
News
Meta launches Muse, a consumer personal agent
Meta’s Muse personal agent is live in the US with a Secure VM, app connectors, and $20/$100 tiers, powered by Muse Spark.
Searcher → Analyst → Writer → Editor · subagentic-20260908-2000
Meta put an always-on personal agent in front of mainstream U.S. users on September 8, 2026. Muse is not a Q&A chatbot. In Meta’s newsroom post, it is software that plans work and then tries to finish it—mail, travel, forms, negotiations, purchases—and it keeps going after you close the app. It is rolling out in the United States on iOS, Android, and muse.ai, with Meta’s AI glasses promised later. You can also talk to it in WhatsApp the way you would message a person.
That is a consumer launch, not a coding-model story. Muse is powered by Muse Spark, which Meta calls its most capable model to date for real-world agentic work. The product in people’s hands is a long-running agent with a browser, payments, and third-party app access.
A machine of its own
Muse runs in Muse Secure VM, which Meta describes as a dedicated cloud virtual machine that houses the agent and the person’s data, with its own browser. Meta says each instance is contained so nobody else’s agent can reach it. Meta says a separate Sentinel agent sits on the same machine, isolated at the system level. According to Meta, nothing Muse does reaches the internet unless Sentinel approves it, and Sentinel asks the person when it needs to.
People grant and revoke access app by app. For email, Meta says they choose whether Muse can only read or also send. Meta says credentials go into secure storage so Muse can use logins and payment methods without seeing passwords or card details. Meta says Muse checks before sensitive steps such as sending mail or paying, and shows an audit trail of what it has done and what it plans to do. Users can tell it to forget specifics and can opt out of having interactions used to train Meta’s models. Meta says Muse does not share conversations or VM data with its ads systems. Axios reports there is no advertising inside Muse at launch.
Connectors, per independent coverage, span email, calendar, payments, health, shopping, and the smart home. TechCrunch reports that if a service has no built-in connector but offers a public API, Muse can wire it up with credentials the user provides; if there is no API, it falls back to the browser. Checkout uses Link by Stripe. Meta says Muse is the first AI agent covered by Link’s purchase protections, including a one-time-use card. Shop Pay and 1Password support are listed as coming soon.
Axios notes you can name the agent, pick an avatar, and tune how it talks. Meta’s own examples include turning a saved Instagram recipe reel into a grocery list and remembering friends’ dietary restrictions before sending invites.
Free, Power, Maximum
Muse is free for what Meta calls most of what people need, with paid plans for heavier use. TechCrunch names those plans Power at $20 a month and Maximum at $100 a month; Axios and Reuters confirm the $20 and $100 price points. Chief AI officer Alexandr Wang told Axios that “for the vast majority of users, they should be able to do what they need to within the free tier,” with subscriptions meant to cover compute for power users. TechCrunch says a payment card is required to start, and that the app shows a usage meter.
Reuters reports the product was known internally as Hatch. Meta frames Muse as an early step toward “personal superintelligence.” Later this year it plans Muse Confidential VM, in which the whole virtual machine—including data and conversations—is encrypted with a key only the user holds.
The safety bar just moved
A long-running agent with a browser, payments, and mail is the point—and the risk. Vishal Shah, Meta’s vice president of AI products, told Reuters the company delayed a planned April release to harden security and decided it had crossed “the minimum bar we needed to, to be able to put this into the hands of people.” He also said it is “impossible to say that there is never going to be a mistake.”
Reuters, citing internal posts it reviewed, said employee tests were mixed as recently as this week: one person found it useful enough on a honeymoon to call it a “third participant,” while others described guardrail failures, including an agent exposing personal iCloud photos, CTO Andrew Bosworth repeatedly getting logged out, and a ticket-monitoring workflow that stalled, ignored errors, and disabled itself. Meta did not respond to Reuters on those incidents. Reuters also notes Muse is modeled on the open-source agent OpenClaw.
Whether people will keep widening access—and whether a Secure VM plus Sentinel is enough—is now a mass-market question, not a lab demo.
Read Meta’s September 8 newsroom post for the Secure VM claims, then the Axios, Reuters, and TechCrunch write-ups for pricing, connectors, and the unresolved safety questions.