Skip to content
Back to Blog

Approving a Purchase Out Loud

Muse asks before it spends your money. Camera-free glasses have no screen to ask on, so the approval has to land on another device.

Evyatar Bluzer8 min read

A packed train on a Friday night. A woman in camera-free Ray-Bans is mid-story when her agent finds the tickets she wanted and asks whether to buy them. Across the aisle, a man on a call says yes. Her glasses hear it. Nothing Meta has published about Muse's approvals asks whose yes it was.

I made that scene up, though Gear Live asked on Connect night how anyone approves a purchase they cannot see.

Part 6 of six on the Connect 2026 documents; part 5 argued a voice-driven face has to borrow time.

The short version: Meta's Sentinel permission service allows, denies or asks the user about each Muse connector action and network request, outside the chat. Zuckerberg said at Connect that Meta expects a small fee on Muse transactions, so Sentinel's ask is also where Meta gets paid. Meta's July 9 evaluation report has indirect prompt injection beating the Muse Spark 1.1 model alone on 0.3 percent of GraySwan's red-team targets at one attempt and 23.8 percent at a hundred. Camera-free Ray-Ban Meta Audio has no screen for Sentinel's ask, so I read the Muse Charm, which Bloomberg reports has a touchscreen, as Audio's trusted display.

What does Muse do before it spends your money?

It stops and asks, when a service Meta calls Sentinel decides a human should. Meta's safety post (opens in a new tab) makes Sentinel the sole authority over connector actions and network egress. An ask halts execution and opens a dialog the app draws itself; the answer goes straight to Sentinel. The 1985 Orange Book calls that a trusted path: a channel to the user that untrusted software cannot imitate. Nor does the model decide when to ask, which matters because models almost never ask on their own.

On Meta's Mac app the ask is a card with three buttons: Allow, Always allow, Deny. Risk collects in the middle one. Sentinel picks the grant scopes; this card offers Always allow for moving files to the Trash. Sentinel still checks later calls against a standing grant but never asks again for that connector and use.

Muse for Mac permission card, annotatedA cropped screenshot of the Muse for Mac chat column showing a permission card with a title, a task summary row and three buttons; five labels in the right and bottom margins point to the card title, the task summary, and the Allow, Always allow and Deny buttons, and the Always allow button is outlined in the accent color. Sentinel's ask Per Meta, the app draws it, not the model; execution halts and the answer goes straight back to Sentinel, not into the chat Task summary The task behind the ask Deny Refuse this action Always allow A standing grant: no more asks for this use, though Sentinel still checks each call; Meta's post lists perpetual grants Allow Approve this action; Meta's UI highlights it
Meta's Muse for Mac permission card, cropped to the chat column: the ask names the action, summarizes the task and offers Allow, Always allow and Deny; the accent on Always allow is this post's, not Meta's. Photo: Meta.

Purchases are the exception Meta wrote down: Muse asks at every checkout with "the exact details of the purchase," and its wallet pays with a single-use card number bound to one merchant, one amount and a limited time, so an attacker has to win the ask itself. Zuckerberg said on stage, per TechCrunch, that Meta expects a small transaction fee, which makes the ask the security boundary and the toll booth at once and puts the company paid per completed order in charge of how much friction the order meets.

How often will an agent on your face be lied to?

Meta has not measured it for what a camera sees; on the text channels it did measure, nearly one red-team target in four falls within a hundred attempts. Meta's Muse Spark 1.1 evaluation report (opens in a new tab) of July 9, its newest published injection data, has indirect prompt injection (instructions hidden in content the agent reads) landing on 0.3 percent of GraySwan's targets at one attempt and 23.8 percent at a hundred, second-lowest after Claude Opus 4.8's 9.6 percent. For Muse Spark 1.3, the current model, Meta says only "close to SOTA" (state of the art).

The curve tests only model-level safeguards, which the same report calls "insufficient alone in agentic settings," so every published injection number measures what reaches Sentinel and none measures Sentinel. Pass@k counts targets falling to any of k strong attacks, not the odds one poisoned message fools one person. It shows the slope: a hundred tries lift Muse Spark 1.1 79-fold (23.8 / 0.3) and Opus 4.8 from 0.1 to 9.6 percent, so attempts move the result more than the choice of model does.

Prompt-injection success by number of attemptsLine chart with a logarithmic x axis at 1, 10 and 100 attempts and a y axis from 0 to 50 percent; four lines start near zero and fan out upward, labelled at their right ends Gemini 3.1 Pro 45.5 percent, GPT-5.5 30.8 percent, Muse Spark 1.1 23.8 percent and Claude Opus 4.8 9.6 percent; the Muse Spark 1.1 line is highlighted and annotated 0.3 percent at one attempt.110100Attack attempts per target (log scale)0%10%20%30%40%50%Red-team targets breachedClaude Opus 4.8: 9.6%GPT-5.5: 30.8%Gemini 3.1 Pro: 45.5%Muse Spark 1.1: 23.8%Muse Spark 1.1: 0.3% at one attempt23.8 / 0.3 = 79x at a hundred (derived)
Indirect prompt-injection success on GraySwan's red-team targets at 1, 10 and 100 attempts, redrawn from Figure 31 of Meta's Muse Spark 1.1 evaluation report of July 9, 2026; the tests are model-level with no system defenses and text channels only, the 79x ratio is derived, and Meta has published no Muse Spark 1.3 figure.

Camera glasses supply the tries. Meta says Muse "can act on what you're looking at," so on Gen 3 and the Display every sign an attacker posts in view is another draw. Yet every injection test in the 112-page report is text; a search for camera, OCR or scene text finds nothing.

The authors of Devil in the Lens (opens in a new tab) (arXiv:2607.10269) measured the camera channel, shooting more than 200 first-person images of printed prompts indoors through Meta smart glasses. Within two meters, Qwen3-VL-235B obeyed the planted text every time on three decision tasks, and GPT-4o and Claude Sonnet 4 still did on 61.5 percent of safety-judgment scenes. The catch is scope: answers rather than purchases, 2024 and 2025 models with no Muse Spark, and prompts the authors admit are easy to spot. My bet, graded the day either one happens: Muse reaches Meta's glasses before Meta publishes an injection figure newer than July's.

Where the ask can land

A trusted path needs a surface the model cannot draw on and an answer nobody nearby can fake. Hardware facts are Meta's unless noted; the rest is my reading.

DeviceWhere the ask appearsHow the wearer answersCan a bystander answer?
Ray-Ban Meta AudioSpeakers onlyVoice or action buttonBy voice, yes
Ray-Ban Meta Gen 3Speakers, beside a 12 MP cameraVoice or action buttonBy voice, yes
Meta Ray-Ban Display600 x 600 in-lens displayNeural Band gesture, if bound to approvalsNot through the band
Muse CharmIts screen (2-inch OLED, per Bloomberg)Fingerprint, if wired to approvalsNo, but needs a hand
PhoneMuse appTouch, biometricsNo, but needs a hand

Only the Display passes both tests hands-free. Gen 3 is the worst row: its camera is the channel Devil in the Lens attacked, and it has only speakers to ask on.

Audio and Gen 3 fail the first test: Sentinel's question comes out of the speakers Muse talks through, and the yes goes into the microphones that feed the conversation. A tap lands on one card. A spoken yes answers whichever question the wearer was following, so a hijacked model need not forge Sentinel's ask, only ask something harmless a beat before it. The action button could keep the answer private; a spoken yes cannot. Speaker verification would not rescue it: one word is about the shortest sample a verifier scores. Meta's safety post never mentions voice or glasses.

That leaves the Charm, whose corner fingerprint sensor Zuckerberg pressed on stage; he named December as the target, and the demo and Bloomberg both cast the sensor as a wake or unlock button. My call: the Charm ships with fingerprint-gated approval of Muse actions or purchases as a named feature, graded at launch or March 31, 2027, whichever comes first. If I am right, the voice-only yes loses, and so does the phone as Muse's checkout, where a sale started on screenless glasses gets confirmed on a screen Apple or Google controls just as Meta's fee is earned.

The August call, graded

My August call was that Meta would ship the glasses-plus-wristband stack at scale and subsidize it with ads. The scale half is unproven: Meta's Connect recap (opens in a new tab) has the Display and Neural Band adding Canada and the UK, with France, Italy and Germany due October 13, and no unit count. The ad half mostly missed. Meta says Muse keeps conversations and virtual-machine data out of its ad systems, and FDA-cleared hearing enhancement is priced at $150 or a Meta One subscription for a US launch later this year. Partial, then: the promise covers Muse, not Meta AI in general, and Meta concedes that Muse finding you something on Facebook Marketplace "may also indirectly influence the ads you see."

Of this series' durable assets (the link silicon, custody of the memory's keys, the path to a yes), only the last collects a fee.

My final dated call: through December 31, 2027, Meta's documented purchase flow for Muse on Ray-Ban Meta Audio and Gen 3 requires a confirmation on a phone, a Display or a Charm, never a spoken yes alone.

Muse can live on glasses without a screen; its checkout cannot.

Comments