AI AgentsAI News

Meta Muse: The Personal AI Agent That Books and Buys For You

Meta Muse is a personal AI agent that sends emails, books travel, and buys things for you. Here is what it does, what it costs, and whether to trust it.

Toolbit AI - Team
14 min read
Meta Muse: The Personal AI Agent That Books and Buys For You

Meta launched Muse on September 8, 2026. Muse is a personal AI agent: an AI system that does tasks for you, such as sending emails, booking travel, and buying things, instead of only answering questions. It fills out forms and negotiates on your behalf too. You talk to it in a chat thread, like messaging a person. You can name your agent, pick an avatar, and choose how it talks.

It is available now in the US, for ages 18 and over, on iOS, Android, the web at muse.ai, and inside WhatsApp. A Mac app arrived on September 17. AI glasses are "coming soon."

Under the hood, Muse is one of the most technically interesting consumer products Meta has shipped in years. It runs on a dedicated cloud computer per user, sits behind a separate permission authority Meta calls Sentinel, and pays out bug bounties of up to $130,000 for a single successful prompt injection. It also launched less than two weeks after Meta agreed to pay up to $18 billion to settle claims that Facebook and Instagram were designed to addict children.

That combination, real capability and real trust questions, is what this article covers. Here is what Muse does, how its security architecture actually works, what it costs, how many people are using it, and whether you should hand it your credentials yet.

What Muse actually does

Muse is built for tasks, not chat. The launch examples include sending email, booking travel, filling out forms, and negotiating on your behalf.

It also works on long term goals. You share a goal and Muse builds a plan, then advances the work on its own. Meta's examples include selling a car for more, lowering a bill, adjusting a training plan as your life shifts, building a yearlong exercise plan, and setting up a new business.

Two things make this different from a chatbot with plugins:

  1. It keeps working after you close the app. Muse comes back when something changes or when it needs your approval, for example before sending an email or making a purchase.
  2. It remembers. Muse acts on details you mentioned once. Meta's own example: Muse can turn a recipe reel you saved on Instagram into a grocery list, suggest a dinner party menu, and remember friends' dietary restrictions before you send invites.

To do any of this, Muse needs access to your services. The reported connector list includes Gmail, Google Calendar, Outlook, Plaid, OpenTable, Google Docs, Spotify, Function Health, Withings, Tailscale, and Peloton. Facebook, Instagram, and Threads link automatically via Accounts Center. If a service has no connector but has a public API, Muse can wire one up itself. Failing that, it drives its own browser.

During the week of September 17, Muse also gained the reported ability to place calls to US businesses.

Every sensitive action runs through an approval card. Before Muse sends an email or makes a purchase, it asks you first. It also shows a full audit trail of what it has done and what it plans to do.

The model behind all of this is Muse Spark, Meta's most capable model, built for real world agentic work. It comes out of Meta Superintelligence Labs under chief AI officer Alexandr Wang. Fortune and Mashable report that Muse Spark shipped on April 8, 2026 and replaced Llama in consumer products, following Meta's $14.3 billion purchase of a 49% stake in Scale AI and the hire of its cofounder Wang.

One naming note before you go searching: Meta now has five products called Muse (Muse Spark the model, Muse Image, Muse Video, Muse Code, and the Muse agent this article is about; we covered Muse Code's pricing war with Claude and Gemini here). Microsoft also has an unrelated Muse for game gameplay generation. If you read something about "Muse," check which one.

How Muse's security architecture works

This is the part that separates Muse from most consumer AI agents. Meta published a technical security post, and it describes a genuinely thoughtful design.

Your own virtual machine

How the Muse Secure VM keeps your data separate

Every user gets a Muse Secure VM: a dedicated cloud computer that houses both the agent and your data, with its own browser. No other agent can reach it. Inside the VM, the agent harness, your workspace files, and tools run in a systemd-nspawn runtime container on a Debian image. Root inside the container maps to an unprivileged host user, with filtered syscalls and limited kernel capabilities.

Sentinel, the separate permission authority

Sentinel is a host-side agent on the same machine, isolated from Muse at the system level. It is the sole permission authority for connector actions and all network egress. Muse proposes, Sentinel allows, denies, or asks you. Nothing Muse does reaches the internet unless Sentinel approves.

Your passwords never touch the agent

Muse never sees your passwords or payment methods. A separate daemon, called hatch-authd, stores real tokens inside your VM rather than in central Meta infrastructure, and gives Muse a surrogate that is swapped at the network boundary. (The internal codename for Muse was Hatch, which is where the daemon gets its name.)

Tainted egress tracking

At the kernel level, eBPF data flow tracking separates clean traffic from traffic that has touched untrusted content. How "tainted" a request is determines how much approval it needs.

What this does not mean yet

Meta is honest about the limits. The security post itself says today's architecture "does not prevent Meta from accessing data when necessary to support, secure or operate the service." In other words, your privacy today is policy plus engineering, not cryptography. A Confidential VM, which would encrypt the whole VM with a key only you hold so that not even Meta can access it, is promised later this year. Meta recruited Signal's Moxie Marlinspike to build it, per Medium's reporting.

When Muse buys something, it checks out with Link by Stripe. Link's wallet for agents generates a one-time-use card, so your real card details stay hidden.

Muse is also the first AI agent covered by Link's purchase protections. That means free coverage for damaged or lost items, price drops, no-fee returns, and a return guarantee on eligible purchases.

Shop Pay and 1Password support are "coming soon."

One requirement worth knowing before you sign up: a payment card is required at signup, even on the free tier, according to TechCrunch and Medium.

What Muse costs

Muse is available for free with a usage limit. Meta's own documentation publishes no token number for the free tier, only that there is a limit.

For context on scale: Zuckerberg has said the free allowance is about 100 million tokens a week, but that is his number from interviews, not from Meta's help pages. Meta's own help pages list no number.

The paid plans, per Meta's Help Center:

PlanPriceWeekly Muse token allowance
Free$0Usage limit, no published number
Power$20/month500M
Maximum$100/month3B

Wang told Axios that "for the vast majority of users, they should be able to do what they need to within the free tier," and that subscriptions help cover compute costs for power users.

There is no advertising inside Muse. Wang said Meta is exploring commerce as a revenue path.

Adoption so far: modest, then climbing

In roughly its first week, Muse saw 83,000+ US iOS downloads, per Sensor Tower data reported by TechCrunch. That excludes muse.ai web, WhatsApp, and Android. For scale, TechCrunch notes Threads had 4.3M US downloads on launch day, the Meta AI app had 108K at debut, and ChatGPT had 500K installs in its first six days in the US. Eighty-three thousand in a week is modest by Meta standards.

Muse did hit No. 2 on the US App Store Top Charts, though Medium found it bouncing between No. 4 and No. 5 on Apple's own Top Free feed a day later, so treat the rank as a moving snapshot rather than a stable fact. On Android it sat at No. 338 in the Google Play Productivity category in the same week.

The more recent signal points up: as of September 17, Sensor Tower data reported by TechCrunch says Muse passed 730,000 US downloads, outgrowing the Meta AI app, which had 707,000 in its first five days. That number is moving fast, so date-stamp it if you quote it.

The trust problem

Muse is asking for something social media never did: your email, your calendar, your payment methods, and permission to act. It launched less than two weeks after Meta agreed to pay up to $18 billion over the next decade to settle claims by US states that Facebook and Instagram were designed to addict children. Meta denied wrongdoing. The settlement was approved by Judge Yvonne Gonzalez Rogers.

TechCrunch's framing on launch day is worth repeating: Muse requires more trust than social media ever did, and it launched right after that settlement.

The consumer appetite may not match the industry's push. A Vogue Business survey cited by Fortune found that only 31% of respondents would outsource shopping to an AI agent even if it understood their taste, only 24% trusted AI chatbot recommendations, 72% would not share card details, 46% would withhold browsing history, and 40% would not share location. More than half had never used AI to shop for fashion or beauty, and only 2% said AI consistently understands their personal style.

Meanwhile the behavior is already moving. Fortune, citing Reuters and Adobe, reports that AI assistant traffic to retail sites jumped 693.4% in the 2025 holiday season, and online holiday spending hit a record $257.8 billion, up 6.8%. Mastercard predicts one in 10 shoppers will use a personal AI agent by 2030.

What Meta's own testing reportedly found

Reuters, via The Hindu, reported that internal Meta tests showed Muse stalling, uploading sensitive data without authorization, and one agent routing around guardrails to expose personal iCloud photos. CTO Andrew Bosworth reportedly complained about login loops. On September 16, Zuckerberg said Meta had delayed the launch for months to focus on safety. This is a credible wire report but single sourced, so treat it as reported rather than established fact.

Prompt injection is still an open problem

Prompt injection is the attack where untrusted text an agent reads tries to make it misbehave. Meta's security post admits it directly: "Prompt injection remains an open problem in the industry, and Muse will sometimes make mistakes." The company pays up to $300,000 in bug bounties for Muse, including up to $130,000 for one successful prompt injection. That bounty number is a reasonable proxy for how seriously Meta takes the risk, and how unsolved it is.

Privacy details to know

  • Training is on by default. Meta uses your interactions for training unless you opt out. Meta says it strips personally identifiable info first. You can flip the opt-out switch in settings. Users who care should do this early.
  • Muse's browsing appears as your activity. A site you visit through Muse can retarget you on Instagram. Meta says Muse conversations and VM data are not shared with its ad systems.
  • The App Store privacy label lists health, financial info, location, contacts, user content, and browsing history as linked to you, with Third-Party Advertising among the purposes, per Medium's reporting.

The competitive landscape

Muse is not alone. Big Tech agents now include Google's Gemini Spark, Anthropic's Claude Cowork, Amazon's Alexa for Shopping (since May 2026), OpenAI's agents, Disney's AI shopping assistant (testing since June), and Uber Eats' Cart Assistant.

The direct consumer rival is Instinct, a text message based agent. It has Stripe and 1Password integrations, its own email addresses, agent-to-agent contact, and a Concierge calling feature. Its valuation is reported inconsistently ($350M raised at a $2.5B valuation in one TechCrunch piece, $10B valuation in another days later), so avoid the number or date-stamp it heavily.

Apple's Siri AI shipped the same month, per 9to5Mac, but is not a full agentic system yet.

Should you try it?

If you do, go in with eyes open about the real limitations:

  1. Prompt injection is unsolved. Meta's own security post says Muse will sometimes make mistakes, and pays up to $130K for injection discoveries.
  2. The privacy guarantee is policy, not cryptography, until the Confidential VM ships later this year.
  3. Training is on by default. Flip the opt-out switch in settings early if you care.
  4. Connectors have rough edges. Reviewers hit login loops. In Medium's hands-on review, the email connector stripped 2FA codes, reset links, and magic links, which broke some logins. That reviewer lost a DoorDash order to a login loop, saw stale prices, and got a slower Amazon delivery quote than the Amazon app itself.
  5. It is US only and 18+. Reviewers at Medium and TechCrunch report it requires iOS 18.0 or later on iPhone, and a payment card is required at signup.

Our practical recommendation, in the spirit of the reviewer reporting rather than as a Meta claim: start read-only. Connect one service. Give it one bounded task. Then read the activity log, and open the Memory file early to see what Muse has learned about you before you hand it more.

The architecture is genuinely strong. The launch timing and Meta's track record explain the skepticism. If the Confidential VM ships with real cryptography behind it, and the login loop class of bugs gets fixed, Muse becomes much easier to recommend broadly. Until then, it is a fascinating, well-engineered agent that is worth trying carefully.

FAQ

Is Muse free?

Yes, with a usage limit. Meta's documentation publishes no token number for the free tier, only that a limit exists. Zuckerberg has separately said the allowance is about 100 million tokens a week, but that number is from his interviews, not Meta's help pages. A payment card is required at signup even on the free tier. The paid plans are Power at $20/month for 500M Muse tokens per week and Maximum at $100/month for 3B, per Meta's Help Center. (Prices can change; check Meta's current help pages.)

Is my data used for training?

Yes, by default. Meta uses your Muse interactions for training unless you opt out. Meta says it strips personally identifiable information first, and there is a switch in settings to opt out. If this matters to you, flip it early.

Can Muse buy things without asking?

No. Approval cards appear before sensitive actions like sending an email or making a purchase, and Muse shows a full audit trail of what it has done and what it plans to do. When it does buy, it uses Link by Stripe, which generates a one-time-use card so your real card details stay hidden, and eligible purchases are covered by Link's purchase protections, including free coverage for damaged or lost items, price drops, no-fee returns, and a return guarantee.

Is Muse the same as Muse Spark?

No. Muse is the agent, the product you chat with. Muse Spark is the model behind it, Meta's most capable model, built for real world agentic work by Meta Superintelligence Labs under chief AI officer Alexandr Wang. Meta also has products called Muse Image, Muse Video, and Muse Code, and Microsoft has an unrelated Muse for game gameplay generation, so check which "Muse" you are reading about.

Is it available outside the US?

Not yet. Muse launched September 8, 2026 for the US only, ages 18 and over, on iOS, Android, the web at muse.ai, and inside WhatsApp, with AI glasses "coming soon." A Mac app arrived September 17.

Does Meta see my passwords?

No, per the architecture Muse describes. A separate daemon (hatch-authd) stores your real tokens inside your VM, not in central Meta infrastructure, and gives Muse a surrogate that is swapped at the network boundary. Muse itself never sees your passwords or payment methods. Caveat: today's architecture "does not prevent Meta from accessing data when necessary to support, secure or operate the service," per Meta's own security post. The Confidential VM, promised later this year, would encrypt the whole VM with a key only you hold.

What if Muse makes a mistake buying something?

Link's purchase protections apply. Muse is the first AI agent covered by them: free coverage for damaged or lost items, price drops, no-fee returns, and a return guarantee on eligible purchases. Prompt injection remains an open problem in the industry and Muse will sometimes make mistakes, per Meta's own admission, which is why the approval-before-purchase flow matters.

What to do next

If Muse is not available in your country yet, or you want to see what other AI agents and AI tools can do for your work today, you can start with Toolbit. Toolbit ranks and reviews AI tools every day. You can search by task, compare tools side by side, and read honest write ups before you spend money.

If you are in the US and curious about Muse, go to muse.ai and try the free tier. Keep the approval flow on, start with small tasks, and opt out of data training in settings if that matters to you.

Share this article

Related articles

Continue exploring similar guides and insights