deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Meta's Muse runs every user's AI agent on a dedicated cloud VM

Meta's Muse agent gives each user a private cloud VM with a browser, a terminal and a credential vault it cannot read, and infrastructure vendors are already selling the same pattern.

Meta's Muse runs every user's AI agent on a dedicated cloud VM

Meta has launched Muse, a personal AI agent that can send email, book travel, fill out forms and make purchases on a user's behalf. According to a dev.to post that draws on Meta's own announcement and engineering write-ups, Muse was introduced on September 8, 2026, and its most notable feature is not what the agent does but where it runs: every user gets a dedicated virtual machine in Meta's cloud.

A private machine for every user

The post, originally published on the Burrowbox blog, describes what Meta calls the Muse Secure VM. Each user's agent runs on its own VM, isolated so that no other user's agent can reach it. Inside that machine the agent has a full working environment, including a file system, a terminal and a complete web browser, and its memory persists between conversations, so context is not lost when a session ends.

How credentials are handled

Passwords and payment details are placed in secure storage that Muse can act on but cannot inspect. The agent itself runs inside an isolated container and only ever holds stand-in tokens; real credentials are attached to a request as it leaves the machine. A separate component Meta calls Sentinel, running on the same machine, must approve any traffic that reaches the internet. On top of that, Muse checks with the user before taking sensitive actions such as sending an email or completing a purchase, and it keeps a record of everything it has done.

Vendors are already selling the pattern

The rest of the dev.to post is a tutorial for reproducing the architecture with Burrowbox, a service offering persistent Linux machines with browsers, and the Vercel AI SDK. The recipe is straightforward: give each customer a machine whose browser stays signed in across restarts, keep logins in an encrypted vault the agent never sees the contents of, connect the AI SDK's MCP client using a machine-scoped token so an agent can only reach its own machine, and embed a read-only live view so users can watch the agent work.

Burrowbox quotes $0.07 per hour for a running tiny machine and $0.001 per hour while stopped, estimating roughly $1.05 a month in compute plus $0.72 in storage for a user whose agent runs 30 minutes a day. Worth noting that this is vendor marketing material, and Burrowbox states it is not involved with Muse. The post also acknowledges one gap in the comparison: unlike Sentinel, Burrowbox does not filter outbound traffic, so the decision about which steps require user confirmation is left to the developer building on it.

Why it matters

Most consumer AI products today run as stateless, shared calls to a model. Muse represents a different bet: treat each user as the owner of a small, persistent computer that an agent lives on. That shift changes the security conversation, moving isolation from prompt-level safeguards to VM boundaries, credential mediation and an approval gate for network access. It also makes agents auditable in a concrete way, because a machine with a file system and a browser leaves a trail of what happened. And it changes the economics: persistent per-user VMs cost real money at consumer scale, which may be part of why infrastructure vendors are moving quickly to sell the pattern to everyone else.

  • #meta
  • #ai-agents
  • #virtual-machines
  • #cloud
  • #security

Related posts