Meta Launches Muse, a Personal AI Agent That Can Shop, Book Reservations, and Send Emails

Meta has launched Muse, a personal artificial-intelligence agent designed to do more than answer questions. The company says Muse can browse the web, fill out forms, book travel and appointments, send emails, make purchases, create documents, monitor selected information, and continue working after a user closes the app.1Ā 2
Ā
The launch took place in the United States on September 8, 2026. Muse is available through a dedicated app for iOS and Android, through the Muse website, and through WhatsApp. Meta says access will come to its AI glasses in the future. The initial product is aimed at adults aged 18 and older, according to reporting from the Associated Press published by PBS NewsHour.3
Ā
The central change is not the chat interface. It is the handoff of digital work. A conventional chatbot may draft an email or suggest a restaurant. Muse is intended to carry out the next steps: open a browser, compare options, enter information, request approval, and complete the task when the user authorizes it.
Ā
āMuse is a personal AI agent. It doesnāt just answer questions, it actually does the work.ā ā Meta1
Ā
What Muse can do
Meta presents Muse as an agent for both small errands and longer projects. A user could ask it to reserve a table, book a trip, prepare a shopping list, or handle an email. The company also describes broader goals, such as creating an exercise plan, coordinating resources for a project, or helping organize the process of selling a car.1
Ā
The system can connect to services that a person already uses, including email, calendars, Instagram, and other applications. Meta says users decide which connections are enabled and what each service allows. Email access, for example, can be configured for reading, sending, or both.1Ā 2
Ā
Muse can also work proactively. If a person asks it to monitor prices, weather, or another changing condition, the agent may continue checking in the background and return when there is an update. Metaās product page says the agent can track goals, manage reminders, and suggest ideas based on information the user has shared.2
Ā
Shopping is a particularly important part of the launch. Meta says Muse can complete purchases through Link, Stripeās payment service for this use case. Link generates a one-time card number so the agent and merchant do not receive the userās real card details. Meta also says eligible purchases have access to Linkās purchase protections. Shop Pay and 1Password support are planned additions.1
Ā
These capabilities make Muse closer to a delegated operator than a writing assistant. The user describes the desired result, while the system chooses and executes a sequence of actions. That convenience also creates a higher standard for accuracy. A wrong sentence in a draft is inconvenient. A wrong reservation, purchase, or message can create a financial or personal consequence.
Ā
How the agent is supposed to stay under control
Meta says Muse runs inside Muse Secure VM, a dedicated virtual machine with its own browser. The userās data, connected credentials, and the agentās activity are kept in that environment. A separate Sentinel system monitors what leaves the virtual machine and can stop an action or ask the person for permission.1
Ā
The company says Muse cannot see the passwords or payment methods stored for connected services. The credentials are placed in protected storage, allowing the browser to use them without exposing them to the model. Muse is also designed to request approval before sensitive actions, including sending an email, making a purchase, or sharing information with another service. Users can review an audit trail of completed and planned actions.1Ā 2
Ā
Metaās design has a useful principle: the agent should not be the sole judge of whether an action is safe. WIRED reports that approval prompts are presented directly to the user rather than being filtered through the model. That separation is intended to reduce the effect of prompt-injection attacks, in which untrusted web content tries to manipulate an agent into ignoring its instructions.4
Ā
The safeguards should still be understood as claims about an evolving product rather than proof that every failure mode has been eliminated. WIRED reports that Secure VM is isolated and governed by policy, but not technically inaccessible to Meta under the initial design. Meta plans a later Confidential VM in which the user controls the encryption key, so the company says even Meta would not be able to access the virtual machine.4
Ā
Meta also says users can disconnect an application, change permissions, or tell Muse to forget specific information. The company states that conversations and data in a userās virtual machine are not shared with Metaās advertising systems. Users can opt out of having their Muse interactions used to train Metaās AI models.1
Ā
CNBC adds an important qualification: users must opt out of training use. If they do not, Meta says it will remove critical personally identifying information before using interactions to improve its models.5Ā That policy choice deserves attention because a personal agent may see a wider range of private information than a general-purpose chatbot.
Ā
Availability and pricing
Meta says Muse is free for most ordinary use, with subscriptions for people who want to do more.1Ā CNBC reported a free tier and paid plans priced at $20 and $100 per month, depending on usage.5Ā The limits and plan details may change as the service expands.
Ā
The first rollout is restricted to the United States. That matters because an agent that books travel, completes forms, or buys products depends on regional services, payment systems, consumer protections, and legal requirements. A successful U.S. launch would not automatically demonstrate the same performance in other countries.
Ā
The trust problem behind the product
Muse asks for a form of trust that is deeper than trusting an assistant to summarize a document. To be useful, it may need access to a mailbox, calendar, social accounts, payment tools, and browsing sessions. It may also retain preferences and personal context so that it can make suggestions without being told the same information repeatedly.
Ā
That design creates a tension. The more context Muse has, the more useful it may become. The more context it has, the greater the cost of an incorrect permission, an unintended disclosure, a compromised integration, or an action that the user did not mean to authorize.
Ā
Meta is responding with isolation, approval gates, credential protection, audit records, and a public security-bounty program. WIRED reports that the bounty can pay up to $300,000 for valid findings, including up to $130,000 for certain prompt-injection attacks affecting one user.4Ā CNBC also reports that Meta is exploring commerce-related revenue, including the possibility of taking a share of transactions generated through the agent.5
Ā
That commercial possibility raises another question. If Muse recommends a product and can also purchase it, users will need clear explanations of how recommendations are selected. Meta says Muse conversations and virtual-machine data are not shared with its ad systems, but a shopping agent still operates at the intersection of personal preferences, merchants, payment providers, and platform incentives. Transparency will be as important as technical isolation.
Ā
Closing Thoughts
Muse is one of the clearest examples yet of AI moving from conversation to delegated action. Its appeal is easy to understand: people do not need another window in which to write instructions. They want routine work removed from their schedule.
Ā
The productās strongest idea is the combination of natural-language requests with explicit approval for consequential actions. Its most important weakness is that the user must still trust a complex system to interpret the request correctly, navigate unfamiliar websites, and know when it is uncertain.
Ā
Meta deserves credit for treating the agent as a security problem rather than only as a model-quality problem. Secure storage, an isolated environment, a monitoring layer, and independent testing are meaningful design choices. They do not remove the need for skepticism. Muse should be judged by how often it makes a mistake, how clearly it reports that mistake, and how easily a user can undo or contain the result.
Ā
What does this actually mean?
Muse means that a personal AI product can now be framed as an operator with permission to act across digital services. The user gives an objective, not a complete sequence of clicks. The agent performs research, makes choices, and returns for approval when Meta considers the next step sensitive.
Ā
It also means that the interface for personal computing may shift from apps and menus toward goals and delegated workflows. The technology is still early, the launch is U.S.-only, and independent evidence about real-world reliability remains limited. The practical test will be whether users can understand what Muse is doing at every important moment.
Ā
Why does it matter?
Muse matters because it connects AI to real-world outcomes. An email can be sent. A reservation can be made. A product can be purchased. A form can be submitted. These are small actions, but billions of them shape how people work, shop, communicate, and manage daily life.
Ā
If agents become dependable, they could reduce administrative work and give people more time for decisions that require human judgment. If they are opaque or overly permissive, they could multiply mistakes at high speed. The debate is therefore not only about whether Muse is impressive. It is about who controls the agent, who bears responsibility when it acts incorrectly, and whether privacy promises can be verified rather than simply accepted.
Ā
References





Muse sounds like a game changer for streamlining everyday tasks! I'm curious about how it will integrate into existing workflows and enhance productivity. Looking forward to reading more about its potential impact on businesses.