The Meta Connect 2026 conference opened with a keynote from CEO Mark Zuckerberg, where he talked about the company’s new agentic artificial intelligence (AI) platform, Muse, which has the potential to disrupt e-commerce.
The company is positioning Muse as a personal AI agent, which people can customise and use to perform tasks such as internet shopping, checking for the best deal on price comparison sites, and booking travel and entertainment.
Some industry watchers believe Muse has the potential for widespread adoption among consumers since it can integrate with third-party services through curated connectors, managed by Meta and programmed as skills that the agentic AI system can use to complete a task.
But for seamless integration, the third-party service provider and Meta will need to collaborate and agree on a set of rules of engagement defining what Muse is allowed to do and what actions are prohibited.
Meta has connected Muse to Shopify for e-commerce and Stripe Link and PayPal for payments. It is also encouraging developers to submit application programming interfaces (APIs) to services curated by Meta for agentic end-to-end workflows.
Among the questions raised in the comments to a LinkedIn post by Prashant Ratanchandani, vice-president of engineering at Meta Superintelligence Labs, is the risk posed by an AI agent that has authority to complete payments.
Addressing Muse security concerns
During the opening keynote, Alexander Wang, who leads Meta’s Superintelligence Labs, said: “Personal agents need their own secure computer, so Meta built one for every person who uses Muse. The Muse secure VM [virtual machine] is yours, and this is how you make personal agents for everyone.”
In a LinkedIn post earlier this month, Tarek Sheasha, software engineer and vice-president at Meta Superintelligence Labs, discussed the security built into Muse. He described the VM as a “dedicated computer in the cloud” where a user’s Muse lives, and where all data and credentials for any service the user connects to are securely stored.
“Each VM is an isolated Linux box with a browser and enough storage, CPU [processing power] and memory to do real work,” he said.
According to Sheasha, the virtual machine is a system of record for everything the user puts into Muse. He said Muse only sends limited data out of the VM where necessary for inference and telemetry, and Muse client software like iOS and Android apps and the web user interface connect directly to the user’s VM via a secure transport layer.
The second area of security involves the way Meta works with third-party services to deliver Muse connectors. In the post, Sheasha said Meta needs to work closely with the service provider to integrate APIs.
“We’ve written and iterated on ‘skills’ – detailed instructions to Muse – on how to get the most out of each connector. Muse can also write its own custom connectors for other services you care about if they have their own APIs or CLIs [command line interfaces],” he said.
From Zuckerberg’s keynote, it would appear Meta sees Muse as a direct alternative to Google Search for e-commerce. It is also something Amazon has felt a need to block (see Retaliation: Amazon blocks Muse box), presumably to protect its own revenue.
Zuckerberg said Muse has a novel business model. “We believe that Muse will make you money and we are standing behind this by making Muse free for a huge number of tokens with the expectation that, over time, we will profit by taking a small fee from transactions,” he said.
Besides the fact that major e-commerce providers may actively block agentic systems like Muse, it is a very new product, and people may be concerned about giving an agentic AI system full control of their financial transactions.
Only 8% of people surveyed by analyst Forrester said they have tried Muse already. Commenting on the platform’s security, Forrester principal analyst Kate Winick said: “Meta did emphasise safety when it comes to their Muse agent, highlighting that it will ultimately utilise technology borrowed from WhatsApp to shield user interactions even from Meta, but Meta is betting big that that number will rise.”
Winick believes Muse is strongly positioned as a personal AI agent for billions of people who will never build their own AI agent. “It is a much more packaged and mediated experience from a company that is well experienced in building engaging user experiences,” she said.
Given that Muse is ready to use out of the box in a way that requires no technical ability, Forrester expects initial adoption to be high. However, Winick said: “Whether they use it long-term will depend on how safe and effective it proves to be.”

