Research investigation R0924 / comparison

Three Meta Privacy Boundaries, Not One: What Protects Muse and AI Glasses?

Meta describes three distinct processing paths with different availability and data-flow scopes. A protection described for one path should not be assumed to cover another.

Current public editionv1Sep 24, 2026
Verified observations
8

7 measured fields

Supported claims
9

9 material findings

Cited sources
5

5 primary or authoritative

Research score
82

Automated topic and evidence score

Interactive figureThree Meta Privacy Boundaries, Not One: What...
CSV JSON
Data statusAwaiting verified observations

The cutoff is the original September 24, 2026, 15:30 UTC collection snapshot. This is a bounded review of supplied public disclosures, not a survey of every account, device, request, or subsequently released feature.

Verified observationNo chart values are being inferredLast updated Sep 24, 2026

Version ledger

Frozen public editions

Each edition preserves the records, method, sources, and downloads available at publication time.

  1. v1 / latestSep 24, 20268 records / 5 sources

    Initial public snapshot with 8 records and 5 cited sources.

Coverage note

The cutoff is the original September 24, 2026, 15:30 UTC collection snapshot. This is a bounded review of supplied public disclosures, not a survey of every account, device, request, or subsequently released feature.

Dataset ID
spd:three-meta-privacy-boundaries-not-one-what-protects-muse-and-ai-glasses-c519d504
Stable URL
/research/three-meta-privacy-boundaries-not-one-what-protects-muse-and-ai-glasses-c519d504
Version
v1
Coverage
Live collection
Records
8
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
Three Meta Privacy Boundaries, Not One: What Protects Muse and AI Glasses? data records
EntityMetricValueUnitObservedSourceTransform
Muse Secure VMaction and network controlSentinel authorizes connector actions and network egress; user approval depends on action and grant scope—2026-09-24https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse—
Muse Confidential VMavailability at cutoffSmall trusted-tester group; general delivery planned later in 2026—2026-09-24https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse—
Muse Secure VMavailability at cutoffRolling out in the US on iOS, Android, and web—2026-09-24https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent—
Private Processing for AI glassesdesigned off-device verificationClient checks TEE certificate and software measurement against a witnessed ledger; failed checks prevent connection—2026-09-24https://engineering.fb.com/2026/09/23/security/private-processing-meta-ai-glasses—
Private Processing for AI glassesdesigned persistent-state protectionIf a feature needs persistent memory, output is encrypted with user-provided keys before leaving the TEE—2026-09-24https://engineering.fb.com/2026/09/23/security/private-processing-meta-ai-glasses—
Meta AI glassesdocumented present processing pathMeta says many directions, including placing calls and answering texts hands-free, occur entirely on device—2026-09-24https://engineering.fb.com/2026/09/23/security/private-processing-meta-ai-glasses—
Muse Secure VMMeta personnel access boundaryRestricted by operational policies; access remains possible to support, secure, or operate the service—2026-09-24https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse—
Muse Confidential VMpromised key holder and protected scopeKey held only by user; promised encryption of whole VM, including user data and Muse conversations—2026-09-24https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent—

Measurement technique

How to read this report

  1. 01Plan an evidence matrix with separate rows for Muse Secure VM, Muse Confidential VM, on-device glasses processing, and planned glasses Private Processing. Record availability, processing boundary, personnel access, keys, approvals, data leaving the boundary, persistent state, verification, and named feature coverage.
  2. 02Mark each cell documented as current, planned, or unspecified; do not infer feature coverage from workload examples or from another product’s threat model.
  3. 03Synthesize the saved Meta product, research, and engineering disclosures and the joint partner release. Treat the WhatsApp Private Processing whitepaper as background, not proof of glasses deployment. No new collection or implementation test was performed.

Sources

Evidence

4 publishers supporting 8 records. Expand a publisher to inspect its cited pages.

Next report / 01AI Model Economics Index All research reports
YOUR READING SPACE

Notifications