메뉴
BL
Wired AI • 17일 전

메타, 개인 AI 에이전트 '뮤즈(Muse)' 공개…프라이버시 강조

IMP
8/10
핵심 요약

메타가 iOS·안드로이드 앱과 WhatsApp, 웹사이트(Muse.ai)를 통해 디지털 작업을 자동화하는 개인 AI 에이전트 '뮤즈(Muse)'를 출시했습니다. 뮤즈는 'Secure VM'이라는 격리된 가상머신 아키텍처와 프롬프트 인젝션 방지용 'Sentinel' 감시 시스템으로 보안과 프라이버시를 설계 단계부터 내재화한 것이 차별점입니다. Stripe의 Link 결제 인프라를 활용해 일회용 카드 번호로 대리 결제를 지원하며, 오픈AI·Anthropic 대항용으로 설립된 메타 슈퍼인텔리전스 랩스의 첫 대표 소비자용 에이전트라는 점에서 의미가 큽니다.

번역된 본문

메타는 화요일, 개인 AI 에이전트 '뮤즈(Muse)'를 공개했다. 사용자는 뮤즈에 메시지를 보내 보안이 유지되는 클라우드 환경에서 디지털 작업을 자동화할 수 있으며, 메타는 보안과 프라이버시가 처음부터 시스템에 '내재화'되어 있다고 강조한다.

메타에 따르면 뮤즈는 오늘부터 iOS와 안드로이드 사용자를 위한 전용 뮤즈 앱과 웹사이트 Muse.ai에서 제공되며, WhatsApp에서도 뮤즈와 직접 대화할 수 있다. AI 안경 사용자들도 곧 뮤즈 에이전트와 상호작용할 수 있게 될 예정이다. 뮤즈는 무료로 체험할 수 있지만, 다수의 디지털 작업을 자동화하려면 메타의 AI 구독 플랜 중 하나가 필요하다.

뮤즈는 오픈클로(OpenClaw)와 인스팅트(Instinct) 같이 사용자에게 메시지를 보내 디지털 작업을 자동화하는 바이럴 AI 에이전트들과 경쟁하기 위한 메타의 최신 시도다. 뮤즈는 메타 슈퍼인텔리전스 랩스(Meta Superintelligence Labs)의 산물로, 이 조직은 마크 저커버그 CEO가 약 1년 전 오픈AI와 앤스로픽(Anthropic)을 따라잡기 위해 만든 AI 부서로, 일부 연구자들에게는 눈이 튀어나올 정도의 파격적인 보상 패키지를 제공하며 영입했다. 이 부서는 AI 에이전트가 일반 사용자의 인터넷 이용 방식과 메타의 제품들을 변화시킬 것이라는 믿음 위에 세워졌다.

와이어드(WIRED)는此前 메타가 '해치(Hatch)'라는 코드명으로 뮤즈를 내부 테스트해왔으며, 직원들이 이를 통해 제3자 애플리케이션을 자율적으로 조작하고 자신을 대신해 웹을 탐색하는 데 사용해왔다고 보도한 바 있다.

메타는 블로그 포스트에서 누구나 별도 학습 없이 뮤즈를 바로 사용할 수 있으며, '학습 곡선이 없도록' 설계되었다고 주장한다. 사용자는 자연어로 뮤즈에게 지시할 수 있고, 에이전트는 스스로 이메일을 보내거나, 여행을 예약하거나, 심지어 사용자를 대신해 자동차 판매를 도울 수 있다. 뮤즈는 Stripe가 설계한 특별한 결제 인프라를 활용해 사용자를 대신해 구매하고 결제를 진행할 수도 있다. Stripe가 'Link'라고 부르는 이 결제 도구는 일회용 카드 번호를 발급해, 에이전트가 인터넷 전역에서 개인의 실제 금융 정보를 입력하지 않도록 한다. 메타는 뮤즈가 에이전트 대상 Link 구매 보호(수수료 없는 반품 보장)를 적용받는 최초의 AI 에이전트라고 밝혔다.

개인 AI 에이전트 시장에서 메타는 뒤늦게 합류했지만, 뮤즈의 보안 및 프라이버시 기능에 초점을 맞춰 차별화를 꾀하는 것으로 보인다. 이 에이전트는 모든 사용자를 위한 'Secure VM'이라는 아키텍처로 데뷔하는데, 이는 각 사용자의 활동을 소위 '가상머신(virtual machine)'으로 격리하여 신뢰할 수 없는 웹 데이터나 각종 연동 서비스가 사용자를 위해 실제 행동을 수행할 수 있는 에이전트 부분과 분리되도록 설계되었다.

개인 AI 에이전트는 사용자의 큰 신뢰를 필요로 하는데, 특히 메타는 수년간 이 부분에서 큰 어려움을 겪어왔다. 사용자가 뮤즈를 사용해보고, 제3자 앱·서비스와의 연동을 허용하도록 만들기 위해 메타는 자사가 사용자 데이터를 적절히 처리할 수 있다는 신뢰를 얻으려 하고 있다.

메타 슈퍼인텔리전스 랩스의 소비자 제품 엔지니어링 부사장 데이비드 싱글턴(David Singleton)은 "이렇게 다양한 개인 데이터 소스에 접근할 수 있는 제품을 만들려면 그 데이터를 정말 책임감 있게 다루는 것이 중요하다는 것을 알고 있고, 그래서 이 시스템을 매우 신중하게 설계했다"며 "'Sentinel'이라는 것을 만들었는데, 이것이 가상머신 밖으로 나가는 모든 것을 감시하여 사용자나 시스템이 허가한 기존 정책과 일치하는지 확인하거나, 취할 행동에 대한 승인을 요청하는 '휴먼 인 더 루프(human-in-the-loop)' 대화 상자를 사용자에게 제시한다"고 말했다.

싱글턴은 이러한 확인 요청 프롬프트가 모델을 거치지 않고 사용자에게 직접 전달되어, 프롬프트 인젝션(prompt injection) 같은 공격으로부터 보호한다고 설명했다. Secure VM은 사용자의 보안과 프라이버시를 유지하도록 설계되었지만, 완전히 잠긴 상자는 아니다. 싱글턴은 메타가 정책상 사용자 데이터에 접근하는 것이 금지되어 있다는 점도 언급했다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story Meta announced Tuesday the release of Muse, a personal AI agent that people can message to automate digital tasks in a secure cloud environment, all while relying on security and privacy that the company says is “built into it” from the start. Meta says Muse is rolling out today for iOS and Android users in a dedicated Muse app, as well as the website Muse.ai. The company also says users can directly message Muse in WhatsApp to interact with the agent. Meta says users of its AI glasses will soon be able to interact with its Muse agent as well. Meta says people can try out Muse for free, but users who want to automate lots of digital tasks will need one of the company’s AI subscription plans. Muse is Meta’s latest attempt to compete with viral AI agents such as OpenClaw and Instinct , which users can message with to automate digital tasks. Muse is a product of Meta Superintelligence Labs , the AI unit CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic, offering some researchers eye-popping compensation packages to join. The unit was built on the belief that AI agents will transform how everyday users navigate the internet, as well as Meta’s products. WIRED previously reported that Meta has been testing Muse internally under the codename “ Hatch ,” and that employees have been using it to autonomously operate third-party applications and browse the web on their behalf. Meta claims in a blog post that anyone can use Muse out of the box, and that the product was designed “so there’s no learning curve.” The company says users can prompt Muse in natural language, and the agent will work on its own to send emails, book travel, or even help sell a car on a user’s behalf. Muse is also capable of making purchases on behalf of users, checking out using special payment infrastructure designed by Stripe. The payment tool, which Stripe calls Link, issues a single-use card number so that agents aren’t going around entering a person’s real financial information across the internet. Meta says Muse is the first AI agent covered by Link’s purchase protections for agents, which guarantees no-fee returns. Meta is late to release a personal agent, but it seems to be seeking to differentiate itself by focusing on security and privacy features for Muse. The agent is debuting with an architecture for all users dubbed Secure VM, which is meant to isolate each user’s activity in a so-called virtual machine to keep untrusted data from the web and any integrations separate from the part of the agent that can actually take action on a user’s behalf. A personal AI agent requires a lot of user trust, something Meta in particular has struggled with significantly over the years . To get users to try out Muse—and allow the agent to be integrated with users’ third-party apps and services—Meta is attempting to convince people that they can trust the company to handle their data appropriately. “We know it’s really important, if we’re going to build a product like this that can access a lot of sources of personal data, that we’re really responsible with that, so we’ve designed this system very deliberately,” says David Singleton, Meta Superintelligence Lab’s vice president of engineering for consumer products. “And we’ve built what we call the Sentinel that actually looks out for everything that’s moving out of the VM and either matches it to an existing policy where the user or the system has given permission for that to happen or presents a human-in-the-loop dialog to ask you to approve the action it’s going to take.” Singleton notes that these check-in prompts for humans come directly to the user and aren’t filtered through the model, to protect against attacks like prompt injections. While Secure VM is built to maintain user security and privacy, it is not a truly locked box. Singleton notes that while Meta is barred by policy from accessing user Muse data, it would still be technically possible. Users can opt out of allowing their data to be used for training. The architecture of Secure VM is noteworthy from a privacy standpoint, if only as a way to set a new industry standard for AI agents. Eventually, Meta will also offer Muse “Confidential VM,” designed so each VM runs in a “trusted execution environment” and users manage their own access keys locally on their devices. This way no one else, including Meta, can access that user’s agent VM. Confidential VM comes as part of Meta’s work with Moxie Marlinspike , creator of the end-to-end encrypted messaging app Signal who also developed the privacy-focused AI platform Confer in recent years. WIRED viewed an advance draft of a technical white paper describing Confidential VM. In addition to structuring the system so the user controls their access keys, Meta is also giving select security firms access to the Confidential VM source to regularly audit and verify its privacy guarantees. Meta will also publish the Confidential VM binaries (machine-readable instruction files) and a transparency log, so users can verify the validity and integrity of their connection to Muse. Singleton emphasizes that Muse Secure VM has already been extensively vetted, including by Meta’s human and agentic red teams as well as through the company’s private bug bounty. And now Meta is adding Muse to the scope of its public bounty as well, with payouts up to $300,000 for valid vulnerability findings, including up to $130,000 for successful prompt injection attacks that affect a single user.
관련 소식