Meta Launched Muse: What Its Personal AI Agent Can Do—and What It Can Access
Muse can work in the background across connected services, but the consequential story is its permission architecture: a dedicated cloud computer, hidden credentials, a separate Sentinel, and explicit approvals.

Bottom line
Meta's Muse personal agent can browse, use connected apps, and complete approved transactions. Here is how access, credentials, privacy, pricing, and safeguards work.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 4 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 4
- Products covered
- 0
- Last checked
- 2026-09-11
Important limits
- • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
*This research-based analysis covers Meta's September 8, 2026 launch. Product capability, security, and scale statements are Meta's claims unless otherwise identified. Muse is new, so availability, subscriptions, integrations, and safeguards may change.*
The short answer
Meta Muse is a personal AI agent that runs in a dedicated cloud virtual machine and can work across connected services, browse the web, fill forms, send approved messages, and make approved purchases. It is rolling out in the United States on iOS, Android, the web, and WhatsApp. Meta says most use is free, but it has not published a complete subscription price table.
The important change is not that Muse can chat. It can keep working after a person closes the app, remember preferences, create connectors, and use credentials without exposing the underlying secrets to its main model. That broader authority makes its permission design, audit trail, recovery process, and real-world error rate more important than a polished demo.
What can Meta Muse do?
Meta describes tasks including email, scheduling, travel booking, web forms, research, negotiation, and longer-running personal projects. Muse can launch subagents and return when a task changes or needs approval. For checkout, Meta says Stripe Link can supply a one-time-use card and purchase protections for eligible transactions; Shop Pay and 1Password support are planned rather than launch-day guarantees.
Users should verify the exact connector and action available in their account. “Can use email” can mean read access, drafting, or permission to send; those are materially different grants. Start with read-only access and one low-consequence workflow before allowing writes or purchases.
How do the Secure VM and Sentinel work?
Each user's Muse operates in a dedicated Linux virtual machine. Meta says the agent runtime is isolated from credential storage and security-sensitive services. Real OAuth tokens remain outside the agent's runtime; a separate service inserts credentials only at an approved network boundary.
A host-side Sentinel is the permission authority for connector actions and outbound network requests. It can allow, deny, or pause an action for user approval. Meta says approvals can be one-time, session-scoped, task-scoped, time-bounded, or persistent, and that users receive an audit trail.
This is a serious defense-in-depth design, not proof that every action will be correct. Meta's own security explanation says Muse will still make mistakes and may encounter hostile instructions in the data it reads. Isolation can limit damage; it cannot turn an ambiguous request into reliable intent.
What are the privacy boundaries?
Meta says Muse conversations and VM data are not shared with its advertising systems, and users can opt out of having interactions used to train Meta's AI models. Users choose connected apps, can revoke access, and can ask Muse to forget remembered information. A planned Confidential VM would encrypt the entire environment with a user-held key, but Meta says that version is coming later in 2026, so buyers should not treat it as available now.
Before connecting a primary inbox, calendar, home system, vehicle, or payment method, verify retention, deletion, export, support access, telemetry, incident notice, regional availability, and what happens to stored data after disconnecting. Privacy promises and security architecture answer different questions; both matter.
How should people evaluate Muse safely?
Use a staged test. First connect a low-risk account with read-only permissions. Give Muse ten representative tasks containing ambiguous instructions, outdated pages, misleading emails, and a request that should trigger approval. Record whether it chooses the right account, preserves constraints, cites evidence, asks at the right time, and leaves a usable audit trail.
Then test cancellation, revocation, duplicate actions, refunds, interrupted sessions, and recovery after a connector fails. Never use a consequential transaction as the first trial. A personal agent earns broader authority through observed reliability, not through the number of integrations on its launch page.
The verdict
Muse is one of the clearest attempts yet to make an action-taking personal agent usable outside a developer sandbox. Its dedicated VM, separated credential handling, network gate, scoped approvals, and audit trail address real agent risks more concretely than a generic “human in the loop” promise.
The architecture reduces exposure; it does not remove judgment errors, prompt injection, or the cost of a wrong action. Start read-only, keep approvals narrow, inspect the audit trail, and expand access only after Muse succeeds on your own failure cases.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
What is Meta Muse?
Muse is Meta's personal AI agent. It runs in a dedicated cloud virtual machine and can use approved connected services, browse, fill forms, send messages, and complete approved purchases.
Is Meta Muse free?
Meta says most Muse use is free and that subscriptions will support heavier use, but its launch announcement does not publish a complete price table. Check the product before relying on a specific allowance or price.
Can Meta Muse see passwords and payment details?
Meta says the main Muse agent does not see real passwords, OAuth tokens, or payment details. Separate credential services and the Sentinel insert approved credentials at the network boundary, but users should still grant the least access necessary.
Does Meta use Muse conversations for advertising or AI training?
Meta says Muse conversations and VM data are not shared with its ad systems. It also says users can opt out of interactions being used to train Meta AI models; verify the current settings and policy in your account.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Read next
