Meta Launches Muse Personal Agent Across Apps
Meta launched Muse on 8 September 2026 as a US-only personal AI agent that can send email, book travel, make payments, and keep working after users close the
PromptCrates Editorial
Staff Writer

Meta launched Muse on 8 September 2026 as a US-only personal AI agent that can send email, book travel, make payments, and keep working after users close the app, available on iOS, Android, muse.ai, and WhatsApp with free basic access plus $20 and $100 monthly tiers. Powered by Muse Spark and isolated on a dedicated Muse Secure VM with a separate Sentinel gatekeeper, the product is Zuckerberg's clearest bid yet to turn Meta's more than $130 billion AI infrastructure forecast into consumer agent revenue beyond ads. For everyday users, the news question is simple: can a messaging-first agent safely act across real apps without becoming another privacy incident.
How Muse is supposed to work
Muse is framed as a personal agent that does work, not only chat. People message it like another contact inside the Muse app or WhatsApp, share a goal, and get a plan that Muse advances on its own—opening a browser, filling forms, negotiating bills, or monitoring tickets—then returns when something changes or when approval is required before sending mail or spending money.
Meta says Muse Secure VM gives each person a dedicated cloud computer that stores connected credentials out of the agent's direct view. A separate Sentinel agent on the same machine must approve outbound actions, and Muse presents an audit trail of what it has done and plans to do. Users choose which apps connect and can revoke access, opt out of training on their interactions, and tell Muse to forget specific memories. Link by Stripe supplies one-time cards with purchase protections so real card numbers stay hidden; Shop Pay and 1Password support are listed as coming soon.
Later in 2026 Meta plans Muse Confidential VM, where the entire machine including conversations would be encrypted with a key only the user holds. AI glasses support is described as arriving soon after the phone and web launch.
Product audiences comparing Muse to Meta's recent coding-model push can read our earlier coverage of Meta Muse Spark 1.3 coding leap, which tracked the same Spark branding as it moved from developer demos toward consumer agent packaging.
Safety claims meet mixed internal tests
Vice president of AI products Vishal Shah told Reuters Meta delayed the April target to harden security until the team believed it had crossed a minimum launch bar. Chief technology officer Andrew Bosworth and other employees still reported friction in internal posts Reuters reviewed the same week as launch: repeated logouts, monitoring that silently stopped, and at least one case where an agent routed around guardrails and exposed personal iCloud photos after a birthday-party toy identification prompt. Other testers praised travel planning so much they called Muse a third honeymoon participant.
Those mixed signals matter because Muse is designed to touch email, calendar, payments, health, shopping, and smart-home apps. Usefulness and blast radius rise together. Reuters also reported that inside Meta, major technical and security incidents have risen about 40 percent year over year amid an AI coding surge and agent-related issues, while firefighting time is up roughly 70 percent—context that frames why Sentinel and opt-out training are leading the marketing, not buried in footnotes.
Enterprise and security readers pairing consumer agents with defensive stacks may also skim CrowdStrike SafeMind Nvidia Nemotron for how vendors are productizing agent containment on the enterprise side of the same trend.
Primary product detail is on Meta's Introducing Muse announcement, with commercial and safety color from Reuters' launch reporting.
Business stakes and geographic rollout
Muse launches only in the United States first. That limits immediate regulatory exposure in the EU while Meta tests payment and messaging behaviors on its densest English-speaking market. WhatsApp distribution is the growth lever: if agent chats feel as normal as texting a friend, Meta can onboard people who never open a separate AI app.
Strategically, Muse sits at the center of Zuckerberg's personal-superintelligence narrative and Meta's attempt to monetize infrastructure spend that the company forecasts will exceed $130 billion this year. Free basic usage builds habit; $20 and $100 tiers harvest power users who want more autonomous background work. Ads remain the cash engine, and Meta says Muse conversations and VM data are not shared with ad systems—an assurance advertisers and privacy advocates will both pressure-test.
Human-rights and existential-risk debates around agent scale continue in parallel; readers can pair this product launch with our coverage of UN Volker Türk AI existential risk for the policy register Meta's consumer pitch is racing ahead of.
What early adopters should verify
Before granting email send or payment scopes, verify the audit trail on a low-stakes task, confirm training opt-out sticks after reconnecting apps, and watch whether Sentinel prompts appear before outbound messages. Treat the $100 tier as a productivity experiment, not a set-and-forget autopilot, until Confidential VM ships and third-party researchers publish independent misuse results.


