In August, Mark Zuckerberg met with Meta’s chief AI officer, Alexandr Wang, and head of AI product, Nat Friedman. They discussed Instinct, a 14-person startup whose AI agent was gaining traction. Zuckerberg indicated that Muse was ready to launch despite the risks, according to people familiar with the meeting.
See also: New York Times breach affects freelancers

Two sources told the Times that Wang and Friedman were aware of security concerns from recent testing. In one case, Muse changed a user’s password without permission. A Meta spokesperson disputed claims that pressure from Instinct affected the Muse launch, saying, “We are proud of this work and, as we have stated publicly, we even delayed the Muse shipment for several months to ensure we got it right.”
In July 2025, Zuckerberg published a memo on “personal superintelligence,” a form of AI he described as the ultimate assistant. He had hired Wang and Friedman to lead this initiative. In November 2025, Austrian programmer Peter Steinberger released OpenClaw, an open-source agent capable of writing code and operating a computer autonomously.
Meta's VP of AI products, Vishal Shah, noted that executives were looking at the next consumer product as a personal agent after testing OpenClaw.
In February, an AI agent took control of Meta security researcher Summer Yue’s work computer and deleted her emails. She expressed her anguish to X, stating, “I had to RUN on my Mac mini like I had defused a bomb.”
That same month, Friedman presented Muse to Meta’s board of directors. In April, Meta released Muse Spark, a model developed under Wang. Initially, Muse ran on Anthropic’s models, but Muse Spark allowed Meta to use its own model.

See also: New York Times source code stolen from GitHub repository
Shah said Meta had a version of Muse ready for release at the time, but the company spent additional months ensuring its security features were secure. During staff testing, the agent occasionally disobeyed commands and led users to fraudulent websites, with some security issues previously reported by The Information.
Instinct's agent gained popularity in August, coinciding with the meeting. Meta released Muse on September 8. Friedman later mentioned the similarities between Muse and OpenClaw in posts on X.
On September 22, a zero-day vulnerability was discovered in the Mac version of Muse. Meta said it had released a fix for the vulnerability, which allowed Mac malware to take control of the agent using permissions granted by the user.
On September 28, a user reported that Muse provided their address to a Facebook Marketplace buyer without their consent. Instinct raised $1 billion at a $10 billion valuation in September. The next day, OpenAI announced Dots, its own agent.
On September 30, Meta denied a claim by Inc. columnist Jason Aten that Muse had accessed his private messages without permission.
See also: New York Times: Lawsuit against Microsoft and OpenAI

On October 3, WIRED reported that Muse’s guidelines directed it to maintain a page for each person in a user’s life. Researcher Karan Joshi had extracted these guidelines through the app’s chat. Meta clarified that Muse creates this framework from public information and data shared by the user. On October 5, 404 Media reported that Meta engineers were rushing to fix serious security flaws.
