AI Newsway

Meta's Muse Agent Wants Your Inbox, Your Calendar and Your Credit Card

A free tier, $20 and $100 plans, and a virtual machine Meta says never sees your passwords.

|5 min read0
AI Summary
Meta launched Muse on September 8, 2026, a personal AI agent that connects to a user's email, calendar, payments and everyday apps to complete multi-step errands such as booking travel, filing forms and making purchases through Link by Stripe. It runs on the Muse Spark model across the web, iOS, Android and WhatsApp in the US, with a free tier plus $20 and $100 monthly plans. Meta says the agent runs in an isolated virtual machine that never sees passwords or payment credentials.
A smartphone app in use; Meta's Muse agent launched on iOS, Android, the web and inside WhatsApp chats for US users.
A smartphone app in use; Meta's Muse agent launched on iOS, Android, the web and inside WhatsApp chats for US users.

Meta launched Muse on September 8, a personal AI agent that connects to a user's email, calendar, payment methods and everyday apps in order to complete multi-step errands on their behalf. It is the company's largest consumer AI bet so far, and it arrives less than two weeks after Meta agreed to an $18 billion multistate settlement over social media harms.

Key takeaways

  • Muse is live in the US on the web, iOS, Android and inside WhatsApp chats, with Meta's AI glasses to follow.
  • Pricing is a free tier plus two paid plans, Power at $20 a month and Maximum at $100 a month, and a payment card is required even to start on the free tier.
  • Meta says Muse runs inside a dedicated virtual machine with its own browser and never sees a user's passwords or payment credentials.

What Muse actually does

The pitch is execution rather than conversation. Meta describes an agent that sends emails, books travel, fills out forms, negotiates lower bills, builds plans, turns a recipe reel into a grocery list, issues party invitations and completes purchases through Link by Stripe. Shop Pay and 1Password integrations are listed as coming soon.

It runs on Muse Spark, Meta's latest model, and ships with built-in connectors for a set of common services. Users opt in to each connection one at a time rather than granting blanket access. Where a service Meta has not integrated exposes a public API, Muse can wire up a connection using credentials the user supplies; where there is no API at all, it falls back to driving a browser. The agent keeps working after the app is closed, and Meta says it will learn from conversations over time and begin making unprompted suggestions.

Users can name the agent, pick its avatar and tune how it communicates β€” a deliberate attempt to make an AI agent with deep account access feel like a familiar assistant rather than a process running somewhere in Menlo Park.

How Meta is framing the security question

The architecture Meta published alongside the launch is the more interesting part. According to the company's Muse overview, the agent operates inside what it calls Muse Secure VM, a dedicated environment with its own browser. A separate process, Sentinel, runs on the same virtual machine but is isolated from Muse at the system level. Meta's stated result is that Muse has no visibility into passwords or payment methods, and that conversations and agent data are not shared with its advertising systems. Meta AI chief Alexandr Wang has described the arrangement as an isolated environment that never sees actual credentials.

Those are claims, not audits. Security researchers have not yet had time to probe the boundary between Muse and Sentinel, or to test what a prompt-injection attack reaches when the agent is mid-checkout in a browser session.

Whether consumers will hand over the keys

Meta's harder problem is history, as TechCrunch noted in its launch coverage. The company settled with the FTC in 2011 over making private information public, paid a then-record $5 billion penalty in 2019, was charged with violating that same privacy order in 2023, stored user passwords in readable form, and remains the defendant of record in the long tail of Cambridge Analytica. A New Mexico judgment over child safety ran to $942 million.

An agent that books flights and pays for them requires more trust than a feed ever did, and Meta is asking for it at an awkward moment.

Outlook

Muse lands in a crowded field. Gemini Spark and Claude Cowork are chasing the same consumer-agent slot, and the underlying plumbing problem β€” how an AI assistant holds state across long-running, multi-service tasks β€” is the same one driving recent changes to the Model Context Protocol. Distribution through WhatsApp is Meta's genuine edge here. Whether that is enough to overcome the trust deficit is the question the next two quarters will answer.

FAQ

Is Meta Muse free?

There is a free tier, but it is metered and Meta requires a payment card to get started. Paid plans are Power at $20 a month and Maximum at $100 a month, and the app shows a usage meter plus a warning when free usage runs out.

Where can I use Muse?

Muse is available in the United States on the web, through iOS and Android apps, and inside WhatsApp chats. Meta says support for its AI glasses is coming, but has not given a date.

Can Muse see my passwords?

Meta says no. The agent runs inside a dedicated virtual machine called Muse Secure VM with an isolated Sentinel process, and the company states Muse has no visibility into passwords or payment methods. Independent security review of those claims has not yet happened.

How do you feel about this article?

SJ

Discussion

Sign in to post
Loading...

Related articles

Qwen3.8 Max Tops Artificial Analysis Agentic Index, Outranking Every US Lab but Two
LLM & Chatbots

Qwen3.8 Max Tops Artificial Analysis Agentic Index, Outranking Every US Lab but Two

Alibaba's Qwen3.8 Max leads the Artificial Analysis agentic index, winning through long-horizon persistence rather than top reasoning scores.

Seung Jung41 days ago
Grok Bot Lets AI Agents Run Their Own Group Chat β€” and Sign Into Your Accounts
LLM & Chatbots

Grok Bot Lets AI Agents Run Their Own Group Chat β€” and Sign Into Your Accounts

SpaceXAI opened a Grok Bot beta where multiple agents coordinate in group chats, assign ownership to each other, and sign into a user's own accounts.

Seung Jung33 days ago
Gemini 3.7 Flash Arrives Three Weeks After 3.6 - At Half the Price
LLM & Chatbots

Gemini 3.7 Flash Arrives Three Weeks After 3.6 - At Half the Price

Google's Gemini 3.7 Flash lands three weeks after 3.6 Flash, scoring 65.3% on DeepSWE and shipping at half the price through the end of 2026.

Seung Jung34 days ago
OpenAI Drops Message Caps on ChatGPT's Free Tier and Hands It a Think Button
LLM & Chatbots

OpenAI Drops Message Caps on ChatGPT's Free Tier and Hands It a Think Button

OpenAI is lifting message caps on ChatGPT's free tier and adding a Think button, with GPT-5.6 Luna becoming the default for Free and Go users.

Seung Jung41 days ago
Anthropic Gives Claude and Cowork a Single Shared Memory
LLM & Chatbots

Anthropic Gives Claude and Cowork a Single Shared Memory

Anthropic merged Claude and Cowork memory into one shared store, on by default for Free, Pro and Max users, with no option to keep the two products apart.

Seung Jung22 days ago
GPT-6 Astra Goes to Work: OpenAI's Priciest Model Bets Everything on Computer Use
LLM & Chatbots

GPT-6 Astra Goes to Work: OpenAI's Priciest Model Bets Everything on Computer Use

OpenAI has begun rolling out GPT-6 Astra to business customers, framing its newest frontier model less as a chatbot and more as a worker that operates software...

Seung Jung7 days ago