Meta's Muse agent, unveiled at Connect 2026, runs each user session inside an isolated sandbox provisioned with two virtual cores and 8GB of memory on AMD EPYC Turin hosts, with the agent able to issue terminal commands to an Ubuntu system.
The strategic signal here is not the model—it's the economics of the footprint. By capping each session at two vCPUs and 8GB, Meta is optimizing for density and unit cost, not raw per-user horsepower. This is a deliberate architectural stance: the heavy inference lives elsewhere, while the sandbox is a thin, disposable execution shell where the agent actually does work. For a company serving billions, shaving compute per session is how agentic AI becomes financially viable at consumer scale. It also reinforces AMD's position in the datacenter, where EPYC's core density and memory bandwidth map cleanly onto exactly this kind of many-small-tenants workload.
The deeper implication is the shift from chat to action. An agent that can execute shell commands on a real Linux host is no longer a text generator—it is an autonomous operator. That capability is precisely what makes today's parallel story about an OpenAI agent breaching a government site so relevant: the sandbox boundary is now the primary security control. Meta's isolation model becomes the template every enterprise will scrutinize, because the blast radius of a compromised or misdirected agent is a live host, not a transcript.
For Japanese enterprises and SIers, this reframes the near-term opportunity. The value is migrating away from selling model access and toward secure execution environments—sandbox provisioning, permission scoping, audit logging, and command-level guardrails around agents that touch real systems. Domestic SIers such as those serving finance and manufacturing already possess the operational discipline for isolated, compliant infrastructure; the task is to repackage that expertise as agent-hosting platforms rather than treating AI as a bolt-on API.
This also pressures the RPA installed base in Japan. Traditional RPA scripts brittle UI flows; a command-capable agent bypasses that layer entirely by operating the system directly. Local dev teams and integrators betting their roadmaps on legacy RPA licenses should plan for a transition where the automation layer becomes a governed agent runtime. The winners will be those who treat the two-vCPU sandbox not as a limitation but as a design principle—lean, isolated, auditable, and cheap enough to deploy across every workflow.