Meta CEO Mark Zuckerberg at a dinner with tech leaders in the State Dining Room of the White House in Washington, Sept. 4, 2025. Credit: FotoField / Shutterstock.com “I personally am much more worried about a small number of labs or people having control of something that is so capable.” That was Mark Zuckerberg, speaking to Alex Heath on the Sources podcast, published on Wednesday. Heath recorded the interview at Meta’s headquarters the previous Friday, days before Meta launched Muse, its personal AI agent. Zuckerberg argued that AI is safest when many people hold it.
He also aimed a pointed line at his rivals. Some labs, he said, are “training more advanced models, and then not even releasing them.” He called that “quite dangerous.” He named no company, though Heath’s follow-up question cited Anthropic and OpenAI. Wide access, but not all of it open Zuckerberg set out three principles from his recent essay. Empowering people drives prosperity.
AI is mainly for inventing new things, not automating old ones. Safety comes from checks and balances rather than restricted access. He applied the last one to cybersecurity. If one AI can hack systems, he argued, the answer is giving everyone an AI to harden their own.
He was also careful not to overclaim. Meta releases some open models and does some closed work, he said. “It’s not that everything we do is open source either,” he added. That matters. Meta shipped Muse Spark, the first model from its new lab, as a closed-source model in April.
The distribution he now champions arrives through a Meta product, not through downloadable weights. What Muse does, in his telling Muse runs on its own virtual machine, works on goals rather than single prompts, and keeps going around the clock. Zuckerberg described what he set his own agent to do. It plans a weekly baking project for his three-year-old daughter and orders the ingredients.
One attempt went badly. “Turns out cake pops, really difficult, surprisingly difficult,” he said. It also watches for mountain permits for his older daughter, and it reviews camera footage from his MMA gym. Its feedback is not always flattering. On one clip, it told him “it looks like you really gave up,” he said.
The coaches laugh about it. For Zuckerberg, Muse is about these everyday uses, not a side show. People should decide what their AI works on, he argued, not “so-called experts sitting at a small number of labs.” The agent also suggests new projects itself. Many people, he said, still do not know what to ask AI to do.
A privacy promise Meta has not yet shown The claim that will decide whether people connect their email and messages is about privacy. Zuckerberg said he and Nat Friedman personally recruited Moxie Marlinspike, the founder of Signal. His job is a confidential virtual machine for Muse. The aim, he said, is a commitment that “even Meta cannot see the content that is in there.” He said he is not aware of anyone offering anything close.
He added that Meta will publish more about the system in the coming weeks, ahead of a wider rollout. Until Meta publishes that detail, nobody outside the company can check the claim. He described other safeguards. A secure credential store keeps passwords and card details away from the agent itself.
Separate sentinel agents watch traffic for prompt injection and trigger a human review before logins, payments or sensitive transfers. Connectors start with the least privilege, so email begins read-only. Free, and meant to pay for itself Zuckerberg said Muse starts with roughly 100 million tokens a week for free, plus the virtual machine, with a paid subscription for heavier users. His hedged wording suggests the number may move.
The bet, he said, is that “this thing is actually going to make you money and save you money.” Sources reported that he plans for Meta to eventually “take a very small cut of whatever the transaction is.” That pitch is a long way from the reported $199.99 tier for the agent in August. Business owners can also connect Muse to Meta’s ad systems, which gives the company an obvious route to recover the compute it is giving away. Llama 4, and the watermelon Zuckerberg was blunt about Meta’s last model generation. He said he wrongly assumed that scaling large language models would resemble Meta’s other machine learning work.
Of Llama 4, he said: “When we launched that, I think we were off the trajectory that we needed to be on.” His fix was talent density: a small team that can hold the whole project in their heads, built literally around where he sits. Meta’s Prometheus cluster in Ohio is now training the models after Watermelon, the codename for its next large model. He said Watermelon ships soon and called it “a significantly more advanced pre-train.” Asked whether it reaches the frontier, he would not commit. Glasses, teens and data centres Heath pressed him on smart glasses, which venues from cinemas to schools are now banning.
Zuckerberg defended the recording light. “If you try to mess with the light, we should basically brick the camera on your device,” he said. He conceded that Meta stopped explaining those safeguards as sales grew. “I think we let up on that a little bit,” he said. On the youth safety settlement, he said Meta limits teen usage first and wants YouTube and TikTok to sign the same terms. Otherwise, he argued, restricting Instagram just sends teenagers to rivals.
He blamed the backlash against data centres partly on speculators, who secure a site only to sell it on to a big lab. Meta, he argued, commits to a community for decades. He cited a Louisiana example where, he said, local tax revenue funded $50,000 bonuses for teachers. The tests are close.
Meta says it will publish more on the confidential VM within weeks, and Watermelon is due soon. Whether YouTube and TikTok accept Meta’s terms will show if going first sets a standard or just costs Instagram users.












Leave a Reply