In August, Mark Zuckerberg met Meta’s chief AI officer, Alexandr Wang, and its head of AI product, Nat Friedman, Eli Tan reported for The New York Times on Friday. They discussed Instinct, a 14-person start-up whose AI agent was taking off. Zuckerberg told them Muse was ready to launch despite the risks, according to three people with knowledge of the meeting.
Two of those people told the Times that Wang and Friedman knew of safety concerns from recent tests. In one case, Muse changed a user’s password without permission. TNW has not independently verified the account. A Meta spokesman disputed that pressure from Instinct drove the Muse launch. He said in a statement to the Times:
“We’re proud of this work and, as we’ve said publicly, we even delayed shipping Muse for several months to make sure we got this right.”
Meta spokesman, in a statement to The New York Times
From a memo to OpenClaw
In July 2025, Zuckerberg published a memo on “personal superintelligence”, a form of AI he said could act as the ultimate assistant. He had hired Wang and Friedman to lead the work, the Times reported.
In November 2025, Austrian programmer Peter Steinberger released OpenClaw. It is an open-source agent that writes code and uses a computer on its own. Meta’s vice president of AI products, Vishal Shah, told the Times that executives then saw the next consumer product as a personal agent.
After trying OpenClaw, Friedman ordered 200 Mac Minis, the computers the agent runs on, to Meta’s headquarters, according to the newspaper.
Testing in 2026
In February, an AI agent took over the work computer of Meta safety researcher Summer Yue and deleted her emails. She wrote on X that she could not stop it from her phone:
“I had to RUN to my Mac mini like I was defusing a bomb.”
Summer Yue, on X
The same month, Friedman showed Muse to Meta’s board, the Times reported. In April, Meta released Muse Spark, a model built under Wang. Muse had run on Anthropic’s models early on. Muse Spark let Meta power it with its own model.
Shah told the Times that Meta had a version of Muse it could have released by then. The company then spent months making sure its safety features were secure. In tests with staff, the agent occasionally disobeyed commands, the newspaper reported. It also led people to buy from fraudulent websites. Some of these safety issues were reported earlier by The Information, the Times noted.
The August meeting and the launch
Instinct’s agent grew in popularity in August, the month of the meeting. Meta launched Muse on 8 September. Friedman later addressed the similarities between Muse and OpenClaw in posts on X.
After the launch
On 22 September, a zero-day flaw in the Mac version of Muse was made public. Meta said it had issued a fix, Ars Technica reported. The flaw let malware already on a Mac take over the agent and use the permissions a user had given it.
On 28 September, a user said Muse gave his address to a Facebook Marketplace buyer without asking him. Instinct raised $1bn at $10bn in September. On 29 September, OpenAI announced Dots, its own agent.
On 30 September, Meta denied a claim by Inc. columnist Jason Aten that Muse read his private messages without his permission.
On 3 October, WIRED reported that Muse’s instructions tell it to keep a page on each person in a user’s life. Researcher Karan Joshi had extracted the instructions through the app’s chat. Meta told WIRED that Muse builds this context from public information and from what users choose to share.
On 5 October, 404 Media reported that Meta engineers rushed to patch severe security flaws in Muse before launch.
As of Wednesday, more than 6.6 million people had downloaded Muse, according to Sensor Tower data cited by the Times. Of those, 1.8 million were using it every day.
Get the TNW newsletter
Get the most important tech news in your inbox each week.