Meta Ships Muse: A Personal AI Agent That Sends Email, Books Travel, and Buys Your Groceries — If You Trust It
Meta's first consumer AI agent connects to your email, calendar, payments, and smart home, running in an isolated Secure VM with a separate Sentinel watchdog — free tier plus $20 and $100 plans.
On Tuesday, September 8, Meta took its biggest swing yet at the post-chatbot era. The company launched Muse, its first personal AI agent for consumers: an assistant you don’t just talk to but delegate to — one that can send your emails, book your flights, negotiate your bills down, fill out forms, turn recipe videos into grocery lists, send party invitations, and complete purchases on your behalf.
The launch landed in the United States for users 18 and over, available on the web at muse.ai, through dedicated iOS and Android apps, and — in a move only Meta could make — directly inside WhatsApp chats. Support for Meta’s AI glasses is promised soon. The agent is free to start using, with paid plans kicking in as usage grows: Power at $20/month and Maximum at $100/month. A payment card is required at sign-up, which tells you exactly what kind of product this is.
An Agent, Not a Chatbot
The distinction Meta is drawing is deliberate. The ChatGPT era produced chatbots that answered questions, served as sounding boards, and in some cases became digital companions. Muse belongs to the agentic era: AI that can actually do things. Built by Meta Superintelligence Labs — the unit CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic — Muse is powered by Meta’s own Muse Spark model family and is designed, in the company’s words, so “there’s no learning curve.” You prompt it in natural language and it works on its own, continuing to operate even after you close the app.
The agent works by connecting to the apps and services that make up your daily workflows: email, calendars, payments, health and fitness, smart home, dining, shopping, music, and events. Users connect services one at a time, making the opt-in structure explicit. Muse ships with built-in connectors for popular services and has three fallback strategies for everything else: if a service exposes a public API, Muse can set up a connection using credentials the user provides; when no API exists, Muse simply operates the service through a browser.
Muse also learns. Meta says it improves over time by learning from your conversations what matters to you, then making suggestions unprompted. Users can customize the agent with a name, an avatar, and settings that shape how it communicates — a design choice aimed at making people feel personally connected to software that holds the keys to their digital life.
The Payments Piece: Link by Stripe
The most commercially consequential feature is checkout. Muse can complete purchases using Link by Stripe, which issues a single-use card number so the agent never spreads your real financial details across the internet. Meta says Muse is the first AI agent covered by Link’s purchase protections for agents, which guarantee no-fee returns. Integrations with Shopify’s Shop Pay and 1Password are coming soon. The choice of Stripe as the trust anchor is telling: Meta knows that letting an AI touch money is the single hardest trust problem in consumer software, and it picked a neutral third party to hold that line.
Secure VM and the Sentinel
Because a personal agent with access to email, payments, and health apps is a catastrophic breach waiting to happen, Meta’s differentiation strategy is architecture. Every Muse user gets a Secure VM: a dedicated, isolated virtual machine with its own browser where untrusted web data and third-party integrations are kept separate from the part of the agent that can take actions on your behalf.
Inside that VM runs the Sentinel — a separate agent that watches everything moving out of the virtual machine. When Muse wants to take an action, the Sentinel either matches it against an existing user-approved policy or triggers a human-in-the-loop approval dialog. Critically, these check-in prompts come directly to the user and are not filtered through the model itself, a deliberate defense against prompt-injection attacks where malicious web content tries to hijack an agent’s instructions.
Meta says Muse has no visibility into users’ passwords or payment methods, and that conversations and data are not shared with Meta’s ads systems. The company has already run the system through human and agentic red teams and its private bug bounty, and Muse is now in scope for the public bounty with payouts up to $300,000 — including up to $130,000 for successful prompt-injection attacks affecting a single user.
There is a harder promise on the roadmap: Confidential VM, where each virtual machine runs in a trusted execution environment and users hold their own access keys locally, making the VM inaccessible even to Meta. That work comes out of Meta’s collaboration with Moxie Marlinspike, the creator of Signal. WIRED viewed an advance draft of the technical white paper: select security firms will audit the Confidential VM source, and Meta will publish the binaries plus a transparency log so users can verify the integrity of their own connection.
The Trust Problem
Whether any of this matters depends on whether consumers believe it, and that is where Meta’s record gets in the way. The launch came less than two weeks after Meta agreed to an $18 billion multistate settlement over social media’s consumer harms, part of a wave of litigation that includes a $942 million New Mexico judgment and thousands of pending personal-injury and school-district cases.
The privacy rap sheet is long: a 2011 FTC settlement over deceiving users about public data, a record $5 billion FTC penalty in 2019 covering eight privacy violations, a 2023 FTC charge that Meta violated the resulting order, hundreds of millions of passwords found stored in readable format, and Cambridge Analytica. Meta’s VP of engineering for consumer products, David Singleton, acknowledges the tension: while Meta is barred by policy from accessing user Muse data, he concedes it would still be technically possible under the current Secure VM architecture. Users can opt out of having their data used for training.
The Competitive Picture
Muse arrives late to a category that already has viral hits. WIRED notes it is designed to compete with OpenClaw and Instinct, agents users message to automate digital tasks, alongside offerings like Gemini Spark and Claude Cowork. Other players are embedding agents into the chat surfaces people already use — Apple’s iMessage, SMS, WhatsApp. Meta’s counter is a triple play no rival can assemble alone: distribution through WhatsApp’s billions of users, Stripe-backed purchase protections, and a security architecture it is willing to open to third-party audit.
The internal codename history is its own signal. WIRED previously reported Muse was tested internally as “Hatch,” with Meta employees using it to autonomously operate third-party apps and browse the web on their behalf. A product that has been battle-tested inside a company of tens of thousands is at least a product that works; whether the public hands over their inboxes and bank accounts to the company that built the news feed is the multi-billion-dollar question.
Muse is live now in the US — free tier first, usage meter visible in the app, and a warning when the free allotment runs out. The agentic era’s most interesting experiment in institutional redemption has begun.
Sources
- [1] https://techcrunch.com/2026/09/08/meta-debuts-its-muse-ai-agent-will-consumers-trust-it/
- [2] https://www.wired.com/story/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it/
- [3] https://www.cnbc.com/2026/09/08/meta-personal-ai-agents-public-reckoning-privacy-safety.html
- [4] https://www.bloomberg.com/news/articles/2026-09-08/meta-announces-muse-ai-agent-for-personal-tasks-and-organization