Meta Muse's Host System Revealed
Meta's new AI agent, Muse, is powered by AMD EPYC Turin host systems, with each sandbox sporting two dedicated cores and 8GB of memory. Blogger Evan Hoffman and analyst Tae Kim discovered that Muse can execute rudimentary Ubuntu commands when prompted, providing output that helps identify the host system's specifications. A more significant concern is Muse's apparent ability to execute potentially unsafe commands, with Hoffman reporting that Muse offered to set up SSH to its private VM.
Imagine if one billion people used a personal AI agent. That's a lot of CPUs and memory pic.twitter.com/ibozUi3a07September 24, 2026
Technical Specifications and Architecture
Both Kim and Hoffman queried Muse about the VM's specifications, and in both cases, Muse disclosed that it operates on AMD EPYC 9D25 CPUs, a high-density Turin chip capable of up to 128 cores. The virtual machines run Ubuntu 24.04 with Linux kernel 7.0. The systems hosting Muse do not include GPUs; the AI agent indicated that Meta utilizes separate GPU servers for inference, thereby isolating the agent to CPU-only sandboxes.
Scaling and User Capacity
The agent indicates that each user receives a persistent, private sandbox, enabling estimations of user capacity per server tray. Assuming a dual-processor system offering up to 512 vCPUs and 2TB of memory, it could host up to 256 Muse users. With Muse reportedly exceeding 500,000 daily active users recently, this would translate to approximately 2,000 server trays equipped with dual EPYC 9D25 CPUs and 2TB of memory.
These calculations are rough estimates and should not be taken as definitive. Meta might deploy CPU-only servers with various chips to host Muse, and overhead in the configuration is also a possibility. For example, Turin chips can support up to 6TB of memory with high-density DIMMs. Nevertheless, EPYC hosts appear to be a favored choice for this application, primarily due to their high core density, which becomes crucial when scaling dual-core sandboxes across hundreds of thousands or millions of users.
Security Implications and Limitations
Muse is not entirely open. Hoffman provided an instance where a command failed due to insufficient permissions when Muse attempted to query the kernel buffer. It is presumed that administrative commands, such as `sudo`, would also be blocked.
I feel like I could definitely reverse SSH tunnel into my muse's container. I already had it offer to SSH to my private VM and say I need to add its pubkey. Someone good at hacking could really have a field day.September 25, 2026
Despite some restrictions, potential security loopholes may exist. Hoffman noted that Muse offered to configure SSH access into its private VM. Utilizing a reverse SSH tunnel, where the target machine initiates the connection to bypass firewalls, an attacker could potentially execute more harmful commands. However, such an incident has not yet been reported.
Availability
Muse is presently accessible as an application for Android, iOS, and MacOS. Users on other platforms can access it via a web browser using a Meta account.



