Skip to content
The TAI Labs community is now on Skool
TAI Labs
All articles

29 September 2026 · 6 min read

Muse doesn't trust its own model, and that's the whole design

Meta's new personal agent can browse the web, spend your money and read your email. The interesting part isn't the model. It's that the model is never allowed to see the keys.

By Dr. Aki Wijesundara, TAI Labs

Most people building an agent that can act on a person's behalf reach for the same fix when something could go wrong: write a better system prompt. Tell the model not to leak the API key, not to buy the wrong thing, not to fall for a prompt injection hidden in a web page. Meta's new personal agent, Muse, launched September 8, 2026, is built on the opposite assumption. Its own safety engineer, Tarek Sheasha, writes that the team designed the system to assume the agent may be under attack and limit the damage when it is. The model never gets the chance to leak a secret it never held.

The agent runs in a cell that can't see the keys

Keep reading

Drop your email and the rest of this article opens right here. No account, and you won't be asked again on the next one.