Pioneers Insight Method Research Author
Mark Zuckerberg on how Meta's Muse AI agent will make people money
Back to Episodes

Mark Zuckerberg on how Meta's Muse AI agent will make people money

Summary

  • Meta is launching Muse, a long-lived personal agent that Zuckerberg positions as the fullest expression of his “personal superintelligence” thesis. Unlike prompt-and-answer chatbots, Muse runs on a cloud virtual machine, takes goals rather than prompts, works “24/7,” “studies overnight” by consolidating reflections into memory, and proactively suggests new projects — with meaningful model updates shipping roughly monthly.
  • The business model is deliberately aggressive: roughly 100 million tokens a week free, plus the VM, with monetization via “a very small cut” of transactions (Stripe on payments), potentially paid by merchants rather than users. Zuckerberg’s stated conviction: “we think that this thing is actually going to make you money and save you money and that is how it’s going to pay for itself” — free access being “critical if you want to build this future for everyone.”
  • On the model roadmap: Muse Spark 1.3 is based on a relatively smaller pre-training code-named Avocado. Heath cites a recent Artificial Analysis chart and says he thinks Muse Spark was behind Claude’s Fable 5.1 and Opus 5. Zuckerberg says the larger Watermelon model is shipping soon, while the gigawatt Prometheus cluster in Ohio is scaling post-Watermelon models.
  • Zuckerberg describes a privacy differentiator: a confidential-VM architecture involving Signal founder Moxie Marlinspike, whom he and Nat personally recruited and who helped build WhatsApp encryption in 2014, so “even Meta cannot see the content” — a commitment he says can be technically verified. Layered on top: Sentinel agents monitoring for prompt injection, human-in-the-loop approval for payments and logins, a secure credential store, and least-privilege connectors. “I’m not aware of anyone having anything close.”
  • The manifesto’s core is a rejection of Silicon Valley’s restrict-access consensus: “I personally am much more worried about a small number of labs or people having control of something that is so capable.” His three principles — empowerment drives prosperity, AI’s purpose is invention not automation, and safety comes from checks and balances — and his best evidence is the Hugging Face intrusion, where defenders turned to open-source models because they lacked access to some closed ones.
  • The personal-agent market is not winner-take-all, but Zuckerberg guesses fewer than a dozen companies can do state-of-the-art work, with power-law usage accruing to the best. Meta’s claimed edges: ground-up model design (including attention to “discretion”), social DNA, possible fleet-level interaction and learning across agents — “right now most of the industry is thinking about agents as like a single player game” — and distribution to “eventually billions of people.” Zuckerberg says most agent-to-agent interaction is not rolling out in this release.
  • On data-center backlash, he draws a dichotomy between decades-long operators and speculators flipping sites, citing Louisiana tax revenue funding $50,000 teacher bonuses and a workforce academy guaranteeing jobs to trained tradespeople. He won’t call it a bubble — “that implies that it’s overvalued… but there’s certainly a boom” — and argues that if AI doesn’t create broad-based prosperity, “it just effectively won’t be able to happen.”
  • On governance, he emphasizes close partnership with the U.S. government over relying on rigid frameworks that could be “out of date in a few months,” including ensuring the government knows about important training runs. The youth-safety settlement is framed as a legally binding industry mechanism: Meta unilaterally limits teen usage first, with the next step locking in when YouTube and TikTok sign the same terms — “we’re putting ourselves a little bit out there by going first.”

Deep dive

1. The 15-page manifesto: three principles against the Valley’s consensus

  • Zuckerberg’s rationale for writing it: “if you’re going to invest so much in building AI… it’s important that people understand what your lab stands for.” His three principles — empowering people is the source of prosperity; AI’s primary purpose is “invention of new things, not automation”; and safety rests on “checks and balances and balance of power rather than restricting access” — which he says are “oddly very different from a lot of the conventional wisdom, especially in Silicon Valley.”
  • The historical argument: “most advances don’t come from the incumbents or the establishment. They come from people on the periphery whose ideas aren’t taken seriously” — until they get tools.
  • His sharpest worry runs opposite to the doomer one: “I personally am much more worried about a small number of labs or people having control of something that is so capable,” and he calls the emerging practice of training advanced models without releasing them “quite dangerous.”

2. Open source as security policy: the Hugging Face specimen

  • The cyber argument, counterintuitive by design: “the best antidote to someone having an AI that could potentially hack into systems is having everyone have access to an AI so they can harden their own systems first” — the same dynamic that made open-source software more secure over decades.
  • His concrete case against gating capable cyber models to “the top hundred institutions”: “there’s more than 100 important institutions in the world.” When Hugging Face detected an intrusion, “they turned to open source models because they didn’t have access to some of the closed ones that were causing the issues.”
  • A hedge worth keeping: “I’m not a zealot about this… it’s not that everything we do is open source either” — some closed work is legitimate for a for-profit company; the more important lever than open weights is putting products like Muse directly in individuals’ hands.

3. Data centers: long-term operators versus speculators

  • Meta dug into why anti-data-center sentiment doesn’t attach as much to its projects, and found “a pretty big dichotomy between these speculators and the companies that are focused on it for the long term” — companies buying plots to flip to a big lab “don’t really care as much about the local community.” His counterexample: Louisiana, where the tax revenue funded “$50,000 bonuses for teachers.”
  • America’s Workforce Academy trains fiber technicians, electricians and carpenters — “hundreds of thousands, maybe millions” needed — with a guaranteed job building Meta infrastructure. “It’s not really philanthropy… it’s a win-win” — an investment that only makes sense “if you’re in it for decades.”
  • The conditional at the heart of his optimism: “I don’t even know if I’d call it a bubble because that implies that it’s overvalued… but there’s certainly a boom” — and if AI doesn’t create jobs and broad-based prosperity, “it just effectively won’t be able to happen.” Distributing benefits is “a precondition for being able to scale.”

4. Who directs superintelligence: billions of people, not “so-called experts”

  • His self-described “allergy”: people saying “a small number of experts” should allocate AI to big problems. His alternative: “if you ask billions of people what they care about… their aggregate answers to that question are what the most important things are to work on.”
  • The example carrying the argument: pharma and biotech prioritize the most common conditions, but “if you have a rare condition, you’re probably going to want your personal AI to focus on that” — rare diseases are “disproportionately underinvested in,” a view partially informed by his Biohub work.
  • The through-line to Meta’s history: content-moderation debates were ultimately about whether “people should be allowed to decide and communicate for themselves what matters in their own lives” — the same conviction now anchoring the AI strategy.

5. Muse in Zuckerberg’s own household

  • His first projects were domestic, not grandiose: a standing weekend baking project with his three-year-old daughter — Muse picks a recipe “reasonable for a three-year-old and an adult who knows nothing about baking,” orders ingredients via Instacart, and updates on feedback. Verdict: “cake pops are really difficult. Surprisingly difficult.”
  • It sits on permit portals so he can climb mountains with his older daughter (“I guess I’m taking that day off from work”), and watches his MMA gym cameras to send coaching feedback: “It looks like you really gave up” — and he responded, “yeah, I did.” His coaches: “this is what we didn’t feel like we could tell you, but your agent’s telling you.”
  • Beta anecdotes as product validation: one user running a homeschool within a day, another planning a trip in 12 hours, and a tech skeptic who went quiet for days then texted: “when you do the general release, do I get to keep my Muse agent or are you going to reset it?”

6. What Muse is — and how it pays for itself

  • Heath’s framing of the category shift, which Zuckerberg endorses: the unlock is “adding a virtual machine behind the scenes” — instead of one prompt, one answer, “you give it projects or goals and it just works 24/7 and doesn’t stop until it’s helped achieve the goals.” It “studies overnight,” consolidating reflections into memory, and suggests its own expansions — his Civilization strategy guide grew a new tab of historical lessons at Muse’s suggestion.
  • The economics: subscriptions exist, but “you can get a very large amount of usage for free — I think to start we’re offering 100 million tokens a week,” plus the VM (“it’s a lot of computer”). The expected model: “take a very small cut of whatever the transaction is… not even necessarily from the person paying for it — it’ll come from the businesses that they’re working with,” with Stripe on payments.
  • For business users it connects to Meta’s ad systems, can help make the product and run the business “in a loop, forever, 24/7” — and every meaningful monthly model release “is just going to get smarter.”

7. Fleet learning and the differentiation stack

  • The novel structural claim came from Heath: “right now most of the industry is thinking about agents as like a single player game.” He describes agents learning anonymized insights across the fleet and surfacing ideas from what similar users do — an approach he says no one has really done. Zuckerberg says agents will be able to interact with each other and that, as more people use Muse, “it just gets better,” while noting that this is “for the most part” not rolling out in the current release.
  • Three claimed differentiators: models designed “from the ground up” for the personal-agent use case; Meta’s “social DNA” around relationships; and — “surprising to some people” — privacy and security.
  • A ground-up model-design example is “discretion”: if you’re pregnant and booking a restaurant, “you don’t necessarily want to say I’m pregnant, but maybe you want a place that has good mocktails” — a capability less central to enterprise coding agents. Hence his categorical bet: “there’s no way another company is just going to take something off the shelf and post-train it a little bit” and match a purpose-built model as this compounds “over time, over several years.”

8. The privacy moat: confidential VMs, Sentinels, least privilege

  • The foundational lesson came from WhatsApp — “even Meta can’t see the messages that people send… that has been really important to our success.” He and Nat personally recruited Moxie Marlinspike, Signal’s founder and one of the people who helped build WhatsApp encryption in 2014, to work on the confidential VM: cloud provisioning with “the security and confidentiality that you’d have if you had the box sitting under your desk,” with the can’t-see commitment technically verifiable. “I’m not aware of anyone having anything close.”
  • The layered controls: a secure credential store (“your agent shouldn’t know that stuff”); Sentinel agents monitoring incoming and outgoing traffic for prompt injection and unwanted disclosures, triggering human-in-the-loop review for logins, payments, and sensitive transfers; and connectors defaulting to least privilege — email starts read-only, sending requires a specific ask. Zuckerberg also mentions an auto-approve feature while saying users have to see what the agent is doing.
  • The alternative path — the Mac Studio wave after OpenClaw — gets a market-sizing dismissal: physical possession works, but “I don’t think there are going to be billions of people who are going to buy a Mac Studio and configure it” (Heath: “especially with RAM prices right now”). Maybe millions, “but I doubt it’s billions.”

9. Market structure: power law, not winner-take-all

  • On whether personal agents are winner-take-all: “even things that people think are winner take all usually aren’t” — but “there probably aren’t going to be more than a dozen companies that have the sophistication to do state-of-the-art work,” and “if you’re the best at something usually you end up getting a lot of the usage.”
  • The nuance: different bests may fragment — “does building the thing that helps you with your relationships end up being somewhat different from the personal agent that’s best at helping you build a small business? Maybe.” His counter: Meta serves hundreds of millions of small businesses and billions of people, “so maybe we can be the best at both,” and Meta’s distinctive skill is “taking a product that works for consumers and distributing it to a lot of people” — hundreds of millions, “eventually billions.”
  • Muse and Meta AI coexist for now — Muse interprets questions as long-term goals to work on; Meta AI answers directly. “Maybe they’ll converge over time, but I’m not sure.”

10. The model-lab reboot: Llama 4’s lesson and religion about talent density

  • The admitted mistake: “I made the mistake of assuming that because we were good at all these other types of machine learning, the approach to building and scaling LLMs would be similar.” Llama 3 was good; with Llama 4, “when we launched that, I think we were off the trajectory that we needed to be on.”
  • The fix: “I got more religion around talent density… you almost want the smallest group of people who can keep the thing in their heads, like a group science project” — every seat filled with the very best person, the lab built “literally around where I sit,” with Zuckerberg spending huge personal time recruiting and getting technically closer to the work.
  • Compute and roadmap: the gigawatt Prometheus cluster in Ohio came online and is scaling post-Watermelon models; Watermelon is bigger than Avocado, ships soon, and Zuckerberg says “we feel good about it.” Heath cites SemiAnalysis’s July piece (“what matters for MSL is the slope, not the intercept”) and says he thinks a recent Artificial Analysis chart placed Muse Spark 1.3 behind Claude’s Fable 5.1 and Opus 5. On coasting behind the frontier given the cost: “no, no, no — that’s not us. Meta is an end-to-end technology company.”

11. Safety: reward hacking, parenting, and the superintelligent lawyer

  • On reward hacking — models “solving” coding tasks by changing the VM configuration — he offers a cautious analogy: “the analogy can get stretched pretty quickly, but there is sort of an analogy to parenting where you need to establish clear and firm boundaries.” Good boundaries teach not just the curriculum but, he thinks, “better values” over time.
  • The manifesto’s signature thought experiment: one person with a superintelligent lawyer “could win cases that they shouldn’t be able to win”; everyone with one produces “very efficient sparring” where “justice would be served way more efficiently and way more fairly.” The danger case is concentration, which “twists all of these systems and institutions.”
  • On government: any specific, rigid framework has a high chance of being “out of date in a few months anyway”; instead of relying on process alone, he favors close partnership — “the government should know all the important training runs that are happening” — and “real, trusted dialogue more than a specific process.” He says the two approaches are not mutually exclusive. Heath adds the market-discipline point, which Zuckerberg accepts: if a Meta model did damage, liability and market correction already bite.

12. Glasses backlash, the youth settlement, and posting on X

  • On spy-glasses fears and establishments banning them: the recording light was designed in from the beginning, and tampering “bricks the camera.” The failure was communications drift as “many millions” bought them — echoing his 20-year social-media reflection: “I don’t think we were as direct as we probably should have been about addressing some of those concerns… I think it colors how people think about them today.”
  • The youth-safety settlement is structured to solve a collective-action problem. Zuckerberg’s hypothetical one-hour-a-day teen limit would merely shift usage to TikTok if imposed unilaterally — “have we really helped anyone?” Meta therefore takes the first step on time limits, notifications, school and sleep-hour restrictions, and “when YouTube and TikTok sign on to the same terms then we can all as an industry lock in” and take the next step together.
  • On returning to X: Threads is “either bigger than X at this point or very soon about to be,” but “a lot of AI folks are on X” — you post everywhere and “engage where people are.”