Back to all posts

cat posts/muse-and-the-eu-no-launch-date-no-dpa-and-your-options.md --category "Security & Compliance" --views 17

Muse and the EU: no launch date, no DPA, and your options

Meta Muse runs in the US and Canada only, the Meta Model API behind it ships with no data processing agreement and no EU residency, and the Confidential VM promised for later this year does not settle who the GDPR controller is. What GDPR, the AI Act, the DMA and the June WhatsApp interim measures mean for a European launch, and the self-hosted Muse Glimmer route a Swedish team can run in Azure Sweden Central today, with the GPU cost math.

  • --author By Falak Mahmood
  • --date September 28, 2026
  • --read 15 min read
  • --views 17 views

Meta's Muse is twenty days old, has passed 2.8 million installs according to Apptopia figures reported by TechCrunch, and cannot be installed in Sweden. Meta's Help Center says only that Muse and its subscriptions "are in a limited testing phase and are not yet available in all locations." The app reached Canada on 18 September. No European country is on the list, and Meta has given no date. For a Swedish IT or compliance team, that leaves four questions: when Muse might arrive, under which terms the models behind it can be used today, what the promised Confidential VM changes under GDPR, and what to do in the meantime. The last one has a concrete answer, with a GPU price attached.

Diagram of Meta's Muse system architecture: user controls on the left, an isolated runtime cell in the middle, host-side safety and credential services and the Sentinel agent below, and connections to external services on the right
Meta's published Muse architecture: the isolated runtime cell, the host-side credential daemon, and the Sentinel that approves every outbound call. The Confidential VM promised for later this year would encrypt the whole machine with a key only the user holds. Image: Meta AI Research.

Part 4 of 4 on Meta Muse. Part 1 covered what Muse is and how the Secure VM and Sentinel work. Part 2 compared Muse connectors with MCP. Part 3 put Muse next to Hermes Agent and OpenClaw. Today: the EU gap, the legal reasons it exists, and the self-hosted route that is open now.

Where each piece of Muse actually is

Muse is four products sharing a name, and their European status differs. The consumer agent is the one in the headlines. Behind it sit the Muse Spark model family, the Meta Model API that sells those models to developers, and Muse Glimmer, the 30-billion-parameter open-weights model Meta released in August. Only the last one can be used in the EU today on terms a Swedish data protection officer would sign.

Product EU availability, 28 September 2026 Data terms
Muse app (iOS, Android, muse.ai, WhatsApp, Mac)US since 8 September, Canada since 18 September. "Limited testing", no EU date.Consumer terms. Training opt-out in settings. Conversations kept out of ad systems, per Meta.
Muse Spark 1.3 via Meta Model API"Public preview. Now available with expanded global access." No country list published.Standard tier: $1.25 input / $4.25 output per million tokens, "not used to improve our products". Contributor tier: $0.10 / $0.20, "used to improve our products". No data processing agreement, no EU residency option, no enterprise tier.
Muse Code (coding agent)Same API, same silence on countries.Same terms; your source code goes to Meta's endpoint.
Muse Glimmer 30BWeights on Hugging Face since 10 August. No geographic clause.Apache 2.0. Runs on your hardware; no data leaves.

The middle rows matter more than the first. A Swedish developer can sign up for the Meta Model API right now and send it customer data, and nothing on the pricing page stops them. The terms link goes to Meta's general policy centre, not to a developer DPA. The innfactory availability tracker, which has followed Meta's model terms since the Llama era, summarised it on 20 September: no GDPR commitments, no data processing agreement, no EU residency. That combination means the API can be used for public or synthetic data and for nothing that falls under Article 28 of the GDPR.

Meta has been here before. Meta AI, the chat assistant, launched in the US in September 2023 and reached Europe on 19 March 2025, in 41 countries but as a text chat in six languages. Meta's own newsroom wrote that it had "taken longer than we would have liked to get our AI technology into the hands of people in Europe as we continue to navigate its complex regulatory system." Eighteen months for a chatbot with no memory and no credentials. Muse holds your inbox, a bank connection through Plaid, and a virtual card. Expect the gap to be longer, not shorter.

Four laws, four separate problems

"Regulation" is the lazy explanation for the delay. The specific obstacles are more useful, because each one tells you what a European Muse would have to look like.

GDPR: the legal basis for the memory. Muse's value is that it remembers you, and Meta's security post says the interaction data, which it calls trajectories, is "sanitized to remove key personally identifiable information" and then used to train models unless you opt out. That is the same opt-out model Meta used when it started training on EU adults' public posts and Meta AI interactions on 27 May 2025, relying on legitimate interest after the European Data Protection Board's December 2024 opinion. The privacy group noyb filed complaints in eleven countries against that approach. For Muse the data is not public posts. It is your email, calendar, purchases and health apps, and the special categories in Article 9 do not accept legitimate interest as a basis. A European Muse would need explicit consent per data category, or no training at all, and the Secure VM's current policy language would not survive contact with a supervisory authority: the same Meta post says the isolation "does not prevent Meta from accessing data when necessary to support, secure or operate the service."

AI Act: a model with no Code of Practice signature. Muse Spark is a general-purpose AI model, and Chapter V obligations for such models have applied since 2 August 2025, with the Commission's enforcement powers active since 2 August 2026. Meta was the only one of the large model developers to refuse the voluntary GPAI Code of Practice outright. Joel Kaplan announced it on 18 July 2025: "Europe is heading down the wrong path on AI." Refusing is legal. What it costs is the presumption of conformity that signatories get. Meta would have to demonstrate compliance on training-data summaries, copyright policy and systemic-risk measures by its own evidence, for a model family it has already declined to open. Article 50 adds a smaller but immediate item: any agent that emails a person from its own address, as Muse can since Connect, must disclose that it is an AI system. That obligation has applied since 2 August 2026 and it binds Swedish operators of any agent, not only Meta.

DMA: the data combination Muse is built on. Meta is a designated gatekeeper for Facebook, Instagram, WhatsApp, Messenger and Marketplace, and Article 5(2) of the Digital Markets Act bans combining personal data across those services without consent. Muse's flagship demo turns an Instagram recipe reel into a WhatsApp grocery list and a purchase. In the US that is a feature. In the EU it is a consent flow that has to survive the same scrutiny that earned Meta a 200 million euro fine over pay-or-consent in April 2025. The Commission's first DMA review, published on 28 April 2026, said it "will in particular further assess whether some AI services need to potentially be designated as virtual assistants," which is the category Muse fits. A designation would bring interoperability and data-portability duties that Muse's closed connector directory does not yet meet.

Competition law: WhatsApp is no longer Muse's private channel. In the US, Muse lives inside WhatsApp and rival agents do not, because Meta banned third-party general-purpose AI assistants from the WhatsApp Business API on 15 October 2025. The Commission sent a statement of objections in February, rejected Meta's March revision that readmitted rivals for a fee, and on 9 June 2026 imposed interim measures ordering Meta to restore free access on the pre-October terms until a final decision. A European Muse would therefore share WhatsApp with ChatGPT, Copilot and any Swedish startup's agent, on equal terms. That removes the distribution advantage that made Muse the number one free iOS app in the US within ten days, and it is a fair guess that Meta would rather delay than launch into that.

The Confidential VM promise, read against GDPR

Meta's answer to the trust question is the Muse Confidential VM. The launch post promises it "later this year": the whole VM, "including a person's data and conversations with Muse, is encrypted with a key only they hold, so not even Meta can access it." The security post adds that a small group of trusted testers already runs on it, that the design and source code are being shared with external auditors, and that Meta intends a "continuous audit of the system that will be visible to and inspectable by anyone." Press coverage credits Signal's creator Moxie Marlinspike with co-designing it. It is a serious piece of engineering and deserves to be taken at face value.

It does not, on its own, make Muse lawful in Europe. Three gaps stay open.

  • Encryption at rest is not the whole pipeline. The model inside the VM has to read your data in plaintext to act on it, and every connector call sends part of that data to a third party: Stripe, Instacart, Expedia, your bank via Plaid. A user-held key protects the disk and Meta's own staff. It says nothing about the 1,500-plus developers who applied to build connectors in the first week, or about the custom connectors that Meta's Help Center says it does not review.
  • The controller does not change. Whoever holds the key, Meta designs the processing, chooses the sub-processors and decides what the model is trained on. Under GDPR that makes Meta the controller, with the duties that follow: a legal basis per purpose, a records-of-processing entry, and a transfer mechanism for any data that leaves the EEA. A trusted execution environment is a security measure under Article 32. It is not an exemption from Article 6.
  • Trusted testers are not a launch. The Secure VM everyone has today is governed by operational policy. The cryptographic version is a promise with a 2026 date and no country attached. Until it ships and the promised public audit exists, a European regulator would assess the product that exists, not the one announced.

For an employer the sharper point is different. If Muse does launch in Sweden and an employee connects a work mailbox, the Confidential VM protects that employee against Meta. It does nothing for you. Your company data sits in a consumer VM under a consumer contract, encrypted with a key held by a person who may leave next month. That is the scenario to write into the acceptable-use policy now, while the product is still geo-blocked and the conversation is easy.

The EU path that exists today: Muse Glimmer on your own GPU

Meta released Muse Glimmer on 10 August 2026 under Apache 2.0, its first open-weights model since the Muse Spark family went proprietary in April. The model card lists roughly 29.6 billion parameters including a vision encoder, a context window of 131,072 tokens, training data in more than 100 languages, and a design "trained end-to-end around the agent loop" for tool calling, long tasks and coding harnesses. Meta's own guidance on hardware: 64 GB of GPU memory at full precision, 32 GB with the K-Quant build, and 24 GB with the K-Quant-17GB build. There is no EU exclusion clause of the kind Meta put on Llama 4's multimodal models. The acceptable-use policy asks deployers in agentic settings to add "human-in-the-loop confirmation for irreversible actions," which is the Sentinel pattern from the Muse app, left for you to build.

Glimmer is not in the Microsoft Foundry model catalogue as of this morning, so on Azure it is a bring-your-own model: vLLM or llama.cpp on a GPU virtual machine, or a custom registration on Foundry managed compute. The retail prices below are pay-as-you-go Linux rates in Sweden Central from the Azure retail price API on 28 September 2026, before reservations. A month is 730 hours.

Option GPU memory Glimmer build that fits Hourly Always-on month
NV36ads A10 v5, pay-as-you-go24 GB (one A10)K-Quant-17GB$4.16$3,037
NC24ads A100 v4, pay-as-you-go80 GB (one A100)Full precision, room for a 131k context$4.775$3,486
NC24ads A100 v4, Spot80 GBFull precision; eviction possible$1.17$855
NV36ads A10 v5, Spot24 GBK-Quant-17GB; eviction possible$0.77$561
One workstation with a 24 GB or 32 GB card, on-premises24 to 32 GBK-Quant or K-Quant-17GBOne-off purchaseElectricity
Muse Max, for comparisonMeta'sMuse Spark, 3 billion tokens a weekn/a$100 per person, not available in the EU

Two things stand out. The A100 costs 15 percent more per hour than the A10 in Sweden Central and gives you more than three times the memory, so the A10 only wins if you commit to the smallest quantised build. And the pay-as-you-go month is thirty Muse Max subscriptions, which sounds absurd until you count what the box serves: one Glimmer endpoint on an A100 can back a team's OpenClaw or Hermes instances, an internal document agent and a coding assistant at once, with every token staying in Sweden Central under your tenant. Spot capacity or a one-year reservation cuts the bill further, and a single on-premises workstation removes it. Muse Max is a per-person consumer price for a service you cannot buy here anyway.

What Glimmer does not give you is Muse. The app's value is the connector directory, the payment rails and the Sentinel, none of which are open. Pair Glimmer with the self-hosted runtime from Part 3, OpenClaw behind Entra with sandboxing on, and you have the shape of a European Muse: a persistent agent, memory, tools and a model, all inside your own subscription. It will be less polished. It will also be yours to audit, which is the thing Meta is still promising.

The Swedish and EU angle: five decisions

  • Employees asking for Muse. There is nothing to block yet, so use the time. Add personal agents to the acceptable-use policy by name, state that work mailboxes and Teams accounts may not be connected to consumer agents, and say who can grant an exception. When Muse does reach Sweden, the policy exists before the App Store listing does.
  • Developers on the Meta Model API. Treat the standard tier as a public-data endpoint until Meta publishes a DPA and a residency option. Never use the contributor tier with client data; its whole price advantage is that your prompts train Meta's models. If Muse Spark's capability is what you need, route personal data to a Foundry model in Sweden Central instead and keep Meta's endpoint for the parts that hold nothing personal.
  • Retailers and merchants. A US Muse user can already buy from a Swedish web shop through PayPal, which says its connector works for merchants worldwide, or through the browser fallback. Nothing in your shop needs changing for that. What you should not do is build against Meta's connector directory for a European customer base that cannot install the app.
  • Teams that want a personal agent this quarter. Self-host. Glimmer on an A100 Spot instance or a workstation, OpenClaw or Hermes as the runtime, Entra in front, and the Article 50 disclosure line in every mailbox the agent can send from. Budget one engineer for two weeks and the GPU bill above.
  • Regulated organisations. Wait for three documents before Muse enters any assessment: a Meta DPA for the model API, the Confidential VM's public audit, and an EU launch announcement with a data residency statement. None exists today. Meanwhile the Article 30 record for any self-hosted agent is a page long and you control every line of it.

If you want help standing up the self-hosted version, that is what our on-premises and sovereign AI and Azure AI integration services are for, and for organisations on Microsoft 365 the Copilot readiness work covers the governance side before Copilot Autopilot's preview arrives.

What to do this quarter

  • Write the personal-agent clause into the acceptable-use policy this week, naming Muse, Hermes Agent and OpenClaw.
  • Audit outbound calls to Meta's model endpoints from your codebase and CI. Anything sending personal data to the Meta Model API needs a different route until a DPA exists.
  • Run Glimmer for a week on Spot capacity in Sweden Central against your own agent tasks and record the token throughput. That number decides whether the A10, the A100 or a workstation is the right home.
  • Add the AI disclosure to any agent-operated mailbox. It has applied since 2 August 2026.
  • Set a watch on three sources: Meta's Help Center availability page, the Commission's virtual-assistant assessment under the DMA, and the Confidential VM audit. Any one of them changing is the trigger to reopen this question.

Zuckerberg told Connect he expects Muse to become "the personal superintelligence that billions of people around the world are going to use." Four hundred and fifty million of those people live in the EU, and for now the most useful thing Meta has shipped them is a 30-billion-parameter model under a licence that lets them build the agent themselves.

subscribe # the AI news that matters, minus the noise

Book a Call

Sources

Tags

Related posts