- Meta launched Muse on September 8, a personal AI agent for US users on iOS, Android, and muse.ai, with support for its AI glasses coming next.
- Each user's tasks run inside a dedicated Muse Secure VM, and a separate Sentinel agent must approve actions before Muse can touch the open internet, while stored passwords and payment details stay hidden from the model.
- Pricing is free for most everyday use, with a Power plan at $20 a month and a Maximum plan at $100 a month.
Meta's Muse books travel, shops, and negotiates bills from one agent
Meta introduced Muse on September 8, describing it as the first personal AI agent built for everyone. It is available now in the United States on iOS, Android, and at muse.ai, with support for Meta's AI glasses promised soon. Unlike a chatbot that answers questions, Muse is designed to carry out multi-step tasks on a person's behalf, from booking travel and completing checkout to negotiating a bill, filling out forms, adjusting a training plan, and building a grocery list from a recipe reel saved on Instagram. It runs on Muse Spark, Meta's most capable model to date, works either in a standalone app or directly inside WhatsApp, and pays through Link built by Stripe with a one-time virtual card so a person's real card details stay hidden.
The product sits inside Meta's wider agent push. In August the company shipped Muse Glimmer, an open-weight agentic model, and the consumer agent now carries the same brand into a mass-market product. It also lands in the same season that OpenAI moved ChatGPT from answering to doing, which makes Muse Meta's entry in a race to own the agent that acts, not just the one that talks.
Meta led its announcement with the architecture rather than the features.
Muse is a personal AI agent that proactively helps you with your goals and tasks, not just answers questions. Every Muse runs in its own secure virtual machine, isolated from other users, and a separate Sentinel agent must approve any action before Muse can access the internet on your behalf.Meta, "Introducing Muse," September 8, 2026
Why Meta is leading with security for an agent that spends your money
The design choices answer an obvious worry. An agent that can shop, pay, and sign forms is also an agent that can be tricked into doing those things, a risk the industry watched play out when OpenAI's public agents went off script. Meta's response is containment. Muse holds credentials in a store the model itself cannot read, routes every outward action through the Sentinel approval gate, and keeps an audit trail the user can inspect. A future Muse Confidential VM will add end-to-end encryption with a key held only by the user.
The harder problem is not technical, it is trust. Meta is asking users to hand an agent their logins, cards, and calendars at the same time the company is still living down a $5 billion FTC privacy settlement and the Cambridge Analytica era. The security scaffolding around Muse is real, and it is also a tell. Meta knows that the barrier to a personal agent is not whether it can complete the task, but whether people believe it will do so without quietly turning their data into another advertising signal.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.