Meta has launched Muse, a personal AI agent that can browse the web, fill out forms, send emails, and make purchases on a person’s behalf. The agent is rolling out now in the US on Android, iOS, and muse.ai, with support for Meta’s AI glasses “coming soon,” according to Meta’s own newsroom announcement.
Unlike a chatbot that answers questions, Muse is built to act. Meta describes it plainly: “Muse is a personal AI agent. It doesn’t just answer questions, it actually does the work.” It can keep working after a person closes the app, and it comes back later when something changes or when it needs approval for a sensitive step, like sending an email or completing a purchase.
What Muse can actually do
Muse runs on something Meta calls Muse Secure VM, a dedicated virtual machine that holds both the agent and a person’s connected data. It is powered by Muse Spark, described as Meta’s most capable model to date, and it works inside the Muse app or directly through WhatsApp.
- Task handling: booking travel, replying to emails, scheduling events, and negotiating on a person’s behalf
- Goal planning: turning a stated long-term goal into a plan and then advancing the work on its own over time
- Shopping and payments: checking out using Link, a Stripe-built agent wallet that generates a one-time-use card so a person’s real card number is never exposed; Shop Pay and 1Password support are listed as “coming soon”
- Memory: recalling details a person mentioned only once, such as turning a saved recipe into a grocery list or remembering a guest’s dietary restrictions before sending dinner invites
Meta’s privacy claims, and where they stop short
Meta is leaning hard on security in its pitch. A separate “Sentinel” agent is supposed to run alongside Muse at the system level, and Meta says nothing Muse does reaches the internet unless Sentinel approves it. Muse is also designed to never see a person’s actual passwords or payment details directly; credentials go into secure storage instead.
On data use, Meta states: “Muse doesn’t share a person’s conversations or the data in their VM with Meta’s ad systems.” That is a narrower promise than it might sound. It rules out one specific use, advertising, but says nothing about other internal uses. Meta separately confirms that people “can also opt out of their interactions being used to train Meta’s AI models” — phrasing that implies training use is the default unless a person actively turns it off. Later this year, Meta plans a “Muse Confidential VM” tier where a user’s own encryption key locks out even Meta itself, but that protection does not exist yet for anyone using Muse today.
“Each person stays in control of their Muse and decides how much access it gets.” — Meta
That control is real on paper: people choose which apps Muse connects to and how much each one can do, and they can revoke access at any time. But an agent that can open a browser, fill out payment forms, and send emails unsupervised between approvals is also a meaningfully bigger trust ask than any assistant feature Android or iOS users have granted an app before.
Pricing and Availability
Muse is rolling out now in the US on iOS, Android, and muse.ai. Meta says it is “free for most of what people need, with subscription plans for people who want to do more,” without detailing what sits behind the paid tiers. There is no announced timeline for expansion beyond the US.
Anyone trying Muse should treat the free tier as intentionally limited rather than assume it covers everything the announcement demonstrates — Meta hasn’t said where that line falls.







