Meta announced Muse on September 8, 2026, a personal AI agent that does more than answer questions: it performs tasks on the user’s behalf and turns long-term goals into action plans. The rollout begins in the United States across iOS and Android devices and the muse.ai website, while the company plans to make it available on smart glasses soon. The service is free for most uses, with subscription plans for those who want to perform more tasks.
An Agent That Works Across Applications
Muse lets users interact with it in a messaging-like way, either inside the Muse app or directly through WhatsApp. According to Meta, the agent can send email, book trips, open the browser, fill out forms, and negotiate on the user’s behalf. It can also continue working after the app is closed, then return when something changes or when approval is needed, such as before sending a message or completing a purchase.
Muse is powered by the Muse Spark model, which Meta describes as its most capable model yet for agentic tasks in the real world. Users can share a general goal with the agent so it can create a customized plan, coordinate time and resources, and move the work forward. The company says Muse can also remember details that users share once, such as friends’ dietary restrictions, and use them later to suggest a menu or create a shopping list based on a recipe saved on Instagram.
Isolated Operating Environment and Access Controls
The product is built on Muse Secure VM, a dedicated virtual machine that hosts the agent, user data, and credentials for connected services. Meta says this environment is isolated from other users’ agents, and that a separate monitoring agent called Sentinel runs on the same device but is system-level separated from Muse. Muse is not allowed to access the internet unless Sentinel approves it, with a request for user permission when required.
According to Meta’s description, Muse does not directly see passwords or payment data; credentials are stored in a secure space that the agent can use without viewing them. It also displays a complete log of what it has done and what it plans to do, and requests user approval before sensitive actions. Users choose which applications Muse connects to and the level of permissions granted to each application, with the ability to modify permissions or disconnect the service at any time.
Payments and Privacy
For purchases, Muse can use Stripe’s Link service, which provides an agent wallet that creates a one-time card and hides the real card details. Meta says Muse is the first AI agent covered by Link purchase protection, including free coverage for damaged or lost items, price drops, fee-free returns, and return guarantees for eligible purchases. Shop Pay is scheduled to be added soon, along with support for 1Password to use existing login credentials.
Users can prevent their interactions from being used to train Meta’s models, and the company says Muse conversations and virtual machine data are not shared with its advertising systems. Users can also ask the agent to forget specific information it has learned. Meta intends to launch Muse Confidential VM later this year, with the virtual machine, data, and conversations encrypted using a key held only by the user, so that Meta itself cannot access them.
Why Does This Launch Matter?
Muse shifts the discussion from a bot that answers requests to an agent authorized to perform ongoing actions across the web and applications. Its practical value is tied to the user’s ability to control those permissions and review the activity log, not merely to the quality of the conversation. At the same time, most of the privacy and security promises come from Meta itself, the initial rollout is limited to the United States, and the agent’s effectiveness on complex tasks and the limits of its reliance on approvals remain issues requiring practical evaluation after use.