What Is Meta Muse? Meta's Personal AI Agent, Explained
Meta Muse is a personal AI agent that sends email, books travel, and shops for you from a private cloud VM. What it does, how its safety design works, pricing, and what it means for agents at work.
Meta Muse is a personal AI agent from Meta that takes real actions on your behalf: sending email, booking travel, filling in forms, negotiating a bill, and paying at checkout. Meta announced it on 8 September 2026 and is rolling it out in the United States to adults, through iOS and Android apps, the web at muse.ai, and WhatsApp. Each user's agent runs in a dedicated cloud virtual machine with its own browser, and a separate supervisor called Sentinel must approve anything the agent sends to the internet. There is a free tier, plus Power at $20 a month and Maximum at $100. Muse is a consumer product. It is not built for teams, does not connect to business systems, and is only available in the US, but the way Meta has engineered it says a lot about what a trustworthy agent has to look like, at home or at work.
This post covers what Muse does, how it is built, what it costs, the trust question everyone is asking, and what its design means for anyone deploying agents in a company. Facts about Muse come from Meta's announcement, Meta's engineering post on Muse safety, and launch-day reporting from TechCrunch and The National, with links so you can check. The product is one day old and details will move.
Key takeaways
- Muse is an agent that does things, not a chatbot. It opens a real browser, fills forms, sends email with your permission, and checks out using a single-use card from Stripe Link.
- Each user gets an isolated VM in Meta's cloud. The agent never sees real passwords; a separate Sentinel process holds the credentials, approves every network request, and asks you before sensitive actions.
- It is free for most use, with $20 and $100 monthly tiers. US only, 18 and over, on app, web, and WhatsApp, with Meta's AI glasses to follow.
- Meta says Muse conversations and VM data never reach its ad systems, and you can opt out of model training. Whether people believe that is the launch's central question.
- For business readers, the interesting part is the architecture. Isolation, scoped permissions, approval before irreversible actions, and a log of everything done are the same primitives a work agent needs. Muse has none of the shared knowledge, team scopes, or business integrations that make an agent useful in a company.
What does Meta Muse actually do?
Meta's own description is "a secure, private personal AI agent that proactively helps with people's goals and suggests ideas." The examples in the announcement are deliberately ordinary: send an email, book a trip, buy movie tickets, book a tennis lesson, fill in a school permission slip, sell a car, get a bill lowered, build a grocery list from saved recipes, or turn a year-long fitness goal into a plan and keep adjusting it.
The distinction from Meta AI, the assistant already inside WhatsApp and Instagram, is that Muse acts. It has a browser you can watch. It has connectors to your email and calendar, with permission set per connector (read-only, or read and send). It remembers what matters to you across conversations, and you can tell it to forget something. Meta's phrasing is that Muse "builds an action plan, tracks your progress and proactively takes tasks off your plate," which puts it in the same category as OpenAI's agent mode in ChatGPT and Google's Gemini agents, rather than the chat assistants of 2024.
Mark Zuckerberg's framing on launch day, as reported by The National, was about control: you choose which apps and services Muse can reach, and you can disconnect them at any time.
How is Muse built?
This is where the launch is most interesting, and Meta has published far more detail than is usual for a consumer product. The engineering post describes four layers.
The Muse Secure VM
Every user gets their own virtual machine in Meta's cloud, running Linux with a Chromium browser. The agent itself runs inside a further sandboxed container within that VM, with filtered system calls and stripped kernel capabilities. Meta's summary: "two isolated security domains on one box, not an LLM powered agent with root." No other user's agent can reach your VM. Your memories, files, and connector data live there, not in a shared Meta database.
Sentinel, the supervisor that says no
Sentinel is a separate process on the host side of the VM. It is the only thing that can grant permission for a connector action or a network request. The model is "propose, authorise, execute": Muse proposes an action, Sentinel evaluates it against policy at the network level (hostname, port, HTTP method, path, and decoded request body), and either allows it, blocks it, or asks you.
The asking part is done outside the chat. When Sentinel needs your approval, it sends the exact action to the Muse app, which shows a dialog describing what is about to happen. Approvals are bound to a specific destination and purpose, and can be one-time, session-scoped, task-scoped, or time-limited. The agent cannot talk its way past this, because the agent does not control it.
Credentials the model never sees
Passwords, tokens, and cards are held in an encrypted vault inside the VM that the agent cannot read. The agent works with placeholder tokens. When Sentinel approves a request, it swaps the placeholder for the real credential at the network boundary. Meta's claim is that any attempt to coerce the agent into revealing secrets "via prompt-injection or otherwise is futile," because the secrets are not in the agent's reach. For purchases, Stripe Link issues a single-use card number tied to one merchant, one amount, and a short validity window. 1Password support and Shop Pay are listed as coming.
Tainted egress and prompt injection
Muse reads untrusted content constantly: web pages, emails, PDFs. Any of it could contain instructions aimed at the agent. Meta's defence has four parts. The model is trained to resist injection and is measured on it. External data is labelled as untrusted before it enters the model's context. An ensemble of independent classifiers scans everything coming in. And at the kernel level, the VM tracks which processes have touched user data; once a process is "tainted," it loses autonomous network access and needs a human to approve anything it sends out. The browser sees an accessibility tree rather than the raw page and cannot execute JavaScript, and checkout pages always trigger a review showing the exact purchase.
Meta is candid about the limits. The engineering post says outright that "prompt injection remains an open problem in the industry, and Muse will sometimes make mistakes." A bug bounty pays up to $300,000, with $130,000 on offer for a working injection against a single user. A Muse Confidential VM, planned for later in 2026, is meant to encrypt the VM with a key only the user holds, so that Meta itself cannot read it; the current design does not prevent Meta from accessing data to operate the service.
What does Muse cost, and where can you use it?
| Tier | Price | What Meta says it is for |
|---|---|---|
| Free | $0 | "Most of what people need" for everyday tasks |
| Power | $20 per month | Heavier use and more compute |
| Maximum | $100 per month | The highest usage allocation |
The tier prices come from TechCrunch's launch coverage. Meta's announcement does not publish usage caps per tier; reports on launch day put the free tier at roughly 100 million tokens a week, attributed to Zuckerberg, but treat that figure as unconfirmed until Meta documents it.
Availability at launch: the United States only, users 18 and over, via the Muse app on iOS and Android, the web at muse.ai, and chats inside WhatsApp. Support for Meta's AI glasses is "coming soon." There is no UK or EU date.
Under the hood is Muse Spark, the model Meta Superintelligence Labs unveiled in April 2026 as the company's first reasoning model, built for tool use and multi-step work. Fortune's coverage at the time framed it as Meta's recovery from the poorly received Llama 4. Muse the agent is locked to Muse Spark; there is no model choice.
Will people trust Meta with an agent?
TechCrunch's headline on launch day was a question, and the article was a list of reasons for doubt: the 2019 record $5 billion FTC penalty, the 2023 charge of violating that order, passwords found stored in readable form, Cambridge Analytica, and the fact that Muse arrived two weeks after Meta settled a multistate lawsuit over harms to children. None of that is about Muse's engineering. All of it is about whether users will hand Meta their inbox and their card.
Meta's answers are specific. Muse "doesn't share a person's conversations or the data in their VM with Meta's ad systems." Users can opt out of their interactions training Meta's models. The engineering post has been published for outside scrutiny, and the Confidential VM design and source are being given to external auditors, with a continuous audit Meta says will be "visible to and inspectable by anyone."
Two things are fair to say. First, the security architecture is more serious than anything published for a consumer agent so far, and the decision to make the approval dialog independent of the chat is the right one. Second, none of it has been tested at scale yet. TechCrunch's own note is that the claims "require deeper investigation by security experts." An agent with email and payment access is a new kind of target, and the bounty programme is an admission that Meta expects to find holes.
What Muse does not do
For anyone reading this from an office, the gaps matter as much as the features.
- No business systems. Connectors cover personal email, calendar, and the open web. There is no Salesforce, HubSpot, Notion, Google Drive for a company, Slack, or Teams. Meta points business users at its separate Meta for Work products.
- No shared context. Muse's memory is one person's. There is no way to give a team of ten the same agent grounded in the same documents, or to let a colleague see what the agent did for you.
- No team permissions. Scopes are per user, per connector. There is no admin, no role, no way to say "everyone in sales can read the CRM but only managers can update it."
- One model, one vendor. Muse Spark only, hosted by Meta only.
- US only, individuals only. No EU availability, and the terms are consumer terms, with no data processing agreement, ISO or SOC evidence, or single-tenant option.
None of these are criticisms. Muse was not built for this. But the search intent behind "can I use Meta Muse for work" deserves a plain answer, and the answer is no, not yet, and probably not in this form.
What Muse's design says about agents at work
Here is the part worth holding onto. Meta has just told a few billion people that a trustworthy agent has four properties: it runs in an isolated environment, it never holds the real credentials, it asks a human before doing something irreversible, and it keeps a record of everything it did and plans to do. That is a consumer-scale endorsement of exactly the checklist security teams have been applying to business agents for the past year.
Translate each one into a company setting and the requirements get stricter, not looser.
Isolation becomes per-organisation sandboxes with no shared file system, so one customer's agent cannot see another's, plus a single-tenant option for firms that need it. QX runs agents this way, and the Trust Center documents the ISO 27001 certification and SOC 2 work behind it.
Credential separation becomes app-level encryption of every integration credential, with the model never exposed to the secret and any integration revocable in one click. Muse's placeholder-token design and QX's encrypted credential store arrive at the same principle from different directions: the model should be able to use a tool without being able to steal it.
Approval before irreversible actions becomes scoping and gating at the team level. An agent's scopes can be trimmed to individual tools and to the account it acts as, so an agent that can read an inbox but cannot send from it cannot send, however it is asked. A Flow can route a draft to a person in Slack or email before the deterministic send step, and branch on rules such as "discount over 15% needs a VP." Muse's per-action dialog is the personal version of the same gate.
A record of everything becomes run history with each step's inputs and outputs inspectable afterwards, which is what an auditor, a compliance lead, or a manager who wants to know why the agent emailed a customer actually needs.
Then add the two things a personal agent never has to solve. A work agent must be grounded in shared company knowledge, with citations, so ten people get the same correct answer from the same policy document; that is what Knowledge Vaults are for. And it must reach the systems where work happens, across 1,000+ business apps, from the channels where the team already talks, which for most companies means Slack and Teams rather than WhatsApp alone. We covered the broader safety question in Are AI agents safe? and the specific failure mode of agent sandbox escapes if you want to go deeper.
The upshot: Muse makes the safety bar legible to non-specialists, which is good for everyone building agents. If your consumer app now asks before it buys, your employees will reasonably expect the agent that touches the CRM to do the same.
FAQ
Is Meta Muse free?
Mostly. Meta says Muse is free for most everyday use, with Power at $20 a month and Maximum at $100 a month for people who want more compute and heavier usage. Meta has not published exact usage caps per tier. Launch-day reports put the free allowance near 100 million tokens a week, unconfirmed by Meta so far.
Where is Meta Muse available?
At launch, only in the United States, for users aged 18 and over. You can reach it through the Muse app on iOS and Android, the web at muse.ai, and inside WhatsApp. Meta says support for its AI glasses is coming soon. No date has been given for the UK, the EU, or other regions.
Does Meta Muse use my data for ads?
Meta says no. Its announcement states that Muse does not share a person's conversations or the data in their VM with Meta's ad systems, and users can opt out of their interactions being used to train Meta's models. A planned Confidential VM would encrypt the VM with a key only the user holds, so Meta could not read it.
Can Meta Muse access my passwords or my card?
Not directly. Credentials are held in an encrypted vault inside your VM that the agent cannot read; it works with placeholder tokens, and Sentinel swaps in the real credential only after approving a request. Purchases use a single-use Stripe Link card tied to one merchant and amount, and checkout always pauses for your confirmation.
Can I use Meta Muse for work or with my team?
Not in its current form. Muse is a consumer product with personal email, calendar, and web connectors, one memory per person, and no team permissions, shared knowledge, business app integrations, or enterprise terms. It is also US-only. Teams that want an agent across Slack, CRM, and internal documents need a business agent platform.
How is Meta Muse different from Meta AI?
Meta AI is the chat assistant inside WhatsApp, Instagram, and Facebook; it answers questions. Muse is an agent that acts: it runs in its own cloud VM with a browser, connects to your email and calendar, and completes tasks such as booking or buying, asking for approval before sensitive steps. Muse is a separate app and subscription.
Where to go from here
If Muse has made you wonder what the business version of this looks like, that is the question QX Agents were built to answer: agents with scoped access to your real tools, grounded in your own documents, gated by approvals where actions are irreversible, and reachable from Slack, Teams, WhatsApp, or email. Start free with every feature included, or book a demo and we will run one of your workflows live.
See what AI agents can do for your team
Deploy agents that can act across your data and 1,000+ apps.