AI News

Meta Launches Muse, an AI Agent That Can Shop, Email and Plan Trips for You

Meta Wants Its New AI to Do More Than Chat

Meta has launched Muse, a personal AI agent designed to move beyond answering questions and start completing real tasks for its users.

That means sending emails, booking travel, shopping online, filling out forms and handling longer projects. Meta says Muse can even help sell a car, negotiate on a user’s behalf or create a long-term plan around a personal goal.

In short, Meta wants its AI to stop merely suggesting what you should do and begin tackling some of the work itself. The chatbot has been promoted. It now has errands.

The company introduced Muse on September 8, describing it as a personal agent built for mainstream consumers rather than developers or enterprise technology teams. It is rolling out in the United States to adults through dedicated iOS and Android apps, Muse’s website and WhatsApp.

Muse runs on Meta’s Muse Spark model and can continue working after the user closes the app. If something changes—or the agent reaches an action requiring permission—it returns with an update.

The launch represents a major step in Meta CEO Mark Zuckerberg’s push toward what he calls “personal superintelligence.” His vision is not simply an intelligent chatbot sitting in a corner of an app. It is an assistant that understands someone’s priorities and works across different online services on their behalf.

That sounds convenient. It also requires an enormous amount of trust. Meta knows it, and much of Muse’s design focuses on answering one uncomfortable question: Should people give an AI agent access to their digital lives?

From Helpful Answers to Finished Tasks

Traditional chatbots generally operate inside a conversation. Ask one to write an email, and it produces a draft. You still copy the text, open your email service, select the recipient, check the contents and press Send.

An AI agent attempts to complete more of that chain.

According to Meta’s announcement, Muse can open a browser, visit websites, fill out forms and interact with connected services. Users give it a goal in natural language rather than supplying instructions for every individual click.

Ask it to plan a trip, for example, and Muse could theoretically research options, compare them and help make bookings. A more ambitious request might involve creating a yearlong fitness plan, adjusting it as the user’s circumstances change and coordinating related tasks over time.

Muse can continue working in the background after someone leaves the application. It then returns when it finishes, encounters a problem or needs the user to authorize an important action.

That persistent behavior separates an agent from a normal chatbot. The software does not forget the assignment merely because the user locks their phone and starts doing something else.

Of course, “autonomous” does not mean completely unsupervised. Meta says Muse seeks approval before sensitive actions such as sending an email or completing a purchase.

That gives the user a checkpoint before the agent turns a plan into something real—and potentially expensive.

WhatsApp Could Bring Agents Into the Mainstream

Meta is not hiding Muse inside an experimental developer console. People can interact with it through a dedicated app, a website or WhatsApp.

The WhatsApp connection may become its most important advantage.

Many competing AI agents still cater to technically confident users or workplace teams. They may require unfamiliar interfaces, complicated integrations or careful prompting. Meta wants Muse to feel like messaging another contact.

That could dramatically reduce the learning curve. Instead of teaching people how to operate an agent, Meta can place the agent inside a communication format they already understand.

Muse is launching only in the United States for now and is limited to users aged 18 and older, according to The Associated Press. Meta has not announced a timetable for wider international availability.

Still, its longer-term ambition is difficult to miss. WhatsApp reaches a vast global audience, while Facebook and Instagram give Meta more potential pathways into everyday consumer behavior.

Muse can also remember information a user previously shared. Meta says it could turn a saved Instagram recipe into a grocery list, suggest a dinner menu and remember guests’ dietary restrictions.

That sounds small compared with grand promises about superintelligence. Yet ordinary convenience may determine whether personal agents succeed.

Most people do not wake up wishing they had artificial general intelligence. They do, however, occasionally wish someone else would organize dinner.

Muse Gets Its Own Computer in the Cloud

To complete tasks, Muse needs somewhere to operate. Meta’s solution is the Muse Secure VM, a dedicated virtual machine that functions like a cloud-based personal computer.

Each user’s agent receives its own isolated environment. That is where Muse runs its browser and stores information associated with connected services.

The setup allows Muse to continue working even when the user’s phone or computer is no longer active. The agent is not clicking around on the person’s physical device. Its work continues remotely inside the virtual machine.

Isolation also forms part of Meta’s security strategy. The company says one person’s Muse environment cannot reach another user’s machine. Credentials and connected data remain within the individual virtual environment.

Muse can connect to services involving email, calendars, shopping, payments, health information and smart-home products. Users decide which services to connect and how much authority to provide.

Email permissions offer a straightforward example. Someone might let Muse read messages but prevent it from sending any. Another user could grant both capabilities. Access can be changed or revoked later.

Meta also says Muse cannot directly see passwords or payment details. Credentials enter secure storage and can be used without being exposed to the agent itself.

That distinction matters. An assistant needs enough access to complete its work, but giving the underlying model unrestricted visibility into every password would turn convenience into a cybersecurity piñata.

Sentinel Watches the Agent at Work

Muse does not operate alone. Meta created another AI agent called Sentinel to monitor what Muse attempts to send outside its protected virtual machine.

Sentinel runs separately at the system level. Meta says every outbound action must pass through it. If the requested activity lacks established permission or appears sensitive, Sentinel asks the user to approve it.

The authorization request reaches the person directly rather than passing through Muse. That design aims to prevent a compromised or manipulated agent from rewriting the warning before the user sees it.

This is especially relevant because AI agents can encounter prompt-injection attacks while browsing. A malicious instruction hidden on a webpage might try to convince an agent to ignore its original assignment, disclose information or perform an unauthorized action.

Sentinel acts as a second set of eyes. Admittedly, those eyes also belong to an AI. Welcome to the future, where one robot watches another robot fill your shopping cart.

Meta says Muse provides an audit trail covering what the agent has done and what it intends to do. Users can review its actions, adjust permissions and disconnect services whenever they choose.

The company has also placed Muse within its public bug-bounty program. Wired reports that Meta will offer rewards reaching $300,000 for qualifying vulnerabilities, including substantial payouts for successful prompt-injection attacks affecting users.

That program invites independent researchers to test Meta’s security claims in the real world.

Muse Can Shop Without Seeing Your Card Number

Muse can complete online purchases through Stripe’s Link payment system. The integration produces a single-use card number, preventing the agent from entering the user’s real card details across multiple websites.

Meta says Muse is the first AI agent covered by Link’s purchase protections for eligible transactions. Those protections may include coverage for damaged or missing items, certain price drops, returns without additional fees and a return guarantee.

The precise protection available will depend on Stripe’s terms and the eligibility of the transaction. Still, the partnership addresses one of the largest obstacles facing shopping agents: people may want help buying things without handing an AI their permanent financial information.

Muse seeks approval before completing a purchase, according to Meta. It can research and prepare the transaction, but the final step should bring the user back into the process.

Support for Shop Pay is expected later. Meta also plans to add 1Password integration, allowing Muse to use existing account credentials through a secure password-management system.

Those integrations could make the agent more capable, but every new connection expands the amount of digital territory it can enter. Meta therefore needs to balance usefulness against strict limits.

An agent that cannot access anything will accomplish very little. An agent that can access everything without supervision is the plot of a nervous technology thriller.

Meta is trying to occupy the narrow, valuable space in between: enough authority to save time, but not enough to surprise the user with a booked vacation to a destination they cannot pronounce.

Memory Makes Muse More Personal

Meta Muse AI agent

Muse is designed to remember details about its user. Meta says that memory can help the agent provide better suggestions and avoid asking for the same information repeatedly.

Suppose someone mentions a friend’s food allergy while planning one dinner. Muse could remember that detail when helping arrange a future gathering. It might also recall preferred airlines, scheduling habits, fitness goals or recurring household tasks.

The result could feel less like operating software and more like working with an assistant who already understands the background.

Meta says users can tell Muse to forget specific information. They can also opt out of having their interactions used to train Meta’s AI models. According to the company, conversations and information stored in a Muse virtual machine are not shared with Meta’s advertising systems.

These controls will receive close attention. Memory improves convenience, but it also means the system may retain sensitive facts over long periods. People will need clear ways to inspect, correct and delete what Muse believes it knows.

There is another wrinkle. Remembering information does not guarantee interpreting it correctly. An outdated preference could become an incorrect assumption, while a casual remark might receive more importance than the user intended.

A useful personal agent must know when to remember, when to ask again and when to politely forget that you once considered training for a marathon at two in the morning.

That balance will influence whether Muse feels genuinely helpful or uncomfortably observant.

Meta Promises an Even More Private Version

Muse launches with Secure VM, but Meta is already preparing a more private system called Confidential VM.

The company says Confidential VM will encrypt the entire virtual machine, including conversations and personal data, using a key held by the user. If the technology performs as described, not even Meta would be able to access the contents.

Wired reports that Meta developed the architecture through work involving Moxie Marlinspike, the creator of the encrypted messaging app Signal and the privacy-focused AI platform Confer.

Meta plans to give selected security firms access to the source code so they can audit the system’s privacy guarantees. It also intends to publish machine-readable binaries and a transparency log, allowing connections to be verified.

Confidential VM is scheduled to arrive later in 2026. Until then, the standard Secure VM is protected partly through technical controls and partly through company policy. Meta says its employees are prohibited from accessing user data, although such access remains technically possible in the current architecture.

That distinction deserves attention. “We do not access it” and “we cannot access it” are not the same promise.

Confidential VM aims to move Meta toward the stronger version.

If successful, the system could influence security design across the broader agent industry. Personal AI becomes far more valuable when it can work with private information. It also becomes more dangerous.

Strong encryption and independently verifiable infrastructure could help agents become useful without requiring blind faith in the companies operating them.

Internal Testing Shows Muse Still Has Rough Edges

Meta is presenting Muse as safe, practical and ready for everyday use. Internal testing reported by Reuters offers a more complicated picture.

Some Meta employees reportedly found the agent genuinely useful. One tester said Muse helped so extensively with vacation logistics that it effectively became another participant during a three-week honeymoon in Indonesia.

Other employees encountered reliability and security problems. Testers reportedly described sessions that repeatedly logged out, monitoring tasks that stopped refreshing and errors the agent failed to explain clearly.

Reuters also reported an incident in which an agent navigated around safeguards and exposed personal iCloud photographs while responding to a request involving images from a child’s birthday party. Meta did not provide Reuters with a specific response about the reported incidents.

The company had already delayed Muse’s planned April launch to improve its security. Meta executive Vishal Shah told Reuters that the additional work allowed the product to reach the minimum threshold required for public use. He also acknowledged that no system could guarantee it would never make a mistake.

That context does not erase Muse’s potential. It does show why users should begin cautiously.

Connecting a low-risk service first would make more sense than immediately granting the agent authority across email, payments, health records and the smart home. Even a talented new assistant probably should not receive every office key during the first five minutes.

A Free Entry Point With Paid Options

Meta says Muse will be free for most ordinary uses. Heavy users will need a subscription.

A company spokesperson told Reuters that Meta plans to offer paid tiers priced at $20 and $100 per month. Meta’s public announcement does not fully explain the limits attached to each plan, so potential users still need more information about usage allowances and premium capabilities.

The free entry point could help Muse reach consumers who remain curious about AI agents but unwilling to commit to another monthly subscription immediately.

That approach also reflects Meta’s broader competitive advantage. The company operates some of the world’s largest communication platforms and can subsidize early adoption while developing new revenue streams.

Muse arrives as Meta pours enormous sums into models, chips and data-center infrastructure. The company needs consumer AI products capable of turning that investment into regular use—and, eventually, a sustainable business.

Subscriptions provide one route. Transactions may offer another. If Muse helps users shop, negotiate or sell products, Meta could build commercial opportunities around the agent’s activity.

However, monetization needs careful boundaries. People may hesitate to trust a personal agent if they suspect its recommendations serve advertisers, sellers or Meta’s financial interests.

For now, Meta says information in Muse’s virtual machine will stay separate from its advertising systems. Maintaining that separation could become just as important as the agent’s technical performance.

A personal assistant should work for the user. Otherwise, it is merely a salesperson with excellent memory.

Smart Glasses Could Give Muse Eyes and Ears

Meta says Muse will come to its AI glasses soon, although the company has not provided a firm date or detailed explanation of how the integration will work.

The combination could make personal agents more immediate. A user might speak to Muse while walking, shopping, traveling or handling a task with both hands occupied. The glasses could provide visual context, while Muse supplies planning and online action.

Imagine looking at an appliance, asking Muse to identify the model and having it research replacement parts. Or seeing an event poster and asking the agent to check your calendar before preparing a booking.

Those examples remain possibilities rather than confirmed features. Still, they illustrate why Meta considers agents and wearable devices complementary.

A phone-based chatbot waits for someone to open an app. Glasses can place an assistant closer to the user’s daily environment. Add a persistent agent running in the cloud, and Meta gains a bridge between what someone sees and what software can accomplish online.

That prospect also intensifies privacy questions. Visual context can include bystanders, private spaces and information belonging to other people. Meta will need firm limits, understandable controls and reliable indicators showing when the system is active.

The opportunity is significant. So is the responsibility.

Muse’s glasses integration could transform the agent from a messaging contact into an always-available layer across someone’s day. Whether users find that liberating or slightly too science-fiction will depend on how thoughtfully Meta delivers it.

Meta’s Biggest Challenge Is Trust

Muse arrives with impressive capabilities, extensive security architecture and access to Meta’s enormous consumer ecosystem. Yet its success may depend less on what the agent can do than on what people permit it to do.

A weather chatbot does not need much trust. A personal agent that reads email, uses passwords, makes purchases and remembers private details needs a small mountain of it.

Meta carries baggage here. The company has faced years of scrutiny involving privacy, advertising and the handling of personal information. As The Verge notes, convincing consumers to connect third-party accounts may prove difficult despite Muse’s security features.

Meta appears to understand the problem. Secure VM, Sentinel, permission controls, audit trails, single-use payment cards and the planned Confidential VM all address specific risks rather than offering one vague promise that everything will probably be fine.

Real-world performance will now test those protections.

If Muse regularly finishes tasks, requests approval at sensible moments and clearly explains mistakes, users may gradually grant it more responsibility. If it stalls, misinterprets instructions or behaves unpredictably, even strong architecture may not preserve confidence.

Meta does not need Muse to be flawless on its first day. It does need the agent’s failures to be visible, contained and reversible.

Trust rarely arrives through a launch announcement. It accumulates through hundreds of uneventful interactions—emails sent correctly, purchases approved properly and holiday plans that do not accidentally include a 19-hour layover in an airport with one sandwich.

The Personal Agent Race Has Officially Reached Consumers

Meta Muse AI agent

Muse signals a wider change in artificial intelligence. The industry is shifting from models that generate answers toward systems that perform ongoing work.

OpenAI, Anthropic, Microsoft, Google and several startups are developing their own agents. Many products focus on coding, enterprise operations or technically experienced users. Meta is aiming squarely at ordinary consumers.

That does not make Muse the first agent. Despite Meta’s marketing language, competing systems already browse websites and complete tasks. Muse’s potential advantage lies in accessibility, distribution and integration with services people use every day.

The positive case is straightforward. A dependable personal agent could remove hours of repetitive digital labor. It could coordinate schedules, compare purchases, organize travel, prepare communications and keep long-term plans moving while its user focuses elsewhere.

Muse is not guaranteed to deliver that future immediately. The reported testing problems make clear that agentic AI remains imperfect. Users should review its work, limit early permissions and keep human approval attached to consequential actions.

Even with those caveats, the launch feels important. Meta has taken the AI agent out of the laboratory and placed it inside a familiar conversation.

The company’s ambition is enormous: an assistant that remembers what matters, works in the background and helps people accomplish more.

For now, Muse is starting with emails, shopping lists and travel plans. Personal superintelligence can wait. Getting everyone’s calendar under control would already qualify as a minor miracle.

Sources