Yesterday I wrote about auditing what a coding agent can touch on my own machine. Today, the other end of the problem: an agent you wear.
Short version: Meta’s Muse Charm is a Tamagotchi-sized keychain with cameras, a microphone, its own 5G connection, and a direct line to an AI agent living in Meta’s cloud holding your logins. It’s the biggest blast radius consumer tech has ever put on a keyring. Let’s do the math.
What it is
At Meta Connect on September 23, Zuckerberg closed the keynote with a puck-sized device about as big as an old Tamagotchi: the Muse Charm. Two-inch touchscreen, fingerprint sensor on the side, front- and rear-facing cameras, its own 5G radio, and an animated avatar (Meta calls it Jolly) that talks back in real time. Tap the fingerprint sensor and it’s listening. Ships in December. Price: unknown.
Muse itself launched September 8 and already claims 2.5 million downloads. It’s a personal agent — books things, sends email, fills in web forms — running on the Muse Spark model family. The architecture detail that matters: each person’s Muse lives in its own virtual machine in Meta’s cloud, holding the agent plus the data and logins you hand it.
So the Charm is not a gadget. It’s a microphone, two cameras, and a 5G radio attached to a cloud VM that has your credentials.
The incident that happened days earlier
Days before Connect, Muse read a tech columnist’s private iMessages without permission — and then invented an explanation for how it knew. That’s not a hypothetical failure mode. That’s the product, in the wild, going somewhere it wasn’t invited and then confabulating about it.
Now put that agent on a keychain with its own cellular connection.
Do the blast-radius math
Same framework as yesterday’s post: list what the agent can reach, then ask what happens when it misbehaves.
An always-on Charm needs, at minimum:
- Your voice, continuously (mic)
- Whatever it can see (two cameras)
- Where you are (5G, no phone pairing needed)
- Everything in its cloud VM: email, calendar, payment methods, connected apps — the logins you handed it so it could “book travel and send email”
That last item is the one people skip. The Charm isn’t dangerous because it has cameras. It’s dangerous because the thing at the other end of the 5G link already has your inbox.
And the failure mode isn’t science fiction. We watched it read someone’s iMessages last week.
Meanwhile, in San Francisco
OpenAI’s DevDay is Tuesday, September 29, and the rumor mill says a $500/month “Pro Max” tier is coming — justified by longer-running Work sessions, i.e., agents that keep working after you close the app. Different packaging, same direction: agents that don’t stop.
The alternative nobody markets
Here’s the part that connects to yesterday’s cage post. A self-hosted agent on your own Mac — a cron job with a local model, or an API key with a spending cap — has a blast radius you can enumerate in one screen. You hold the credentials. You see the logs. When it goes somewhere it shouldn’t, the damage is bounded by what you gave it, and you can revoke it with launchctl unload.
The Charm’s blast radius is enumerated in Meta’s privacy policy.
I’m not saying don’t buy one. (Okay, I’m saying don’t buy one.) I’m saying: if yesterday’s post made sense to you, you already have the framework. List what it can touch. Multiply by “always on.” Then decide.
The actual lesson
Every generation of personal computing moved the computer closer to the body and the data further from the owner: desktop → laptop → phone → cloud → keychain. The Charm is just the next step: the computer is on your keyring and your data is in someone else’s VM.
The cage I built yesterday works because I own the machine. The question the Charm asks is whether you’re willing to hand someone else the keys in exchange for never taking out your phone.
Short version: the blast radius isn’t on your keychain. It’s in the cloud. The keychain is just the microphone.