Learning Objectives
- Understand what Meta Muse does and how a connected personal agent differs from a chatbot
- Explain the Muse Secure VM and Sentinel design, and what it does and does not protect
- Weigh the access Muse asks for against Meta's own record on personal data
What Is Meta Muse?
Meta Muse is a personal AI agent announced on September 8, 2026. Meta's framing is that it "doesn't just answer questions, it actually does the work" β you give it a goal, it makes a plan, and it carries the plan out across the applications you already use.
The distinguishing feature is not the model but the connections. Muse links to a person's email, calendar, payments, health and fitness, smart home, dining, shopping, music and events accounts, and then acts inside them: sending mail, booking travel, filling in forms, turning a saved recipe video into a grocery list, sending invitations, and completing purchases through Stripe's Link checkout. Where a service publishes an API, Muse can connect using credentials you supply; where none exists, it drives the site in a browser the way a person would. Long jobs keep running after you close the app, and it returns when something changes or when it needs approval to spend money.
π‘Key Concept
Why connection is the whole product. A chatbot is useful with no access to anything β you paste in what it needs. A personal agent is useless without access, because the work it is supposed to save you is the moving of information between your accounts. That inverts the usual privacy calculation: the more valuable the agent, the more of your life it has to hold. Every product in this category is asking for the same trade; what differs is who is asking.
π―Tip
Access Meta Muse: muse.ai, plus iOS and Android apps and chat inside WhatsApp. Rolling out in the United States only at launch, with Meta's AI glasses named as "coming soon."
Muse and Muse Spark are different things
The naming here trips people, and it is worth getting straight before anything else. Muse Spark is Meta's frontier model, announced April 8, 2026 out of Meta Superintelligence Labs, code-named Avocado during development. Muse is the consumer agent launched five months later, and it runs on Muse Spark. One is the engine, one is the car. Meta also ships Muse Code and Meta Muse Image under the same family name.
The security design
Muse runs on its own dedicated virtual machine, the Muse Secure VM β which is where the agent lives and where the credentials for every service you connect are stored. Meta says Muse itself has no visibility into your passwords or payment methods, and that Muse conversations are not shared with Meta's advertising systems.
The more interesting piece is the second agent. A separate system called Sentinel runs on the same machine but is kept apart from Muse at the system level, and Meta's own description is specific: nothing Muse does reaches the internet unless Sentinel approves it, and Sentinel asks the person for permission when it needs to. That is a meaningful architectural choice rather than a policy promise β it puts a separate process in the path of every outbound action, which is the standard defence against an agent being talked into something by a malicious web page.
Meta says a Muse Confidential VM will follow later in 2026, encrypted such that Meta itself cannot access it.
β οΈWarning
Meta says users can opt out of having their Muse interactions used to train its models. It has not said whether that opt-out is on or off by default, which is the detail that decides what it is worth. Separately, every claim in this section is Meta's own description of its architecture, published at launch; none of it has yet been examined by outside security researchers. Treat it as a design worth crediting and not yet as a design that has been tested.
Pricing
Meta's announcement says Muse is "free for most of what people need, with subscription plans for people who want to do more," and does not publish tier names or prices. TechCrunch, briefed at launch, reported two paid plans β Power at $20 a month and Maximum at $100 a month β plus a usage meter in the app and a requirement to put a payment card on file before you start. The Verge, covering the same launch, noted that Meta specified neither the cost nor the free-tier limits.
- Meta says this covers most of what people need
- Usage-metered, with limits Meta has not published
- A payment card is reportedly required to begin
- More Muse usage for everyday task handoff
- Meta expects most people to stay on the free tier
- Tier names and prices reported by TechCrunch
- The highest usage allowance
- For continuous or heavy delegation
- Confirm current pricing in the app before subscribing
Because the tiers are metered rather than feature-gated, the practical question is not which features you need but how much delegating you actually do β and there is no published number to plan against yet.
The claim to check
Meta is marketing Muse as "the world's first personal AI agent built for everyone." That is a positioning claim rather than a fact, and it does not survive contact with the market: Gemini Spark targets much the same consumer audience, and Grok Bot, Claude Cowork and Microsoft's Copilot Tasks all shipped earlier, along with the open-source agent Moltbot. What is defensible in the claim is the distribution β Muse reaches people inside WhatsApp, which nothing else in this category can do, and that is a genuine difference worth naming without the superlative.
Strengths
- Distribution nothing else has β an agent you message inside WhatsApp meets people where they already are, rather than asking them to adopt a new app
- A real isolation design β a second approving process (Sentinel) in the path of every outbound action is a stronger answer to prompt injection than a policy promise, and the credential store sits outside the agent's view
- Genuinely broad connectors β email, calendar, payments, health, smart home, dining, shopping, music and events out of the box, with a browser fallback when a service has no API
- No technical setup β the pitch is that there is no learning curve and nothing to configure, which is the actual barrier for most people in this category
- Free tier that is meant to be usable β Meta says most people will not need to pay, which is a different posture from the $20-and-up floor most agent products start at
Limitations & Considerations
- The trust question is the product's central risk, not a footnote. Muse asks for more personal access than any assistant Meta has shipped, from a company fined $5 billion by the US Federal Trade Commission in 2019 over privacy violations, charged with breaching the resulting order in 2023, and which settled multistate claims over social-media harms for $18 billion less than two weeks before this launch. None of that makes the engineering wrong. It does mean the engineering is the only thing carrying the argument
- United States only at launch, with no announced timeline for other countries
- The training opt-out's default is unstated β and for an agent that reads your mail, the default is the whole question
- No independent security review yet β the Secure VM and Sentinel design is credible as described, but "as described" is doing the work until someone outside Meta tests it
- Pricing is not officially published, so the figures above could move before you read this
- Metered, not feature-gated β heavy delegation is where cost appears, and Meta has published no allowance you can plan against
Getting Started
- Open muse.ai, or install the iOS or Android app β United States only for now
- Expect to add a payment card before the free tier will start, per launch reporting
- Connect one service first, not all of them. Permissions are granted per app and per scope, so start with something low-stakes β calendar or a shopping account β rather than mail
- Check the training opt-out in settings before you connect anything sensitive, since Meta has not said which way it defaults
- Give it a task you can verify end to end, and watch where Sentinel stops to ask permission β that tells you where the approval boundary actually sits
- Only widen access once you have seen it handle something correctly
Key Takeaways
- Meta Muse is a connected personal agent, launched September 8, 2026 in the United States on iOS, Android, muse.ai and WhatsApp, running on Meta's own Muse Spark model
- It acts inside your accounts rather than returning drafts β mail, calendar, payments, shopping, smart home β using a browser where a service offers no API
- The security design is the notable engineering: a dedicated Muse Secure VM holds connected credentials outside the agent's view, and a separate Sentinel agent must approve anything Muse sends to the internet
- Meta has not published pricing. Reported tiers are Power at $20 a month and Maximum at $100 a month, with a free tier Meta expects most people to stay on
- "World's first personal AI agent built for everyone" is marketing β Gemini Spark, Grok Bot and Claude Cowork all preceded it; the real differentiator is reaching people inside WhatsApp
- Judge it on the trust trade. The access it needs is the access that makes it useful, and Meta's privacy record is the reason that trade deserves more scrutiny here than it would elsewhere














