i
News
News · 2026-09-28

Meta’s enterprise AI bet hinges on control, not capability

@neuronium_ai @neuronium_ai

Meta has launched an enterprise AI platform and appointed MongoDB CEO and President Dev Ittycheria to lead it. The move turns the company’s fast-growing consumer assistant, Muse, into a possible opening bid for business customers. But the announcement leaves the central issue unresolved: a useful agent needs access to company data and tools, while the businesses deploying it need clear ways to monitor, limit and audit what it can do.

Cover: Meta’s enterprise AI bet hinges on control, not capability

From personal assistant to workplace tool

Muse can send email and book trips. Meta says it runs in a separate virtual machine, asks permission before sensitive actions and records what it does. Sensor Tower estimated that the app had passed 3.4 million downloads by September 24, TechCrunch reported. Downloads, however, do not show how many people still use it. Muse also reached No. 1 in the US Apple App Store and Google Play Store during its first two weeks.

Meta AI product head Nat Friedman said the company built Muse from scratch, while drawing on design ideas from OpenClaw after experimenting with the open-source assistant. That is influence, not evidence that Muse uses OpenClaw code.

The architecture matters because an agent becomes more useful as it gains access to more accounts, data and actions. For a business, the same access raises the stakes of oversight.

Meta describes a separate credential store and Sentinel, a monitoring component that checks actions requested by the agent. But its security documentation says the current architecture does not technically prevent Meta from accessing information in a user’s virtual machine when needed, including for service operation or protection. Meta says Confidential VM, which uses encryption, is intended to limit that access in the future; it has not said the protection is already available in Muse.

A separate issue surfaced in a Mac app vulnerability reported by VentureBeat last week. Security researcher Patrick Wardle found that malware already running in a user’s account could intercept authentication data and control the agent. Meta fixed the vulnerability within a day. The attack required malware to be on the Mac already, and did not compromise Muse’s cloud isolation.

VentureBeat also found that the consumer version records individual actions but does not describe a shared activity view for a company security team. In a test, the publication’s security correspondent Louis Columbus used a personal account to ask Muse to create a simple deal list and add a row to a connected Google spreadsheet. The test showed the agent could perform a business-relevant task, not whether corporate controls would detect or stop it.

That gap between capability and control is the real enterprise question. Meta’s Monday announcement did not explain how a personal agent would work with shared company data, employee permissions or approval procedures. Nor did it say how Muse Code and Muse API would fit into the offering, or how the products would be sold and administered.

The appointment is clearer than the product

Ittycheria brings experience selling software to large organizations. Before becoming MongoDB’s CEO and president, he led product and engineering teams at Cloudflare, then spent nearly eight years at ServiceNow, including as president and chief operating officer, Meta said.

At launch, Ittycheria said the platform would turn Meta’s AI tools into products companies could deploy themselves. He also said security and privacy were built into Meta’s enterprise products. The company did not provide detailed technical specifications for enterprise data protection.

The consumer launch gives Meta an audience and a working demonstration of what an agent can do. It does not establish that the company has solved the harder organizational problem: deciding who grants access, who reviews actions and what happens when an agent makes a mistake.

I think that distinction is where business buyers will focus. A demo can show an agent adding a spreadsheet row; it cannot show whether the company’s security team can see that action, approve it or reverse it.

The potential effects may extend beyond a company’s own systems. In a September 27 note, Apollo chief economist Torsten Slok described a hypothetical “agentic bank run”: future assistants could move household cash from low-interest checking accounts into higher-yield accounts. Slok compared the 0.1% average rate on US checking accounts with rates of 3.3% to 5.0% elsewhere. This was a scenario about what future agents might do, not evidence that Muse is moving deposits or that customers are withdrawing money at scale.

Meta’s enterprise history raises a different test

Meta already sells business tools, but its current Meta for Business suite—formerly Facebook for Business—is for managing a company’s presence and customer interactions on Facebook, Instagram and Messenger. It is not Workplace, the internal communications product Meta launched in 2016.

Workplace had more than seven million paid subscribers by 2021. Meta announced in 2024 that it would discontinue the product. It remained available for normal use until August 2025 and closed in May 2026.

Meta also promoted virtual reality for work. It introduced Horizon Workrooms, an app for meetings and collaboration, in 2021 and marketed Quest headsets to businesses. Workrooms closed in February 2026. Horizon Worlds, Meta’s social virtual platform, is separate from Workrooms.

Those closures do not determine the fate of the new AI platform. But they give buyers a practical reason to look beyond what an agent can do in a demonstration. I’d want to know what Meta will commit to on pricing, service guarantees, data handling, administrator rights, integrations and migration to another system. The launch announcement supplies none of those terms.

For Meta, the challenge is not simply to make Muse useful at work. It is to persuade companies that the platform will remain governable—and supported—after the demo ends.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X