The Decoder reports that David Singleton, VP of Engineering at Meta Superintelligence Labs and former CTO of Stripe, says every Muse user gets a free, full-featured computer in the cloud. The machine runs a complete Ubuntu Linux image. Users can install software, write and compile code, or browse the web. Singleton says it was designed so people can do almost anything they would do on a physical machine under their desk.

He calls the arrangement the Muse Secure VM. The user and the Muse agent work inside a Runtime Cell, where activity is unrestricted. A Sentinel process outside the cell monitors sensitive actions. Passwords and credentials are stored outside the cell as well.

[1]
Tempera picture: a lit workroom with a computer, and a lock with a closed booklet sitting outside the room.
The computer is inside the workroom, while the lock and the credential booklet stay outside it. They stand for the cloud computer each user receives, and for credentials kept outside the workspace., AI-generated illustration, not a news photograph

The Runtime Cell has its own root filesystem, separate from the host. Singleton says someone looking around inside it does not get privileged access to Meta's infrastructure or to other users' data. He also says the architecture guards against prompt injection.

Meta made the cell's files visible on purpose. Users can see everything from Debian system files to the binaries that run Muse inside the cell. A file explorer sits in the Library tab, and the Markdown files Muse writes while reasoning are visible too. People who do not want that view can export their material from Settings, then Data controls, then Download your agent data.

The Decoder also reports that the app drew more than 500,000 users in its first week and reached number one on the Apple App Store. At Meta Connect 2026, the company added real-time video chats, dedicated email addresses, and the ability to control Mac apps. The user count and store ranking appear in the article's product recap; the piece does not attribute those two figures to Singleton by name.

[1]

The report does not give memory, CPU, disk quota, or how long the computer is kept, and it does not say whether the free tier will change. It does not list which actions Sentinel blocks, or which prompt-injection attacks were tested. Being able to see system files is not the same as administering the host. Singleton's claim is that the workspace is separated from the host, not that each user receives a private physical server.

[1]

要点

  • Each user gets an Ubuntu cloud computer that can install software.
  • Credentials and the monitoring process sit outside the Runtime Cell.
  • The article's figure of 500,000 first-week users is not attributed to Singleton by name.