메뉴
BL
The Decoder • 15일 전

메타, 왓츠앱으로 조작하는 AI 에이전트 '뮤즈' 공개

IMP
8/10
핵심 요약

메타가 왓츠앱(WhatsApp)으로 제어하는 AI 에이전트 '뮤즈(Muse)'를 공개했습니다. 뮤즈는 여행 예약, 쇼핑, 이메일 작성, 가격 협상 등을 스스로 수행하며, Stripe의 Link 서비스를 통한 일회성 카드 결제로 사용자 승인 후 구매를 완료합니다. 이는 OpenAI가 ChatGPT에서 철회한 직접 결제 기능을 메타가 선점한 것으로, 격리된 가상머신과 감시 에이전트 '센티널(Sentinel)'을 통한 보안 구조도 강조됩니다.

번역된 본문

뮤즈는 쇼핑, 이메일 작성, 가격 협상을 사용자 대신 수행하며, 모든 것을 왓츠앱을 통해 처리한다

주요 요점

메타는 왓츠앱을 통해 제어하는 AI 에이전트 '뮤즈(Muse)'를 공개했다. 메타에 따르면 뮤즈는 웹에서 여행 예약 같은 작업을 스스로 처리한다. 양식 작성과 사용자 대상 협상도 가능하다.

뮤즈는 사용자 승인 후 Stripe의 Link 서비스를 통해 메타가 안전하다고 설명하는 일회성 카드로 구매를 완료한다. 이로써 메타는 OpenAI가 최근 ChatGPT에서 제거했던 직접 결제 기능을 확보하게 됐다.

뮤즈는 메타가 '격리된 가상머신'이라 부르는 환경에서 실행되며, 감독 에이전트가 모니터링한다. 메타는 이 구조가 비밀번호를 숨기고, 상호작용이 광고 시스템으로 흘러들어가지 않는다고 말한다.

본문

메타의 새 에이전트 뮤즈는 여행 예약부터 쇼핑까지 작업을 스스로 처리하도록 설계됐다. 자체 가상머신에서 실행되며 왓츠앱으로 제어한다.

사용자는 이메일 전송이나 여행 예약 같은 간단한 작업을 뮤즈에게 맡길 수 있지만, 메타는 더 큰 목표도 수행할 수 있다고 주장한다. 이런 경우 뮤즈가 단계를 계획하고 시간과 자원을 조율한다고 메타는 설명한다.

에이전트는 브라우저를 열고, 양식을 작성하며, 사용자를 대신해 협상한다. 메타에 따르면 뮤즈는 자동차를 더 비싸게 팔거나, 요금을 낮추거나, 운동 계획을 조정할 수 있다. 장기 작업의 경우 앱을 닫아도 뮤즈는 계속 실행된다. 메타는 상황이 변하거나 실제 이메일 전송이나 구매 직전처럼 승인이 필요할 때 사용자에게 확인을 요청한다고 말한다.

메타에 따르면 뮤즈는 사용자에게 중요한 정보를 기억하고 스스로 제안도 한다. 어시스턴트는 메타의 생태계와 연결된다. 인스타그램에 저장한 레시피 릴을 장보기 목록으로 바꾸거나, 친구들의 음식 알레르기를 고려해 저녁 모임 메뉴를 제안할 수 있다고 메타는 말한다.

OpenAI가 포기한 결제 기능을 메타가 구축하다

뮤즈는 Stripe가 만든 Link 서비스를 통해 결제할 수 있다. 메타는 뮤즈가 Link의 구매 보호 대상이 되는 최초의 AI 에이전트라고 밝혔는데, 이 보호는 파손·분실 상품, 가격 인하, 반품을 다룬다. 각 결제 시 Link가 일회성 카드를 생성해 실제 카드 정보는 숨겨진다. Shop Pay와 1Password 연동도 이어서 지원될 예정이어서, 뮤즈가 기존 로그인을 사용할 수 있게 된다.

이는 사용자가 채팅에서 제품을 조사했지만 그곳에서 구매하지 않았고, 판매자 연결이 수작업으로 남아 있던 채로 직접 결제 기능을 중단하고 결제를 판매자에게 돌려준 OpenAI를 메타가 앞서게 된 것이다.

데이터 보호를 위해 격리에 의존하는 메타

메타는 발표의 상당 부분을 보안에 할애하고 별도 블로그 포스트에서 더 자세히 다룬다. 뮤즈 시큐어 VM(가상머신)은 클라우드의 자체 머신에서 실행되며, 외부 에이전트가 접근할 수 없도록 격리된다. 메타에 따르면 연결된 서비스의 로그인 자격 증명도 그곳에 보관된다.

메타는 '센티널(Sentinel)'이라는 두 번째 에이전트가 뮤즈와 분리되어 같은 머신에서 실행된다고 밝혔다. 센티널이 승인하지 않는 한 뮤즈의 어떤 행동도 인터넷에 도달하지 않는다. 메타에 따르면 뮤즈 자신도 비밀번호나 결제 수단을 볼 수 없다. 자격 증명은 뮤즈가 사용할 수는 있지만 열람할 수 없는 보안 저장소에 보관된다.

민감한 행동 전에는 뮤즈가 먼저 물어보고 모든 단계의 전체 기록을 보여줘야 한다. 사용자는 에이전트가 어떤 앱에 연결할지, 이메일을 읽기만 할지 보내기도 할지처럼 접근 범위를 결정한다. 접근 권한은 언제든 변경하거나 차단할 수 있다.

메타는 시스템이 얼마나 견고한지에 대한 수치는 공개하지 않았다. 보안 연구자들은 조작된 콘텐츠를 통해 에이전트 시스템이 탈취될 수 있음을 보여왔다. Perplexity의 Comet 브라우저에서는 조작된 캘린더 초대장만으로 비밀번호 관리자 계정을 장악할 수 있었다.

메타 광고 시스템은 이미 AI 채팅을 사용한다

사용자는 메타가 AI 모델 학습에 자신의 상호작용을 사용하는 것을 거부할 수 있다. 메타에 따르면 뮤즈는 대화와 VM의 데이터를 회사의 광고 시스템과 공유하지 않는다. 에이전트는 잊어버리도록 되어 있다(원문 누락).

원문 보기
원문 보기 (영어)
Muse can shop, write emails, and negotiate prices for users, all through WhatsApp Jonathan Kemper View the LinkedIn Profile of Jonathan Kemper Sep 10, 2026 Meta Key Points Meta unveils Muse, an AI agent controlled through WhatsApp that Meta says handles tasks like booking travel on the web on its own. According to Meta, it fills out forms and negotiates on the user's behalf. Muse completes purchases after a user's approval through Stripe's Link service, using one-time cards Meta describes as secure. That gives Meta a direct payment feature, which OpenAI recently dropped from ChatGPT. Muse runs on what Meta calls a walled-off virtual machine, monitored by an oversight agent. Meta says the setup keeps passwords hidden and that interactions don't flow into its ad system. Ask about this article… Search Meta's new agent Muse is built to handle tasks on its own, from booking travel to shopping. It runs on its own virtual machine and you control it through WhatsApp. Users can hand Muse simple jobs like sending an email or booking a trip, but Meta also claims it can take on bigger goals. For those, Meta says Muse plans the steps and coordinates time and resources. The agent opens a browser, fills out forms, and negotiates on the user's behalf. According to Meta, Muse can sell a car for more, lower a bill, or adjust a workout plan. For longer tasks, Muse is supposed to keep running even when the app is closed. Meta says it checks in when something changes or when it needs approval, like before it actually sends an email or makes a purchase. Ad Muse also remembers what matters to users and makes suggestions on its own, according to Meta. The assistant taps into Meta's ecosystem here. Meta says it can turn a recipe reel saved on Instagram into a shopping list, or suggest a menu for a dinner party while accounting for friends' food allergies. Ad Meta builds the payment feature OpenAI walked away from Muse can pay through Link, the service Stripe built. Meta calls Muse the first AI agent covered by Link's purchase protection, which is meant to handle damaged or lost items, price drops, and returns. For each payment, Link creates a one-time card, so the real card details stay hidden. Shop Pay and a connection to 1Password are set to follow, so Muse can use existing logins. That puts Meta ahead of OpenAI, which stopped its direct payment feature in ChatGPT and handed checkout back to merchants . Users researched products in the chat but didn't buy there, and connecting merchants stayed a manual job. Ad Meta relies on isolation to protect data Meta spends a big chunk of the announcement on security and offers a deeper look in a separate blog post . Muse Secure VM is supposed to run on its own machine in the cloud, walled off so no outside agent can reach it. According to Meta, that's also where the login credentials for connected services sit. Meta says a second agent called Sentinel runs on the same machine, separate from Muse. Nothing Muse does is meant to reach the internet unless Sentinel clears it. Muse itself sees neither passwords nor payment methods, according to Meta. Credentials are supposed to land in a secure store that Muse can use but not view. Ad Before sensitive actions, Muse is supposed to ask first and show a full record of every step. Users decide which apps the agent can connect to and how far its access reaches, like whether it only reads emails or also sends them. Access can be changed or cut off at any time. Ad Meta doesn't share numbers on how robust the system is. Security researchers have shown how agentic systems can be hijacked through manipulated content. With Perplexity's Comet browser, a doctored calendar invite was enough to take over a password manager account. Meta's ad system already uses AI chats Users can opt out of letting Meta use their interactions to train AI models. Muse doesn't share conversations and data from the VM with the company's ad systems, according to Meta. The agent is supposed to forget what it learned if you ask it to. Later this year, Meta also plans to launch Muse Confidential VM, which is meant to encrypt the entire VM with a key only the user holds. That doesn't apply to Meta AI. Since December, the company has used interactions with the assistant for personalized ads and content on Facebook and Instagram in most regions, leaving out sensitive topics like religion, health, or political views. Meta talks about "personal superintelligence" Meta calls "personal superintelligence," which Zuckerberg also made the central theme of a recent essay , one of the most transformative technologies there is, and it calls Muse a first step toward it. The model behind it has closed the gap sharply in five months. Muse Spark , released in April, would score just 31 points on the current Artificial Analysis Intelligence Index v4.3. Since early September, version 1.3 reaches 44 points on the available xhigh tier and 48 on the max tier, which so far is open only to partners. GPT-5.6 Sol (Max) sits at 47, while GPT-6 Astra (Max) and Claude Fable 5.1 land at 53. In May, word got out that the company was training an agent called Hatch , which learns in walled-off web environments on simulations of real sites like DoorDash, Etsy, and Reddit. Muse is likely based on it. Most recently there was talk of a paid product costing up to $200 a month . Muse launches first in the US for iOS and Android, with a link to Meta's AI glasses to follow. Users get a free usage limit that refills on a regular basis. For more, Meta offers subscriptions. AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now Source: Meta | Security