AI NewsModels & agentsReported
Meta says Muse is meant to give each user a Linux computer in the cloud
Meta says Muse is designed to hand every user a persistent Linux virtual machine, and asking Muse to zip up its whole filesystem is now a one-click action.

Image: The Verge
Why it mattersA developer picking an AI chatbot to prototype in can install software, compile code and open a browser inside a Meta-hosted Linux box that keeps state between sessions, and ChatGPT and Gemini do not offer this.
Every Muse user has their own Linux computer running in the cloud, and Meta says that is on purpose. The Verge reports that the chatbot will now zip its whole filesystem and hand it to you when you ask, and that Meta calls this the intended way to use the product.
The story ran on 25 September. On Wednesday, developers Peter James and Jonny L. Saunders had coaxed Muse into sharing its filesystem, and the chatbot itself told them it was not supposed to. On Thursday, Meta's Nat Friedman said on X that this is the "intended behavior". David Singleton of Meta Superintelligence Labs added: "Your Muse Secure VM truly is your own computer in the cloud. You can install software in it, write and compile code, use the browser to surf the web: it is your own Linux box that you can operate as you choose with your Muse."
What changed between one day and the next
On the first day, The Verge writes, Muse "merely offered a text file download that showed its directory tree" and refused a full copy of the root directory, "citing security concerns". On the second day, the same request pulled up a clickable file browser rooted at /, and asking for a zip returned "the full filesystem listings, all with secrets stripped out".
Meta spokesperson Daniel Roberts told The Verge: "We're continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine."
The whole environment is what you get
The Verge compares the design for readers who use several chatbots side by side: Muse "is closer to running OpenClaw on a local machine, except the machine is in the cloud." ChatGPT and Gemini give the user tools like Python and a browser, and they keep the environment hidden. In Muse, the environment is what you use.
For a developer picking a chatbot to prototype in, that is a real difference. You can keep files across sessions, install a package once and use it later, and run a small server behind the chatbot's browser. The Verge says the model still refused some requests earlier in the week citing security, and asked Meta why filesystem access was called a security issue if it was always intended. Meta had not answered by press time.
The Verge also writes that Muse, like other AI systems, "is not fully reliable at knowing what it can and can't do." So a refusal from the model is a sign of what the model thinks, and Meta's real policy may say something different. That is worth knowing before you build a workflow around a request the model happens to refuse today.
Source
- Meta makes the Muse filesystem even more accessible, The Verge, 25 September 2026, quoting Nat Friedman and David Singleton on X and Meta spokesperson Daniel Roberts.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.


