On September 28, Mark Zuckerberg announced Meta Enterprise Platform, calling it "the next major pillar of our business." Chirantan "CJ" Desai joins as Chief Enterprise Platform Officer, reporting directly to Zuckerberg, having stepped down as CEO and President of MongoDB. The initial scope named in the post: the Muse agent, Meta Business Agent, Muse API, and Muse Code, brought "to businesses and developers to help them grow."

That is the entire product disclosure. No SKUs, no pricing, no ad-account APIs, no dates. If you buy media on Meta, nothing in your account changed today and nothing will next week.

So this post is not a product breakdown, because there is no product to break down yet. It is about the one sentence in the announcement that actually points somewhere useful, and where it points.

The One Line Worth Following

Desai's statement includes this: "As with Muse, security and privacy are built into Meta's enterprise products from the outset."

That link is not decoration. It goes to a long, unusually specific engineering post about how Meta built the security model for Muse, its consumer personal agent. Meta is telling you, in the only technical sentence in the announcement, that this architecture is the precedent for what it sells to businesses.

Which makes it the closest thing available to a spec for how Meta thinks an agent should be allowed to act on your accounts. Worth reading in full. Here is what it establishes.

The agent never sees real credentials

Muse runs in an isolated Linux container. Credential storage lives outside that container in a separate daemon, and the agent only ever handles surrogate tokens. Real credentials are swapped in at the network boundary, after the specific request has been authorized. As Meta puts it, any attempt to coerce the agent into revealing secrets "is futile" — because the agent does not have them.

One gate for every action and every outbound request

A separate host-side component called Sentinel is the sole permission authority. The agent proposes; only Sentinel grants. That applies to connector actions and to every network request, evaluated at both layer 4 and layer 7 — hostname, resolved destination IP, port, protocol, HTTP method, path, and the decoded request body. Meta also built kernel-level data-flow tracking ("tainted egress") so a process that has read user data loses its ability to make auto-allowed outbound calls.

Approvals are capabilities, not conversation

When Sentinel needs a human decision, execution stops and the prompt is rendered in the client UI — deliberately not inside the chat with the agent — and the answer routes back to Sentinel directly. Grants are scoped: one-time, session, task, time-bounded, or perpetual, bound to a specific connector and use case. The agent cannot widen a grant by asking nicely.

Meta says prompt injection is unsolved

The post cites Simon Willison's "lethal trifecta" by name — private data access, exposure to untrusted content, and an outbound channel — and says the team has been obsessed with it. It lists four independent layers of defense, then concludes: "Muse isn't immune to attack. Prompt injection remains an open problem in the industry." Meta is now paying up to $300,000 for valid bug bounty reports, including up to $130,000 for a successful prompt injection affecting one user.

A company does not price a single-user prompt injection at $130,000 unless it expects to pay out.

The Case for Ignoring All of This

The strongest argument against this post is that it treats an org-chart announcement as a technology event. Meta named a division and hired an executive. Nothing shipped. Enterprise pivots announced with a leadership hire and no product have a poor track record, and the responsible move is to wait for a GA product with documentation.

That is fair, and it is why this post is not telling you to plan a migration.

The second argument is harder and deserves a real answer: agents are not new risk. Advertisers have granted third-party tools write access to ad accounts through OAuth for a decade. Agencies, bid managers, and creative platforms all hold tokens that can spend money. Why would an AI agent be treated differently?

Because of one property, and only one. A bid-management platform executes the rules you configured. It cannot be argued into a different rule by something it read. An agent that reads ad comments, landing pages, competitor sites, creative briefs, or a spreadsheet a client emailed is processing untrusted content — and it holds credentials that move money. That is the trifecta, in an ad account, with a budget attached.

Everything else about agents is genuinely comparable to the tools you already use. This one thing is not, and it is the thing Meta spent an entire engineering post building fences around.

What an Ad Account Actually Exposes

It is worth being concrete about the blast radius, because "an agent with account access" is vague enough to sound either trivial or apocalyptic.

Write access to a Meta ad account permits: raising budgets, launching campaigns, editing creative and destination URLs, changing audience definitions, and pausing everything. Read access exposes conversion data, customer-list audience names, and the full performance history of the account. An agent with both — and an outbound channel — can, in a bad case, quietly move spend to a changed destination URL, or read audience metadata and send it somewhere.

None of that requires a sophisticated attacker. It requires one string of text in a place the agent reads and a permission model that says yes by default.

Six Questions Before an Agent Gets Write Access to Spend

These apply to Meta Business Agent when it arrives, and equally to any MCP-based agent setup you build yourself today. Meta's post is useful precisely because it makes the questions specific.

1. Does the agent hold real tokens?

If your access token is sitting in the model's context or in an env var the agent can read, a prompt injection is a credential leak. The bar Meta set is that the agent never sees the credential at all.

2. Is there one gate, outside the agent, for every action?

Scattered per-tool permission checks inside the agent's own process are not a boundary — the agent can be talked around them. The architecture that works puts the decision in a component the agent cannot instruct.

3. Is spend separated from read?

Reporting, pacing analysis, and anomaly detection need read access only. Most of the value people want from agents in ad ops is read-shaped. Start there and grant write deliberately, per action, not as a bundle.

4. Where do approvals appear?

If the confirmation is a message in the same chat the agent controls, it is theater. It has to render somewhere the agent cannot write.

5. Are budget changes bounded?

A daily spend delta cap and a cap on new-campaign budgets turn the worst case from unbounded into a number you chose. This is the cheapest control on the list and the one most often skipped.

6. Is there a log of what the agent did, separate from what it said?

Chat transcripts are not an audit trail. You want the executed mutations — account, object, field, before, after, timestamp — recorded outside the agent, because that is what you will read at 2am.

The Takeaway

Meta Enterprise Platform is, today, a name, a leader, and a stated intention. Treat the announcement accordingly.

But the direction is not ambiguous, and it is not only Meta's. MCP connectors into ad platforms already exist, teams are already wiring agents across accounts, and the industry is moving toward agents that hold credentials rather than dashboards that hold settings. The interesting part of today's announcement is that Meta, pushing that future, published a frank account of how hard it is to do safely — and priced a single prompt injection at six figures.

The teams that will be fine are the ones who decide their permission model before the vendor decides it for them. Read-only first. Bounded write. Approvals outside the agent's reach. A mutation log you own. None of that depends on which platform ships an agent first, which is exactly why it is worth settling now, while nothing is on the line.

Sources: Meta Newsroom — Launching Meta Enterprise Platform (September 28, 2026), Meta Research — Security and Safety for AI Agents: Our Approach with Muse, MongoDB — MongoDB Announces CEO Transition, Simon Willison — The Lethal Trifecta for AI Agents

Decide the permission model, not the vendor's

Ads Agents connects your AI agents to Google, Meta, and TikTok over MCP — with scoped access per account, so you can start read-only, grant write where you mean it, and keep a record of every change an agent makes.

Get Started Free →