Meta launches Muse at a moment when the company can least afford a trust misstep. Introduced on September 8, 2026, Muse is Meta’s most ambitious consumer AI product yet. It is designed to do more than chat. The AI agent can complete tasks such as booking travel, managing email, negotiating bills, and making purchases for users.
The launch comes less than two weeks after Meta agreed to an $18 billion multistate settlement over social media’s impact on children. This creates a high-stakes test for the company. Users must decide whether they are willing to give Meta deeper access to their digital lives.
What Muse Actually Does
Unlike a typical chatbot that waits for a prompt and gives an answer, Muse is built to keep working in the background after a conversation ends, returning only when it needs approval to proceed. It can send emails, book flights and hotels, comparison-shop, and pursue longer-term goals across multiple steps, the kind of multi-stage work that previous AI assistants mostly couldn’t handle on their own. Users interact with it through a chat-style interface, can name it, give it an avatar, and customize how it communicates. It’s designed to work the way people already message each other, functioning both inside a standalone Muse app and directly within WhatsApp.
The agent is powered by Muse Spark 1.3, a new model from Meta Superintelligence Labs built specifically for long-horizon agentic work, things like calling command-line tools, juggling multiple task threads at once, and correcting its own mistakes when pulling information from messy sources. Meta says the model is close to state-of-the-art in resisting prompt injection attacks, a growing concern for any AI system given the ability to take real-world actions.
The Security Model Behind the Agent
Because Muse can touch email, calendars, payment methods, and even health-related services, Meta has put unusual emphasis on its security architecture. Each user gets a dedicated cloud virtual machine, called Muse Secure VM, where the agent, its browser, and all credentials are isolated from the rest of Meta’s systems. The agent itself runs inside a restricted execution environment with limited system access, while a separate oversight system called Sentinel reviews every action Muse proposes at both the network and application level, before deciding whether to allow it, block it, or send it to the user for manual approval.
Meta AI chief Alexandr Wang has stressed that the agent “never sees your actual passwords or payment details,” and that permissions can be scoped narrowly, read-only access, single transactions, or time-limited windows. Signal co-founder Moxie Marlinspike contributed to the data-separation design, lending some outside credibility to Meta’s privacy claims. Even so, internal employee testing reportedly surfaced real flaws, including cases of private data exposure and inconsistent behaviour, a detail that has already fueled skepticism about how ready the system is for wide use.
Pricing and Rollout
Muse launched with a free tier and two paid subscriptions. The plans cost $20 and $100 per month, depending on usage needs. Wang has said that most people should be able to use the free tier. The paid plans are mainly designed for heavy users who need additional computing resources.
Meta says Muse currently has no advertising. However, the company is exploring commerce as a future revenue stream. This could include in-app purchases.
Muse is initially rolling out in the United States. It is available on iOS, Android, and the web. International expansion is expected to follow a phased rollout similar to previous Meta AI features.
Conclusion
Muse represents the clearest signal yet of where Meta wants its enormous AI infrastructure spending to go. Mark Zuckerberg has described “personal agents” as the foundation of Meta’s next wave of products and revenue. Muse is the first concrete consumer product built around this idea.
Muse is also deeply integrated with WhatsApp, which has billions of users. This gives Meta a major distribution advantage over rivals such as OpenAI, Google, and Perplexity. It could also push competitors toward similar messaging-based AI agent strategies.
But the core tension remains unresolved. Muse asks users to give an AI system greater access to their personal and financial lives. This comes at a time when public trust in Meta is already strained.
Muse’s success may depend on more than its technical capabilities. Users must also trust Meta’s security promises. That trust may be difficult to rebuild after previous privacy concerns.
