Meta introduced Muse, a personal AI agent, in the United States on September 8. Rather than simply answering questions, it carries out work on a person's behalf, from sending an email to booking travel. The agent lives inside a dedicated virtual machine, and every outbound connection is screened by a separate agent. Alongside a free tier, Meta is offering subscriptions at 20 USD and 100 USD per month.
From answering to getting it done
Muse is not positioned as another chatbot. Meta describes it as an agent that actually finishes the errand it was handed. One-off tasks such as sending a message or reserving a table are the easy case, but the agent also accepts vaguer, longer-horizon goals. Share a goal with Muse and it turns that into a plan, sorts out how time and resources should be allocated, and keeps moving the work forward while the person is doing something else.
While working, Muse opens a browser of its own, fills in forms, and will negotiate terms when that is what the job requires. Longer tasks continue after the app is closed, and the agent comes back when circumstances change or just before it takes a consequential step such as sending an email or making a purchase. On the interface side, one detail stands out: besides the dedicated app, people can talk to Muse directly inside WhatsApp. Meta is not asking anyone to learn a new interaction model, it is reusing the one they already use to message another person.
Memory is built out carefully as well. Muse retains preferences that were mentioned only once and will volunteer suggestions that were never requested. Among the examples Meta gave: turning a recipe reel saved on Instagram into a grocery list, and recalling friends' dietary restrictions before invitations go out.
Payments run through Stripe's Link, with protections attached
Letting an agent shop for you makes payment unavoidable. Muse can check out with Link, built by Stripe. Meta says it is the first AI agent covered by Link's purchase protections, which include free coverage for damaged or lost items, handling of price drops, no-fee returns, and a return guarantee on eligible purchases.
Mechanically, a wallet for agents issues a single-use card number so the real card details stay hidden across the sites where the agent transacts. Shop Pay is planned as an additional payment method, along with 1Password support. Once the latter lands, Muse will be able to work with logins the person already uses.
Sentinel, not Muse, holds the permissions
The first question in this category is always how much personal data you are willing to hand over. Muse only becomes useful once it is connected to the services that run a person's life, including email, calendar, financial, health and fitness, and smart home apps. Put another way, the volume of information involved is considerable.
Meta's answer is Muse Secure VM. The agent and the person's data are enclosed in a dedicated virtual machine (VM, a virtual computer carved out of a physical server) in the cloud, out of reach of anyone else's agent. Credentials for connected services are stored inside it as well.
On that same machine, a separate agent called Sentinel runs, isolated from Muse at the system level. Whatever Muse tries to do, nothing reaches the internet unless Sentinel approves it. Sentinel sorts each action into allowed, blocked, or sent to the person for approval, and permissions can be scoped narrowly by service, transaction, or period of time. Granting read access while withholding the ability to send is possible.
Muse cannot see passwords or payment methods. Credentials, including passwords typed into the browser by the person, go into secure storage, and Muse uses them without ever viewing them. Everything the agent has done and plans to do is visible as an audit trail. On training, queries are used to improve Meta's models by default, but that can be switched off. Meta states that conversations and data inside the VM are not shared with its advertising systems. Later this year the company plans to ship Muse Confidential VM, where the entire VM is encrypted with a key only the person holds.
Meta also acknowledges that how you ask for approval is itself a hard problem. Prompting for every small action trains people to tap through without reading, which makes the system less safe rather than more. Muse is designed to require confirmation for higher-impact operations while letting previously authorized, low-risk work proceed. There is good reason for the caution: several incidents this year have involved agents deleting mail or files after being granted access.
Availability and pricing
Muse is rolling out first in the US on iOS, Android, and the web, with support for Meta's AI glasses arriving soon. It runs on Muse Spark, developed in-house and described by Meta as its most capable model to date.
Pricing assumes the free tier covers most of what people need, with two paid plans at 20 USD (about 3,000 yen) and 100 USD (about 15,000 yen) per month. Alexandr Wang, Meta's chief AI officer, has explained that the subscriptions exist to cover compute costs. There is no advertising inside Muse, though the company says it is exploring commerce as a source of revenue.
※1 USD = 153 JPY (as of September 9, 2026)
Summary
Meta's Muse is a personal AI agent that carries out the work it is asked to do. It runs in a dedicated virtual machine, and a separate agent called Sentinel sorts its outbound actions into allowed, blocked, or awaiting approval. Payments go through Stripe's Link and come with purchase protections. It is available in the US on iOS, Android, and the web, with a free tier plus plans at 20 USD and 100 USD per month. Whether people will trust it enough to hand over the center of their digital lives, from email to finances, is the question that decides what happens next.
