minted elsewhere, and Sentinel swaps in the real credential at the network boundary after the specific request has been authorised. Card details go through Stripe's Link rather than sitting in the agent's context. Genuinely good design. It isn't an audit, though, and nobody outside Meta has verified the implementation, so treat it as a credible claim rather than a proven one.

What does 100 million tokens a week actually buy?

Nobody has published a conversion, which is my main complaint about the pricing page. Tokens here cover the agent's own reasoning as well as every page it reads, so one multi step booking can cost what a month of chat never would. Meta's line is that most people won't leave the free tier. Until somebody measures a real errand end to end, that's an assertion rather than a number you can plan against.

Should I connect a work account to it?

I wouldn't, and if you administer a Google Workspace or Microsoft 365 tenant you'll want to decide that before your users do. Muse asks for OAuth scopes against whatever mailbox you point it at, and it's a consumer product with a consumer agreement behind it. The controls are per connector and revocable, which helps. But a copy of your mail lands in a VM that Meta can still read until the Confidential VM ships, and that alone rules it out for anything under a data processing agreement.

Tags: AI agentsmetamusenewsoauthprivacy
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
Answer card: Apple released iOS 26.6 and iPadOS 26.6 on 27 July 2026 with a release note covering bug fixes, security updates and an optimized Spotlight index to prepare for iOS 27, the index the rebuilt Siri reads for personal context.

iOS 26.6 is out: the Spotlight index it quietly builds

27 July 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
Answer card stating that OpenAI published its research acceleration measurements on 6 September 2026, that as of mid August 2026 its research organisation logged 3.1 agent workdays of coding agent runtime for every workday of human labour normalised to a standard eight hour day, and that OpenAI states this should not be read as a 3.1 times productivity gain because it measures runtime rather than delivered output.

OpenAI’s 3.1 agent-workdays per human day is not a 3.1x gain

7 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.