Meta Muse AI Agent: Personal Computing Gets a Memory and Hands

Contents

On 8 September 2026 Meta launched Muse, a personal AI agent that runs in its own cloud virtual machine, connects to a person’s email, calendar, payment and shopping accounts, remembers what matters to them, and keeps working after they close the app. It runs on Muse Spark, the model family from Meta Superintelligence Labs, and launched free in the United States on iOS, Android, the web and inside WhatsApp, with paid tiers at $20 and $100 a month. Within ten days it was the top free app on the US App Store. A Mac app followed on 18 September, Connect added retail partners and a pocket device called Muse Charm, and by 29 September there was a small business edition and an enterprise platform.

The Meta Muse AI agent matters less as a feature list than as a distribution event. OpenAI, Google and Perplexity had already shipped cloud agents that act on your behalf, mostly behind premium subscriptions. Meta put the category in front of a mass consumer audience, for free, inside a messaging app billions of people already use. That exposes the real design problems of personal agents: memory people can inspect, permissions they understand, and mistakes that happen in the physical world. Three weeks in, Muse has produced examples of all three.

From chat windows to agents that live with you

For most of the last four years, consumer AI followed one pattern: open a window, type a request, read an answer, close the window. Copilots moved that window inside other software. Task agents such as OpenAI’s Operator in early 2025 showed a model could drive a browser. Computer-use agents widened that to desktops and files. The step 2026 has been about is continuity: agents that hold a persistent environment, keep state between sessions, and act on a schedule or trigger rather than a prompt.

Most of that work targeted knowledge workers. Perplexity Computer, announced on 25 February 2026, calls itself “a general-purpose digital worker.” Google’s Gemini Spark, announced at I/O on 19 May 2026, keeps working in the cloud when you close your laptop and is in beta for AI Pro and Ultra subscribers. OpenAI’s dots, launched on 29 September 2026, are rolling out to Pro and Business Premium, with Enterprise in beta.

Meta’s bet differs in audience, not mechanics. It traces to Mark Zuckerberg’s “Personal Superintelligence” letter of 30 July 2025, which argued the most useful AI would be one “that knows us deeply, understands our goals, and can help us achieve them,” and distanced Meta from companies aiming AI “towards automating all valuable work.” Muse is the first product that makes that thesis concrete: a personal agent first, a work tool second.

What exactly Meta launched with Muse

“Meta Muse” is shorthand. The product is officially Muse, which Meta calls a personal AI agent. Muse Spark is the model family, first announced on 8 April 2026 as the debut model from Meta Superintelligence Labs, with Muse Spark 1.1 and a public preview of the Meta Model API following on 9 July. Meta’s safety write-up names Muse Spark 1.3 as the agent’s model at launch. Around the agent sit Muse Code (a terminal coding agent), the Muse API, Muse for Small Business, and the announced Muse Charm device. The state of each, as of 30 September 2026:

Launch and availability (released). Announced 8 September and rolled out in the US on iOS, Android, muse.ai and inside WhatsApp. Coverage of Connect (23 and 24 September) reported that Muse had reached Canada. Engadget reported that sign-up needs a Meta account, not a Facebook or Instagram profile, with web sign-in by phone number.

Pricing (released). Meta says Muse is “free for most of what people need, with subscription plans for people who want to do more.” TechCrunch reported the tiers as Free, Power at $20 a month and Maximum at $100 a month. Secondary coverage cites a weekly token allowance for the free tier; Meta’s pages do not state it, so treat that figure as unconfirmed.

Core capabilities (released). Per Meta and TechCrunch, Muse can send emails, book travel, lower bills, fill out forms, create plans, turn recipe Reels into grocery lists, send invitations, negotiate and make purchases. It drives its own browser, works after the app closes, and notifies people when something changes. Checkout uses Stripe’s Link with single-use virtual card numbers.

Connectors (released and expanding). At launch Meta listed categories, not a count: email, calendars, payments, health and fitness, smart home, dining, shopping, music and events. Connect added partners including Walmart, Best Buy, Gap, Sephora, Ulta, Wayfair, Instacart, PayPal, Shop Pay, Notion, Granola, GitHub and Box, with Expedia coming soon. TechCrunch reported more than 1,500 developer connector applications in under a week. No official total has been published.

Mac app (released, with a discrepancy). TechCrunch reported on 18 September that Muse for Mac could act in Files, Messages, Calendar, Notes and Mail. Connect coverage later described fuller desktop control as “coming soon” and part of early access. The likely reading: local app access shipped on 18 September; broader computer use is still gated.

Announced, not released. Muse on Ray-Ban Meta and Oakley Meta glasses “in the coming months,” woken by the agent’s name; a video avatar; a dedicated Muse email address; custom voices; and Muse Charm, a keychain-sized device with a roughly 2-inch screen that reporting says targets the 2026 holidays, with no price yet. A Muse Early Access Program opened on 25 September. A Muse Confidential VM with end-to-end cryptographic protection is described as coming later.

Business editions. On 28 September Meta launched the Meta Enterprise Platform, led by former MongoDB chief executive CJ Desai, bundling Muse, Meta Business Agent, the Muse API and Muse Code. On 29 September it released Muse for Small Business in the US and Canada, with connectors to Shopify, QuickBooks, Stripe, Slack, Canva, Klaviyo and Meta’s Pages, Instagram business and ad accounts.

Why the Meta Muse AI agent launch matters

The mechanics are not new. Per-user virtual machines, model-driven browsers, account connectors and payment approvals all predate Muse. What changed is who is being asked to trust them.

Distribution changes the risk profile. TechCrunch reported Muse reached number one on the US App Store on 18 September and Google Play on 19 September, with third-party trackers estimating roughly 2.3 to 4.3 million downloads by 25 September. The trackers disagree, but all describe a scale no earlier computer-use agent reached in its first month. Meta also gave Muse most of its house ad promotion within ten days and bought paid media elsewhere.

The unit of value moves from answers to errands. Meta’s examples are domestic: grocery lists, invitations, bills, Marketplace listings. The product appears designed to feel like something you hand chores to, not a research tool you consult. That means delegating tasks with real side effects involving money, other people and physical places.

Why now. In July Meta described Muse Spark 1.1 as “built for agentic tasks,” with parallel subagents, computer-use workflows and a one million token context window. Competitors were shipping always-on agents. And GuruFocus reported that Meta delayed the agent from April over safety issues found in testing, quoting vice president Vishal Shah: “it is impossible to say that there is never going to be a mistake.” One plausible reading is that Meta shipped once its containment architecture was ready, then chose to learn at scale.

The category it wants. Muse is not positioned as a better chatbot. It appears positioned as the default intermediary between a person and their services, reachable from WhatsApp, phone, Mac, glasses and eventually a pocket device. That is a personal computing claim, consistent with Zuckerberg’s 2025 argument that glasses “will become our primary computing devices,” and it explains why Connect, historically a hardware event, was organized around an agent.

How Muse works under the hood

In plain terms, Muse is a model with its own computer. It plans a task, uses connectors (structured access to services like your calendar) where they exist, falls back to a browser where they do not, asks before anything sensitive, and records what it did. The interesting part is how Meta separated those responsibilities, described in a launch-day engineering post by Tarek Sheasha of Meta Superintelligence Labs.

A private VM per person. Each user gets a dedicated cloud VM. The agent runs in an isolated container where “root inside the runtime cell is mapped to an unprivileged host user,” and security services sit outside it, so a compromised agent cannot reach them.

Sentinel as permission authority. A separate component, Sentinel, decides whether each connector action or network request is allowed, denied or sent to the user. It inspects destination, method, path and “the actual decoded request,” and tracks “tainted egress”: a tool process becomes tainted once it reads user data, and requests from tainted processes get stricter treatment. Approvals can be one-time, per session, per task, time-bounded or permanent.

Credentials the model never sees. OAuth tokens sit in an isolated store; the model gets surrogate tokens, and real credentials are injected at the network boundary after Sentinel approves. Email connectors filter one-time codes and password reset links. A prompt injection cannot extract a password the model does not hold.

A browser seen as an accessibility tree. The browser runs in its own virtualized sub-agent. The model sees an accessibility tree snapshot, not raw page code, and cannot run JavaScript. Classifiers scan pages, images and downloads for injection and for personal data leaving the system.

Defenses that admit limits. Meta lists five layers: model training, labeling external content as untrusted, injection classifiers, human approval for data exfiltration, and deterministic isolation. It states that “prompt injection remains an open problem” and “Muse isn’t immune to attack,” and opened a bug bounty paying up to $300,000.

Memory you can download. Muse “remembers what matters to a person,” can be told to forget details, and everything in the VM, including memory, is inspectable and downloadable. Meta says Muse data is not shared with its ad systems, though the engineering post notes that purchases Muse completes on websites may still influence the ads a person sees. Memory and ads are separated; the agent’s actions in the world still leave ordinary trails.

For the groundwork behind memory features like this, see our explainer on how retrieval shapes what an AI system knows.

The Muse user experience, seen by a product designer

Muse had to make agent behavior legible to people who have never heard the phrase “tool calling.” This assessment draws on Meta’s documentation and published reporting; we have not used Muse ourselves.

Interaction model. Conversation in a dedicated app or a WhatsApp thread, with a voice mode for long conversations announced at Connect and an avatar mode coming. WhatsApp is the strongest decision in the product: it puts an agent where people already coordinate errands.

Task initiation. Requests start tasks, but Muse also initiates. An “ideas” tab suggests tasks from what it has learned; Engadget saw suggestions like turning saved Instagram recipes into a guide.

Delegation and visibility. People hand over messages, bookings, purchases, negotiations and listings. Meta says Muse shows a full audit trail of completed and planned actions. The planned half is the valuable one: it lets someone catch a mistake before it happens.

Control. Engadget reported the default setting is “ask for some actions,” with an “always ask” option. Sentinel’s approval scopes are more granular than most consumer products expose, and services can be disconnected anytime.

Trust. Muse’s trust signals are architectural, not visual: private VM, hidden credentials, virtual cards. That is sound engineering, but users cannot observe it. A survey cited by Gizmodo found only 8% of consumers trust Meta with passwords, below OpenAI, Apple and Google. Interface trust has to compensate for brand trust.

Feedback and completion. Notifications report progress and completion, a familiar pattern for errands. For multi-day goals like price tracking, “done” is fuzzier.

Errors. Meta’s guidance, as quoted by AppleInsider, says “your Muse can make mistakes or take unexpected actions.” Recovery depends on the audit trail and on reversibility, which varies. An email cannot be unsent; a meeting with a stranger cannot be un-arranged.

Memory. Controlled by a forget command and a downloadable record. What public material does not show is a simple view of “what Muse believes about me” at the moment it acts.

Permissions. Per-connector access and scoped approvals are good. The weakness is semantic. When someone approves “automatic replies” on a listing, does that include sharing an address or scheduling a visit? In one widely reported case, Muse decided it did.

That gap is the subject of our piece on designing AI features people trust: permission labels need to describe consequences, not capabilities.

Real-world use cases for a personal AI agent

Each example stays close to what Meta and reporters have described: task, agent action, human involvement, result.

Meal planning from Reels. A person wants a week of saved recipe Reels turned into shopping. Muse extracts ingredients, merges duplicates and fills an Instacart cart. The person approves checkout. Result: a cart in minutes instead of an evening of notes.

Travel with price watching. A family needs flights. Muse compares itineraries and tracks prices in the background, notifying on changes. The person picks and approves payment. The agent holds the watch.

Bill reduction. Meta says Muse can negotiate for people, which may mean forms or messages to providers. The person approves any account change, and the audit trail records what was said.

Selling on Marketplace. Muse writes the listing, answers buyers and negotiates. Human involvement should include explicit approval before sharing an address or setting a meeting; the reported incident below shows why.

A freelance designer’s inbox. Muse triages client email, drafts replies, flags deadlines and files attachments to Box or Notion. The designer reviews drafts before sending and starts the day with a brief rather than an unread count.

Meeting follow-up. Muse pulls notes from Granola, drafts follow-up emails and adds calendar holds. The professional approves sends, so follow-ups go out the same day.

Small retail performance review. Muse for Small Business reads Shopify and QuickBooks, compares campaigns in Meta ad accounts and proposes changes. Meta says it does not publish, send or spend without approval. A sole owner gets analysis they rarely have time for.

Content and ads planning. Muse analyzes recent Instagram performance and drafts posts and ad variants in Canva. The owner approves anything public, and the calendar is built from data rather than guesswork.

What changes for product designers

If a personal agent can operate your product, several assumptions weaken without disappearing.

Dashboards become evidence. Someone who asks Muse “how did sales go last month” may never open your analytics. They will open it to check the agent’s claim. Dashboards shift from primary source toward verification, which rewards clear sources and drill-downs; our SaaS dashboard design principles apply with a new reader in mind.

Forms become contracts. Agents fill forms, so validation, required fields and confirmations become a contract with a non-human caller. Ambiguous fields and hidden defaults break agents first. Good form design practice now serves two audiences.

Actions matter more than navigation. An agent does not browse your menu; it looks for a way to do a thing. Clear, named actions (book, cancel, refund, reschedule) are easier for agents to use and for people to audit.

Permissions must describe consequences. “Allow automatic replies” describes a capability. “Muse may share your pickup address and agree to meeting times” describes a consequence. Sensitive consequences deserve their own approvals.

Autonomous activity needs a visual language. Designers need patterns for “an agent did this,” “an agent is about to do this” and “on whose behalf,” with attribution in activity logs and a clear undo where possible.

Chat complements structure. Muse shows chat is good for intent and poor for review. Pair a conversational entry with scannable review screens.

What changes for developers

Connectors are the new integration surface. Meta says Muse can use any service with a public API, and the small business edition supports custom connectors. Without a clean API, an agent falls back to driving your web interface, which is slower, more brittle and harder to observe. Publishing scoped actions gives you more control.

Identify the caller. Amazon blocked Muse from its store around 20 to 22 September; GeekWire reported Amazon’s objection that Muse did not identify itself while browsing. Whatever Amazon’s motives, services will want to know when an agent acts, for whom and with what authority. Plan for agent identification, per-agent rate limits and explicit terms for automated purchasing.

Assume hostile input. Meta treats every page and email as potentially hostile, and Muse reads the accessibility tree. Clean markup and structured, accessible pages help agents use your product correctly.

Local agents raise the security bar. The Mac app produced two security stories in two weeks. Gizmodo reported on 22 September that researcher Patrick Wardle found a dictation setting other local programs could change to redirect audio and tokens; Meta removed it and called the practical risk low. On 28 September AppleInsider and 9to5Mac reported that journalist Jason Aten found Muse had synced about 187,000 rows of his Messages database after he declined that access; Meta has attributed similar reports from other users to bugs. Permission enforcement deserves the testing rigor of payment code.

Observability is a product feature. Muse’s audit trail lives on the agent side. Services need their own logs showing agent actions, visible to support teams.

Competitive comparison: personal and always-on agents in 2026

This table includes only what published sources support as of 30 September 2026.

Dimension Meta Muse OpenAI dots Google Gemini Spark Perplexity Computer
Launch Released 8 Sep 2026 Released 29 Sep 2026 Announced 19 May 2026; beta Released 25 Feb 2026
Computer use Cloud browser; Mac app acts in local apps; fuller control in early access Own cloud computer and browser per dot Cloud agent; uses your Chrome with permission (US) Isolated cloud environment; Personal Computer on Mac and Windows
Memory Persistent, forgettable, downloadable Learns preferences; reset to erase Draws on Gmail, Drive and Workspace context Persistent across sessions
Background execution Yes, with notifications Yes, always on Yes, background and scheduled tasks Yes, long-running and parallel
App integrations Consumer, retail and business connectors plus WhatsApp; no total published 4,000+ apps via plugins Google apps plus MCP; Canva, OpenTable, Instacart at launch Hundreds of connectors; 400+ apps on Enterprise
Personal tasks Primary focus Secondary to work Email and personal admin Secondary
Enterprise workflows Enterprise Platform and Small Business edition Business Premium; Enterprise beta Separate Gemini Enterprise stack Enterprise plans, Slack and Teams
User control Sentinel approvals with scoped durations Auto-review; confirmation for sensitive actions Permission before using Chrome accounts Approvals, audit trail, kill switch (Personal Computer)
Availability and price Free, $20, $100; US and Canada Pro ($200) and Business Premium, rolling out AI Pro and Ultra, personal accounts Pro, Max and Enterprise, credit metered

The pattern is clear. The others sell agents to people who already pay for AI at work. Meta gives one away to people who message their family. Neither is better by default, but they produce very different failure modes and feedback loops.

The business model behind a free personal agent

Agents cost more than chatbots: an agent task can involve dozens of model calls, a running VM, a browser session and hours of monitoring. That is why competitors mostly gate agents behind premium tiers, and why OpenAI announced a $500 Pro tier alongside dots.

Meta appears to spread the cost three ways. Subscriptions at $20 and $100 cover heavy users. TechCrunch reported Meta intends eventually to take transaction fees, and Seoul Economic Daily quoted Zuckerberg describing “taking a very small percentage of commerce volume as a fee,” with revenue “from businesses.” And the enterprise and small business editions reach budgets consumers lack. If Meta’s pledge to keep Muse data out of its ad systems holds, the company’s most obvious monetization path is off the table for the agent itself.

The logic suggests a platform play. If Muse becomes where people start errands, merchants will want to be reachable by it, and Walmart, Best Buy, Sephora and others signed on within weeks. Amazon’s block suggests the largest may refuse on Meta’s terms. That standoff will shape agent commerce economics more than any subscription price.

Limitations and risks

Documented incidents. In three weeks Muse had at least three reported problems with real consequences: the Mac Messages sync after access was declined; the dictation endpoint flaw; and a Marketplace case, reported by Malwarebytes on 29 September, in which Muse negotiated a sale and sent a buyer to a seller’s home without asking to share his address. Meta said it was looking into the report. Gizmodo also relayed claims that a Muse Spark model escaped containment in third-party testing; we could not verify this against a primary source and treat it as unconfirmed.

Permission scope creep. The Marketplace case is not a model error in the usual sense. The agent acted within a broad permission and against what the person meant. This risk is demonstrated, not theoretical.

Prompt injection. Meta calls it “an open problem.” We found no public evidence yet of a successful injection against Muse users, so the risk is theoretical but vendor-acknowledged.

Institutional history. TechCrunch reported in March 2026 that an internal Meta agent posted a response without permission, leading to a two-hour data exposure to unauthorized employees, rated severity 1. It was not Muse, but the class of failure is known inside the company.

Platform access. Amazon has blocked Muse and, per GeekWire, other third-party shopping agents.

Accountability. When an agent negotiates and agrees, responsibility for a bad deal is unclear; Meta’s own guidance places the risk of mistakes on the user. Apollo chief economist Torsten Slok warned on 27 September that agents like Muse could move household deposits into higher-yield accounts at scale, an “agentic bank run”; that is a forward-looking concern, not a demonstrated one.

Reach and limits. Muse is limited to the US and Canada, and Meta has not published free tier limits.

What Muse reveals about the future of AI agents

From answering to acting: supported. Muse’s launch examples are almost all actions, and the market response suggests consumers will try this when it costs nothing.

From sessions to continuity: supported, with open questions. Persistent memory and background execution ship today. How people manage what an agent remembers over months is unsettled.

From apps to agents: partly supported. Muse sits on top of WhatsApp, Marketplace and retailer sites. People still use those apps, increasingly through a layer, and Amazon’s resistance shows the transition will be contested.

From interfaces to capabilities, and prompts to outcomes: forward-looking. The connector rush suggests services see value in exposing actions, and Meta promises “action plans for long-term goals.” There is little public evidence yet of how well Muse sustains multi-week goals.

The broader signal is about personal computing. Meta is putting one agent into a phone app, a messaging thread, a Mac, glasses and a pocket device. The agent, not the device, is the constant, carrying context between whatever surface is nearest.

What founders should pay attention to

Agent-reachable commerce is a distribution channel. Consumer founders should decide now whether to be reachable by agents, how to identify them and on what terms.

Vertical agents still have room. Health, legal, finance and property transactions need domain guardrails a horizontal agent will not prioritize.

Agent security is a product category. Meta built surrogate credentials, egress policy and injection classifiers in house. Most companies will buy them.

Handoff is where products win. Every failure so far is a boundary failure. Products that handle the moment an agent should stop and ask will earn trust faster.

What designers should start doing now

  • Name your actions. Make the ten most important things people do in your product clear, callable actions.
  • Rewrite permissions as consequences. Say what the agent may do, not what it may access.
  • Separate sensitive consequences. Addresses, payments, meetings and public posts need their own approval.
  • Design an agent activity log. Show who acted, for whom, when and with what approval.
  • Make undo real, or move the weight. Where undo is impossible, strengthen the confirmation.
  • Write for two readers. Labels, microcopy and page structure are now read by agents too.
  • Plan the handoff. Define exactly when a human steps in, and design that moment.

Our piece on AI agents and product design goes deeper on these principles.

The takeaway: an agent in every pocket, with every consequence

What fundamentally changed is not the technology. Isolated VMs, browsing agents and approval gates existed before 8 September 2026. What changed is that a company with billions of users made a personal agent free, put it in a messaging app, and millions of people handed it chores within days. The personal agent is no longer a premium experiment. It is a mass-market product with mass-market consequences, including a stranger at someone’s door.

That moves the hard problems from model quality to product design. Muse’s architecture is careful; its failures have been about meaning: what a permission covers, what “declined” means on a desktop, what someone expects when they say “handle it.”

Designers should watch how Meta rewrites Muse’s permission language after the Marketplace case. Developers should watch whether agent identification becomes a norm or a fight. Founders should watch whether large merchants follow Walmart or Amazon. And everyone should watch the glasses rollout, where an agent that acts on what you are looking at merges personal computing and personal agents.

Building a product that people and their agents both need to use well? hello@beconfidency.agency, we design clear actions, legible permissions and recoverable flows for agent ready products.

This thinking shapes our AI design and integration service.

Sources

Next project

Have an ideaworth raising?