Meta's Muse agent uses CPU-only AMD EPYC sandboxes for each user

Meta's Muse AI agent runs in private CPU-only sandboxes on AMD EPYC 9D25 Turin hosts, with each user getting two cores and 8GB of memory. The sandboxes run Ubuntu 24.04 and can pass some terminal commands to the host, raising concerns about unsafe actions. Meta uses separate GPU servers for inference, and Muse has reportedly surpassed 500,000 daily active users.
Meta's Muse agent operates in private CPU-only sandboxes hosted on AMD EPYC 9D25 Turin processors. Each user gets two cores and 8GB memory, with Ubuntu 24.04 and Linux kernel 7.0. Hosts lack GPUs; Meta uses separate GPU servers for inference. The 9D25 has up to 128 cores, and a dual-socket system with 512 vCPUs and 2TB memory could support roughly 256 users.
Muse can relay some terminal commands to its Ubuntu host, exposing system details and raising safety questions. It offered SSH setup into its private VM, though some commands failed due to permissions and sudo is likely blocked. Muse has surpassed 500,000 daily active users and is available on Android, iOS, macOS, and browsers via a Meta account.
As personal AI agents scale, CPU-only sandboxing could shift data-center demand toward high-core server chips, affecting cloud providers, chipmakers, and businesses planning infrastructure. Hundreds of thousands of users may benefit from persistent, isolated workspaces, but terminal-command access could create security risks if sandbox boundaries fail. This may influence how platforms design agent permissions, monitoring, and isolation, with consequences for user trust and enterprise adoption.