233: Muse Is Why Meta Has No Business Building The Agentic Web

Slobodan "Sani" Manic
Website Optimisation Consultant, No Hacks Founder & Keynote Speaker
CXL-certified conversion specialist and WordPress Core Contributor helping companies optimise websites for both humans and AI agents.
Mark Zuckerberg says Meta's AI agent, Muse, needs to be discreet. The same month, some of the calls Muse made to businesses were placed by people in a call center. I went through what he told Joanna Stern and Alex Heath about Muse's privacy and security, and what Meta's launch documents say, and sorted every claim by tense. The virtual machine and the Sentinel agent exist today, and only Meta has checked them. The version Meta itself cannot see inside is promised for later this year, and nothing Meta has published says what happens if the version in use today is breached. Meta made 97.6% of its revenue from ads last year, its plan for Muse is a small cut of every transaction paid by the businesses, and the early web worked because nobody owned it. My verdict: stay away from this.
KEY TAKEAWAYS
- Before you connect your email, passwords or card to any AI agent, ask how it protects you today, in the present tense. A promise about a version coming later protects nothing you hand over now.
- Read the vendor's documents, not the interview. Meta's engineering post says what Muse does on a website can be used to show you an ad on Instagram, which no interview mentioned.
- If you run a store on Shopify, check Sales channels, then Agentic. Meta's agent and Google's AI may be able to check out from your store by default.
- Treat any agent that plans to take a cut from the store as a new middleman between you and your customers, and price that in before you switch it on.
- Watch Joanna Stern's full interview with Zuckerberg and judge his answer on privacy and security yourself.
SHOW NOTES
Zuckerberg Says Muse Needs To Be Discreet, But Some Of Its Calls Were Made By People
In his interview with Joanna Stern, Mark Zuckerberg explained what it means for an AI to be discreet. You ask it to book a restaurant, and it does that without telling a stranger you are pregnant. The same month, some of the calls Muse made to businesses were placed by people in a call center, and at least one person testing it was not told the caller was human.
Muse is Meta's AI agent, an assistant that goes off and does things for you: it books, it buys, and it can read your email. It is free, and according to The Information more than half a million people tried it in its first week. How many kept using it, only Meta knows. Stern uses it every day and still has not connected her personal Gmail, because she is not sure she trusts Meta with it. His answer described the design and a lot of what is coming. It did not answer her question.
Only Meta Has Checked How Muse Protects Your Data
Every user gets a separate virtual machine, a computer Meta runs for you in the cloud, and your logins live there. A second program, Sentinel, keeps your passwords away from Muse and approves anything it sends out. That is present tense, and nobody outside Meta has published a check of it. Meta says your conversations stay out of its ad systems, and in the same section says what Muse does on a website can be used to show you an ad on Instagram.
The protection from Meta itself is future tense. The Muse Confidential VM, encrypted with a key only you hold so Meta cannot see inside, is promised for later this year. Nothing Meta has published says what happens if the version in use today is breached.
Meta Makes Its Money From Ads And Wants A Cut Of Every Muse Transaction
Meta made 97.6% of its 2025 revenue from ads, and in 2019 the FTC fined Facebook $5 billion for deceiving people about their ability to control their privacy. Zuckerberg told Alex Heath the business model for Muse over time is a very small cut of every transaction, paid by the businesses.
In 1993 CERN gave the web away, and it ran on your computer. That is how it became the web. The agentic web is being built by companies that want to run the computer, sit in the middle, and take a cut.
WATCH ON YOUTUBE
QUESTIONS ANSWERED
What is Meta Muse?
Meta Muse is Meta's AI agent, an assistant that does things for you on websites and apps: it can book, buy, and read your email. It runs on a virtual machine Meta sets up for each user in the cloud, and it launched in September 2026.
Is Meta Muse free?
For most people, yes. Mark Zuckerberg said on the Sources podcast that free use starts at around 100 million tokens a week plus a virtual machine, and that a paid subscription is available for anyone who wants one.
Is Meta Muse safe?
Meta describes a separate virtual machine for each user and a second program, Sentinel, that keeps your passwords away from Muse and approves anything it sends out. Nobody outside Meta has published a check of that design. In September 2026 Amazon blocked Muse, saying it appears to capture and store customer credentials, and Meta patched a flaw in the Muse Mac app within hours of it going public.
Can Meta see your Muse data?
Meta says Muse does not share your conversations or the data in your virtual machine with its ad systems. The version that Meta itself cannot access, the Muse Confidential VM, encrypted with a key only you hold, is promised for later this year and was not available when Muse launched in September 2026.
Does Meta Muse use your conversations to train AI?
Yes, by default. Meta's engineering post on Muse says conversations are used to train Meta's AI models, and there is a switch in the Muse settings to turn that off.
Does Meta Muse make phone calls?
Yes. Meta Muse can phone a business to book something for you, such as a restaurant table. Reuters reported from Meta's internal posts that in September 2026 some of those calls were placed by human contractors rather than the AI, and that at least one person testing Muse was not told the caller was human.
SOURCES
- Joanna Stern's interview with Mark Zuckerberg her Gmail question at 29:11, his answer to about 32:06
- Alex Heath, Sources podcast, with Mark Zuckerberg the take rate at about 25:06
- Introducing Muse, Meta
- Security and safety for AI agents, Meta's approach with Muse the section on ads, and the Confidential VM
- Meta's 2025 annual report advertising, 97.6% of revenue
- FTC, $5 billion privacy penalty on Facebook, 2019
- CERN, 30 years of a free and open web
CHAPTERS
- 00:00Discreet AI, and calls made by people
- 00:59What Muse is, and the agentic web
- 02:33Joanna Stern's question
- 03:57Present tense: the virtual machine and the ads
- 05:45Passwords, Sentinel, Amazon and the Mac app
- 07:05Future tense: the locked version and discretion
- 10:10Who is asking: an ad company with a privacy record
- 11:40From the browser wars to the agent wars
- 14:42Two documents, 1993 and 2026
- 16:00After the episode: moving to Saturdays
RELATED ARTICLES
Amazon Blocked Meta's Muse, And robots.txt Had Nothing To Say
Amazon cut Meta's Muse off from its store on 20 September with a Conditions of Use notice. Its own robots.txt blanket-refuses 99 named agents, and Muse is not one of them, because Meta's crawler documentation lists no user agent string for it.
The Text-Only Version Of Your Website Strips Out The Wrong Layer
Strip a website down for machines and you should get something a machine can use. The text-only versions being served to AI are the page with the buttons removed, and GEO, the discipline for getting cited in AI answers, has organised itself around the half that cannot act.
Apple On The Agentic Web: Every Way It Uses Your Website
Siri AI runs on Google's Gemini, and for a website the interesting part is not the model. Apple now reaches your pages five ways, three of them new this month, two with no user agent and nothing you can set. Every agent, every control, and what each control actually covers.
ENJOYING THIS EPISODE?
Practical strategies for making your website work for AI agents and the humans using AI to find you. Once a week you get the new articles, the latest podcast episode, and a few links worth keeping.
