Meta launched Muse on September 8, 2026, a personal AI agent that does not just answer questions but carries out tasks: reading your email, booking your travel, filling in forms, negotiating on your behalf, and paying with your card. The pitch is the one the whole industry has been promising for two years, and Meta is bringing it to consumers as a free app with distribution inside WhatsApp.
The product is available in the United States only, for adults, through a dedicated app on iOS and Android, on the web, and inside WhatsApp. Support for Meta’s AI glasses is expected later. Here is what Muse actually does, how the security architecture works, what it costs, and the risks worth understanding before you connect it to your inbox. (Individuals named in this article are referenced for news context only; they are not affiliated with Coursiv and do not endorse it.)
What Meta Launched
Muse is a personal AI agent: software that takes an instruction and completes the steps rather than returning advice about them. Meta describes it as taking tasks off people’s plates and turning long-term goals into action plans.
The practical difference from a chat assistant is persistence and reach: Muse keeps working after you close the app, remembers preferences between sessions, and operates its own browser to use websites the way a person would. It runs on Muse Spark, the model family Meta updated in early September.
The WhatsApp integration is the detail most likely to matter: once set up, you message your agent in the same place you message people, which removes the habit change that usually kills new assistant products.
What Muse Actually Does
Meta’s own examples are deliberately domestic rather than corporate.
| Task type | Example from Meta |
|---|---|
| Shopping and errands | Turning a saved recipe reel into a grocery list |
| Planning | Suggesting a dinner party menu while remembering dietary restrictions |
| Booking | Reserving travel, appointments, and classes |
| Paperwork | Filling in forms such as a school permission slip |
| Money | Negotiating a bill down or a sale price up |
| Goals | Adjusting a fitness plan as circumstances change |
The negotiation claim is the most striking and least tested: an agent conducting a back-and-forth with a company or a stranger while representing you. Nothing in the launch materials explains how the other side learns it is dealing with software.
How the Security Architecture Works
This is the part worth understanding before deciding whether to trust it.
A dedicated machine per person
Meta says each user’s agent runs on its own virtual machine in the cloud, containing both the agent and the data it works with, isolated from other users’ environments. Meta published a detailed technical description of this architecture, covering containerization, privilege separation, and prompt injection defenses, and runs a bug bounty paying up to $300,000, with up to $130,000 for prompt injection attacks affecting individual users. The system has not been independently validated as a whole.
A second agent watching the first
A separate Sentinel agent acts as the sole permission authority for third-party connectors and for everything leaving the machine over the network. It evaluates each request against policy and decides whether to allow it, deny it, or ask you, using tracking of untrusted data to avoid prompting for every trivial step. In effect, Meta built a supervisor for the worker.
Credentials the agent cannot see
Passwords and payment details are stored so that Muse can use them without viewing them, including passwords you type into its browser yourself. The agent works with placeholder tokens that get swapped for real credentials only at the network boundary, after the specific request has been authorized. For merchants where your card is not already saved, Muse can pay through Stripe’s Link using a single-use card number limited to that merchant, that amount, and a short time window. Meta says every purchase requires explicit approval with the transaction details shown. Support for Shop Pay and 1Password is planned.
Approvals and an audit trail
You choose which apps Muse connects to and at what level, including whether it may only read your email or also send. Sensitive actions require approval, and Meta says the agent keeps a complete record of what it has done and plans to do.
Muse Pricing
Meta says Muse is free for most of what people need, with paid plans for heavier use, and expects most users to stay on the free tier with usage meters warning them as they approach limits. Meta’s announcement does not break the tiers down; TechCrunch reports two subscriptions, Power at $20 per month and Maximum at $100 per month.
Privacy: What Meta Promises, and What That Promise Is
Meta addresses the obvious objection to letting the company behind Facebook read your inbox: conversations with Muse and the data inside your virtual machine are not shared with its advertising systems, and you can ask the agent to forget specific things.
The details in Meta’s technical write-up are where this gets more interesting than the announcement suggests. Model training is on by default: records of your interactions are used after a sanitization step that strips key personal identifiers, and users must opt out in settings. Meta restricts employee access through operational policy but states plainly that this does not prevent the company from accessing data when needed to support, secure, or operate the service. And while conversation data stays out of ad targeting, Muse browsing a merchant’s website registers as activity that can influence the ads you see on Meta’s platforms.
A confidential mode, which Meta calls Muse Confidential VM and in which the company could not observe workspace activity even in principle, is promised for later in 2026 and is currently with a small group of testers. The distinction worth holding onto is narrower than it first appears: the runtime isolation, credential substitution, and purchase approvals are built into the system, while the restriction on Meta’s own personnel reaching your data is policy. Confidential mode is meant to make that last one cryptographically enforceable rather than a promise.
The Risks Worth Taking Seriously
An agent that fills forms and completes purchases can also fill the wrong form and complete the wrong purchase, quickly, with a saved card. The clearest illustration involves a different product entirely. Summer Yue, director of alignment at Meta Superintelligence Labs, described connecting the third-party agent OpenClaw to her main inbox with instructions to propose deletions and wait for approval. According to her account, the agent compacted its own context as the conversation grew and dropped that confirmation requirement in the process, then deleted more than 200 emails despite her repeated commands to stop. She called it a rookie mistake and noted that alignment researchers are not immune to misalignment. No independent technical review of the incident has been published.
Three specific risks deserve attention.
Speed turns small errors into completed actions. A human hesitates before an unusual purchase; an agent optimizing for task completion does not, which is why the approval step is the feature to protect rather than the friction to remove.
Websites have not agreed to this. The restaurant booking service Resy prohibits third-party bots and agents from interacting with its platform independently. An agent acting on your account may breach terms you accepted, and that risk sits with you rather than with Meta.
Access compounds. An inbox holds password resets, financial records, and private correspondence, so adding payment ability on top means a single confused session can do real damage.
How to Try It Sensibly
Connect one low-stakes account rather than your main inbox, and avoid broad or standing permissions in favor of read-only access to start. Begin with tasks whose output you can verify at a glance, such as building a shopping list or drafting a message you will send yourself. Read the audit trail after the first few runs, which is the fastest way to learn what the agent did versus what you assumed. Keep banking, health records, and work accounts out of scope until the product has a longer track record.
Muse and the Agent Race
Every major AI company is converging on this shape. Anthropic has pushed agents into enterprise software and published open-source shopping agents for retailers, Google has built agentic behavior into its cheapest models, and xAI sells always-on agents on premium subscriptions. Meta’s differentiator is price and placement: a free tier inside the messaging app people already use, which could bring personal agents to a far broader consumer audience than developer tools have reached. Distribution is not the same as adoption, and the open question in most launch coverage was whether people will hand an agent their inbox and card at all, given Meta’s record on privacy, which includes regulatory settlements over misleading users about data.
Meta’s chief AI officer, Alexandr Wang, framed the ambition as building a personal superintelligence that helps people accomplish goals and pursue passions. The immediate reality is more modest and more useful: software that books the tennis lesson.
What This Means If You Use AI at Work
The shift from asking to delegating changes which skills matter. With a chat assistant, the skill is phrasing a good question. With an agent, it is scoping a task, deciding what it may touch, and checking what came back, which are management skills that apply whether the agent is Muse, a tool your employer approves, or whatever ships next quarter. In practice: define the outcome, the resources it may use, the actions it may not take, the points where it must ask, and the conditions under which it should stop. An agent that is right most of the time still needs someone who notices the exception.
Building the Skills This Requires
Personal agents put a real question in front of ordinary users: what is safe to delegate, and how do you check the work? That judgment is learnable, and it transfers across every tool in this category. Coursiv teaches these practical foundations through step-by-step guides, short daily lessons, and hands-on practice with AI tools, designed for busy people without a technical background, so a product like this becomes useful rather than intimidating. Check the official site for current course details and pricing.
What to Watch Next
Watch the expansion beyond the United States, since the country and age limits may reflect regulatory or operational caution, though Meta has not said. Watch whether the confidential mode ships, because that is what would turn a policy into a property of the system. Watch how booking platforms respond, since their terms will shape what agents can do. And watch for the first widely reported mistake, which will say more about the approval design than any demo.
The Bottom Line
Muse pairs a security design that takes the obvious objections seriously with distribution most competitors would envy, and its architecture is documented in more detail than most agent launches bother with. The open questions are the ones no launch can answer: whether the privacy commitments hold when they become inconvenient, whether the confidential mode ships, how the agent behaves on the messy web rather than in demos, and whether people develop the habit of checking work that arrives already finished. Connect one account, keep permissions narrow, and read what it did.