Meta Muse and Sentinel: A Technical Comparison of Meta's Public Disclosures with Earlier Execution-Finality Disclosures
Abstract
Author: Sangam Das Independent Inventor Motto Computation is not authority. What this is: An independent technical comparison, written by the author, of publicly reported facts about Meta's Muse/Sentinel architecture against the author's own earlier patent disclosures. What this is not: This is not a Meta publication, not an official Meta document, not endorsed or reviewed by Meta, and not a claim that Muse is DAS or that Sentinel is a Finality Sink. It is not an allegation of copying, derivation, or infringement. See §1 (Scope and Disclaimer) for the full list of things this paper does not assert. Abstract On 8 September 2026, Meta publicly introduced Muse, a personal AI agent designed to perform consequential tasks such as using applications, sending communications, browsing the web, and making purchases.[^1] Meta also disclosed a separate security component called Sentinel, described as the sole permission authority for connector actions and network egress. Muse may propose an action; Sentinel determines whether that action may proceed, must be denied, or requires user approval. Meta further described network-boundary enforcement, credential isolation, just-in-time credential insertion, and auditability.[^2] This development is technically relevant to execution-finality architecture that I had independently been developing, filing, and publishing before Meta's public Muse disclosure. Earlier filings include PCT/IB2026/053385, filed 7 April 2026, concerning hardware-enforced execution-time governance and capability withholding, and PCT/IB2026/055615, filed 4 June 2026, concerning the broader hardware-rooted execution-finality architecture ("the Mothership"). Those disclosures separate computation from authority, hold proposed consequential actions in a non-effective state, use protected enforcement domains, govern AI-agent actions and network egress, and require protected authorization before external effectuation. This paper does not claim that Meta copied, derived from, infringed, or was influenced by this work (see Scope and Disclaimer, §1). Instead, it documents a narrower and technically useful observation: Independent engineering efforts appear to be converging on the principle that the component which computes or proposes an AI action should not necessarily possess final authority to make that action externally effective. This convergence is relevant to the emerging engineering problem of consequential AI agents, and to future work on interoperable effectuation-boundary security. The documented filing record underlying this work extends to Indian provisional applications filed from December 2025 and January 2026, preceding Meta's September 2026 public disclosure; this chronology is presented only as evidence of independent development and should not be interpreted as an allegation of copying, derivation, or access by Meta or any researcher. Purpose of This Article The purpose of this article is to document and explain the technical relevance of Meta's publicly described Muse/Sentinel architecture to the broader problem of separating AI computation from authority to cause external effects. The article compares Meta's September 2026 public disclosures with earlier execution-finality work filed and published by the author, including PCT/IB2026/053385 and PCT/IB2026/055615 (WO 2026/150382), together with underlying Indian provisional filings dating from December 2025 and January 2026. The purpose is not to allege copying, derivation, infringement, or access to unpublished work (see §1 for the full disclaimer). Instead, the article records a narrower and more useful technical observation: independent engineering efforts appear to be converging on the need to separate the component that reasons, computes, or proposes an AI action from the component that holds authority to permit that action to become externally effective. The comparison is intended to: document the public technical chronology; identify areas of architectural convergence and difference; show the growing industry relevance of consequence-boundary control for agentic AI; respectfully note the direction the industry — including a company as significant as Meta — appears to be moving toward, and place that direction alongside earlier independent work on the same problem; clarify how execution-finality architecture extends beyond ordinary authorization, human approval, or software policy checks; and contribute to future discussion on interoperable, verifiable, fail-closed control of consequential AI actions. This article is intended to document technical convergence, not to assert technical identity, endorsement, copying, or legal infringement. 1. Scope and Disclaimer This is a technical comparison of publicly described architectures. It does not state or imply that: Meta copied any work of the author; Meta researchers had access to the author's unpublished materials; Muse or Sentinel was derived from the author's work; Meta has infringed any patent or patent application; Meta has endorsed, validated, evaluated, implemented, or licensed execution-finality architecture; the author has priority over any unpublished Meta invention or patent application; Meta lacks independently developed intellectual property; or similarity between the architectures establishes legal equivalence. Meta states publicly that work on Muse had been underway since early 2026.[^1] The date of Meta's public disclosure must therefore not be confused with its date of conception, development, invention, or any possible patent priority date. Statements in this paper about earlier patent applications are provided only to establish the author's documented technical chronology. Questions of patentability, anticipation, inventive step, claim scope, priority entitlement, validity, infringement, or freedom to operate depend on applicable law, the actual claims, effective filing dates, and the complete evidentiary record — none of which this paper attempts to resolve. The appropriate characterization is: independent technical convergence visible in the public record. 2. What Meta Disclosed Meta describes Muse as a personal AI agent capable of carrying out work rather than merely answering questions. Muse operates inside a dedicated "Muse Secure VM" and can interact with applications and websites to perform tasks such as sending email, completing forms, booking travel, and making purchases.[^2] The architecturally significant component is Sentinel. Meta states plainly: Muse proposes actions, but Sentinel controls whether those actions receive permission. Sentinel is characterized as the sole permission authority for connector actions and network egress.[^1] For connector actions, Sentinel evaluates the connector, requested method, action class, scope, and user context, and may allow, deny, or ask the user before permitting the action.[^1] Meta extends this to network traffic as well: every concrete network request from the Muse runtime is governed at egress. Sentinel can examine destination hostname, resolved IP address, port, protocol, HTTP method, path, and decoded request content.[^1] This matters because the security decision is not confined to model reasoning — it is tied to the point at which a proposed action reaches an external boundary. 3. Credentials Separated from the Reasoning Agent Meta has separated sensitive credentials from Muse itself. The architecture includes credential-storage and privilege-separated components; Muse does not receive unrestricted visibility into the user's passwords or payment credentials. Surrogate credentials are used inside the runtime, with real credentials inserted only after a concrete network request has been authorized at the boundary.[^2] The underlying security principle: being able to reason about or request an external action does not automatically mean possessing every secret or authority necessary to complete that action. This is closely related to capability-withholding approaches, though the implementation and terminology differ. 4. Earlier Indian Provisional Filing Record The technical development described in this publication did not begin with the April or June 2026 PCT filings. The associated patent record includes a series of Indian provisional patent applications dating back to December 2025 and January 2026. For example, the April 2026 international application expressly identifies underlying provisional filings including: 20 December 2025 — Indian Provisional Patent Application No. 202531129538 22 December 2025 — No. 202531130168 23 December 2025 — No. 202531130665 3 January 2026 — No. 202631000572 7 January 2026 — No. 202631001586 12 January 2026 — No. 202631002990 22 January 2026 — No. 202631006616 26 January 2026 — No. 202631007467 These filings concern, among other subjects, cryptographic execution-time enforcement, separation of computation from execution authority, fail-closed control of outputs, purpose- and jurisdiction-bound authorization, commit-time and irreversible-boundary enforcement, hardware-rooted capability withholding, and execution-finality architecture.[^3] [These provisional numbers are drawn from the author's own filing record and priority claims; readers cross-checking claim support should refer to the specification of PCT/IB2026/053385 directly, which lists the underlying provisionals it claims priority from.] Accordingly, the relevant technical record extends back to December 2025 and January 2026, well before the public disclosure of Meta Muse and Sentinel in September 2026. This chronology is provided solely to document the development and filing history of the author's work. It does not imply that Meta, its researchers, or any other party had knowledge of, access to, copied from, derived from, or were influenced by these earlier filings. Meta's internal research timeline, unpublished work, and any confidential patent fi