Zuckerberg’s Next AI Bet: Teaching Muse When to Keep Quiet

A personal AI agent can know something about you without having permission to share it. Zuckerberg says teaching Muse that distinction is a core capability—and a requirement for earning users’ trust.

Written By
Corey Noles
Corey Noles
Sep 30, 2026
6 minute read

An AI assistant books you a restaurant. It finds a table, checks the menu, and handles the reservation.

Then it tells the restaurant something about your health that you never intended to share.

The booking worked. The assistant failed.

That’s the problem Mark Zuckerberg keeps returning to in his interview with Jacklyn Dallas on The Next Big Thing. As Meta builds Muse into a personal agent that can take action across your life, he argues that it needs to learn a surprisingly human skill: discretion.

An assistant might need to know something about you to make a good decision. It also needs to understand how much of that information belongs in the next conversation.

“You have to train that into the model,” Zuckerberg said. “I mean, just like any other capability.”

That’s a useful way to think about the next phase of personal AI. We’re asking these systems to remember more, work independently, and interact with other people and services. Each capability creates more opportunities to get something done—and more opportunities to overshare along the way.

Coding skills only get an agent so far

Zuckerberg’s explanation starts with the rise of coding agents. He separates two capabilities that often get bundled together: expertise at writing software and the ability to operate effectively as an agent.

Muse needs both. Even when someone asks it to handle an everyday task, code may be part of how it completes the job.

“Your muse is writing code for you to do all this stuff in the background all the time,” he said.

But representing a person introduces another set of demands. At roughly six minutes into the interview, Zuckerberg argues that discretion hasn’t been central to how companies have trained coding agents.

“Most of these companies haven’t trained that in,” he said.

That’s Zuckerberg’s assessment of competitors, rather than an established finding about every coding product. Coding agents also need to protect credentials, private files, and confidential business information. The distinction he’s drawing is about the social judgment required when an assistant carries personal knowledge into interactions on your behalf.

A personal agent could know why you’re booking a trip, what you’re worried about, and which details you’ve shared privately. It has to decide what a hotel, restaurant, colleague, or merchant needs to hear.

Advertisement

Being able to complete the transaction is only part of the job.

The restaurant doesn’t need your whole story

Zuckerberg’s example is straightforward: you want a restaurant reservation, and Muse knows about an allergy or a pregnancy that affects your preferences.

You want a suitable restaurant. You may also want to keep the underlying information private.

The assistant should complete the task “while disclosing as little information as possible,” he said.

“So that’s a specific skill,” Zuckerberg added, describing it as “basic social skills or common sense that people have.”

The right amount of disclosure will depend on the situation. A serious allergy may require an explicit conversation with the restaurant. A preference for a particular menu may require no explanation at all. An assistant needs to recognize the difference—and ask when the boundary is unclear.

That makes discretion harder than a blanket instruction to keep secrets. The system has to use private context without automatically passing it along.

A human assistant would be expected to understand that telling them something doesn’t authorize them to tell everyone else. Personal AI will face the same expectation.

Meta says it is teaching discretion from the start

Zuckerberg presents this as a reason for Meta to develop the underlying model and the agent together.

“We’re training the model,” he said. “We’re not just taking someone else’s model off the shelf and trying to build a scaffold and an agent around it.”

“We trained the whole model specifically to be good at that.”

His argument is that discretion should influence how the model learns to act, alongside the memory, tools, and other systems surrounding it.

Later in the interview, he says Meta spent additional time improving that behavior before releasing Muse.

“We thought that we could train in some more behavior around discretion like we talked about,” he said. “So, we took the time to do that.”

The company also worked on the security of the computer provided to each agent.

“So, we took a few extra months to do that,” Zuckerberg said.

He doesn’t provide a detailed training curriculum or an independent measure of Muse’s discretion in this interview. Those remain important questions. But he does make the product priority clear: an assistant needs judgment about the information it uses to pursue your goals.

Advertisement

Privacy also needs something sturdier than good manners

Discretion inside the model is one part of Zuckerberg’s answer. The surrounding system needs to limit access and intervene when necessary, too.

He describes Muse as working inside its own virtual machine—a separate cloud computer—with a credential store designed to let it log into services without seeing raw passwords.

A separate security agent, Sentinel, monitors information moving in and out and can require user permission for an action.

“If it thinks that your muse is going to take an action … that you should be in the loop on,” Zuckerberg said, it can “override your muse” and return the decision to the person.

He also describes a confidential virtual machine intended to prevent Meta from accessing its contents. In the interview, that version is still being developed.

These protections address different parts of the problem. Restricting access to credentials can reduce what an agent might expose. Requiring permission can stop a questionable action. Discretion helps the agent recognize that a disclosure is questionable in the first place.

An assistant has to understand what you meant

Near the end of the conversation, Zuckerberg connects discretion to alignment: getting an AI system to act in ways consistent with a user’s intentions and values.

The products need to understand “not only … specifically what you asked but the intent behind it and your values,” he said.

That’s where a simple request becomes complicated. “Book dinner” carries plenty of unstated expectations about budget, privacy, timing, and whose information the assistant can share.

Zuckerberg argues that companies have a commercial reason to improve this. People won’t keep using an assistant that acts against their wishes.

That incentive makes sense. It still leaves users needing evidence that an agent handles those boundaries reliably.

As we covered in Meta’s Big AI Bet Now Fits on Your Keychain, Meta wants Muse to move through more of everyday life, including dedicated hardware and AI glasses. More context could make it more helpful. It could also give it more sensitive information to manage.

Advertisement

And with Meta pursuing an enterprise business around its growing AI stack, the same question extends into work: can an agent use what it knows without sharing more than it should?

Discretion deserves to become something we test directly. Give an assistant private context, ask it to complete a task involving someone else, and inspect what it actually says. Did it share only what was necessary? Did it ask before revealing something sensitive?

A reservation confirmation can prove that an agent finished the job. The message it sent to get that reservation may tell you whether you’ll trust it with the next one.


Corey Noles

Corey Noles is the Host of The Neuron: AI Explained podcast and Managing Editor of AI and Experimental Content at TechnologyAdvice, where he leads the charge in testing and refining emerging content strategies across the company's portfolio.

The Neuron Logo

Don't fall behind on AI. Get the AI trends & tools you need to know. Join 700,000+ professionals from top companies like Microsoft, Apple, Salesforce and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

Stay in the loop

Get notified when we publish new articles.