Meta launched Muse on September 8, 2026 as a personal AI agent that can keep working after a user closes the app. It can plan travel, send email, fill forms, negotiate, shop, and maintain longer-running goals through the Muse app or WhatsApp. The US rollout covers adults on iOS, Android, and muse.ai, with AI glasses support planned.
The product is more consequential than another chatbot interface because it combines memory, browser control, credentials, and payment access. Meta's central launch claim is therefore architectural: every user's agent runs inside a dedicated Muse Secure VM, while separate services control what the agent can see and do.
MetaWhat the Meta Muse personal AI agent can do
Muse is designed around outcomes rather than individual prompts. A user can provide a long-term goal, after which the agent builds a plan, coordinates time and resources, and advances the work in the background. Meta's examples include selling a car, lowering a bill, adjusting a training plan, and converting a saved Instagram recipe into a grocery list.
The agent can also complete purchases using Stripe's Link. Link generates a one-time-use card so Muse does not receive the user's underlying card number, and purchase protections apply to eligible transactions. Meta says Shop Pay and 1Password support will follow. Muse is free for common use, with paid plans for higher usage, though the launch announcement does not publish a detailed pricing table.
Muse separates task execution from security decisions
Meta's published launch architecture, simplified to show where access and approval checks sit.
Muse agent
Plans work and operates a browser inside one dedicated cloud VM.
Sentinel agent
Separately reviews outbound actions before they reach the internet.
Credential service
Stores tokens and passwords outside the agent runtime and supplies scoped surrogates.
Human control
Requires approval for sensitive actions and exposes an audit trail and connection controls.
Source: Meta's "How We Built Safety Into Muse," published September 8, 2026. This diagram summarizes the disclosed design and is not an independent audit.
How Muse Secure VM separates access
Meta's technical description divides responsibility across components. The main Muse agent plans and executes tasks inside a dedicated cloud computer. A separate Sentinel agent reviews actions before they reach the internet. A credential service stores OAuth tokens, usernames, and passwords outside the main runtime cell, then supplies scoped credentials without revealing the secret to the model.
Human approval remains another boundary. Meta says Muse asks before sensitive actions such as sending email or making a purchase, and users can inspect an audit trail, choose whether a connection is read-only or can write, revoke access, and tell the system to forget remembered information.

The privacy promise and its present limit
Meta says conversations and data stored in a Muse VM are not shared with its advertising systems. Users can also opt out of having their Muse interactions used to train Meta's AI models. Those are meaningful product commitments, but they should not be confused with end-to-end encryption at launch.
The company says a later Muse Confidential VM will encrypt the entire virtual machine with a key held only by the user, preventing even Meta from accessing its contents. Until that feature ships and can be evaluated, the initial product depends on Meta's technical isolation, access controls, and policy promises. The published design is detailed, but it remains a vendor description rather than an independent security audit.
What users and companies should test
An agent that can act across email, commerce, calendars, and the web creates a much larger failure surface than a chatbot that only drafts text. The important tests are not whether Muse can produce an impressive plan, but whether it reliably stays inside granted scope, pauses at the right approval points, resists instructions hidden on webpages, and produces an audit trail a person can understand.
Meta's design addresses each category structurally. The Sentinel separates security review from task planning, credential surrogation limits secret exposure, and dedicated VMs reduce cross-user risk. None eliminates model error or prompt injection. Users should begin with narrow permissions and reversible tasks, especially before connecting email or payment accounts.
Muse also turns Meta's recent Muse Spark 1.3 release into a consumer product with ongoing authority. That transition from model capability to delegated action is the real launch: the competitive frontier is moving from who answers best to who can operate safely for hours without constant supervision.
Sources:
- Introducing Muse | Meta
- How We Built Safety Into Muse | Meta AI Research
- Meta launches Muse personal AI agent | Associated Press
- Meta releases Muse with privacy built into it | WIRED
Image credits
Header and in-body photograph: Meta Platforms headquarters in Menlo Park, California, photographed by LPS.1 via Wikimedia Commons, dedicated to the public domain under CC0 1.0. Reviewed September 9, 2026. The photograph does not depict the Muse product.