Moving from rigid prompt engineering to goal-oriented agentic workflows changes the fundamental nature of security operations. We are finally shifting the burden of execution away from the analyst, allowing the machine to navigate intent rather than syntax. This transition mirrors the reality that internal decision chains in automated systems will remain opaque by design. Trying to force an audit trail for every micro-decision inside a high-speed agent is a distraction from the actual outcome. We should focus on the integrity of the goal itself instead of the black box mechanics of how the agent reaches it. Trusting the output requires a shift in how we validate performance at scale.
Worth separating what shipped from what was announced. Meta's 8 September newsroom post describes Muse running on Muse Secure VM today, and says Muse Confidential VM, the version encrypted with a key only the person holds so Meta cannot access it, arrives later this year. So the claim that Meta is locked out of the agent's memory is the roadmap, not the current build. The same post puts the rollout in the US only. For a European firm scoring agents against vendor questionnaires, both lines matter: the guarantee is dated, and availability is not there yet.
Love killing the prompt part. But it is not safe if they need to: “Handing an agent your credentials is the scary part of this whole category. Meta built a separate layer specifically to catch it doing something you wouldn’t approve of.”
Moving from rigid prompt engineering to goal-oriented agentic workflows changes the fundamental nature of security operations. We are finally shifting the burden of execution away from the analyst, allowing the machine to navigate intent rather than syntax. This transition mirrors the reality that internal decision chains in automated systems will remain opaque by design. Trying to force an audit trail for every micro-decision inside a high-speed agent is a distraction from the actual outcome. We should focus on the integrity of the goal itself instead of the black box mechanics of how the agent reaches it. Trusting the output requires a shift in how we validate performance at scale.
https://cyrilsimonnet.substack.com/p/nobody-will-ever-make-your-socs-ai?utm_source=substor&utm_medium=substack&utm_campaign=comment
Worth separating what shipped from what was announced. Meta's 8 September newsroom post describes Muse running on Muse Secure VM today, and says Muse Confidential VM, the version encrypted with a key only the person holds so Meta cannot access it, arrives later this year. So the claim that Meta is locked out of the agent's memory is the roadmap, not the current build. The same post puts the rollout in the US only. For a European firm scoring agents against vendor questionnaires, both lines matter: the guarantee is dated, and availability is not there yet.
Love killing the prompt part. But it is not safe if they need to: “Handing an agent your credentials is the scary part of this whole category. Meta built a separate layer specifically to catch it doing something you wouldn’t approve of.”
Fuzzy or funny 😹 revelations post hindsight sweet 🍬 mountains of grandeur, melting 🫠 AI 🤖.. muse 🥸