Meta's Muse AI Agent Explained: What It Can Do, What It Costs, and the Privacy Question

Meta's Muse AI Agent Explained: What It Can Do, What It Costs, and the Privacy Question
Meta launched Muse on September 8, 2026 — a personal AI agent designed to do things for you, not just chat with you. Two weeks in, it has already climbed to the top of US app download charts with over 2.5 million downloads, and Meta is quietly testing features that blur the line between AI and human help. Here's what Muse actually is, what it can do, what it costs, and the trade-offs you should understand before handing it your inbox and your wallet.
What happened: Meta's consumer bet on agents
For years, Meta's consumer AI story was Meta AI: a familiar chatbot that answers questions, similar in spirit to ChatGPT. Muse is a deliberate step beyond that. Meta positions it as the company's clearest move yet toward "personal superintelligence" — an AI tuned to your context, preferences, and goals that executes tasks across apps and websites with limited step-by-step instruction.
Muse is rolling out in the US on iOS, Android, the web at muse.ai, and WhatsApp. Support for Meta's AI glasses is planned for a later stage. The agent is powered by Muse Spark, Meta's latest model built specifically for agentic work, and it runs inside a dedicated cloud environment Meta calls the Muse Secure VM. The headline idea: you give Muse a goal, it builds a plan, and it keeps working — even after you close the app — returning when something changes or it needs your approval.
This launch lands in the middle of an industry-wide shift. As Neowin noted at launch, Google has expanded Gemini Live with agentic capabilities, OpenAI has introduced ChatGPT Work, and Microsoft has made Copilot Cowork available through its Frontier program. Meta's play is distinct mainly in its audience: Muse is aimed squarely at regular consumers, not developers or enterprise teams.
What Muse can actually do
Muse's selling point is execution across the messy, multi-step tasks of everyday life. According to Meta, it can:
- Send emails and book travel — drafting, then acting after your approval.
- Browse the web and fill out forms on your behalf, with access to a browser, file system, and terminal.
- Negotiate and lower bills, or gather quotes from different contractors.
- Make purchases using Link by Stripe, which generates a one-time-use card so websites never see your real payment details. Meta says Muse is the first AI agent covered by Link's purchase protections, which include coverage for eligible damaged or lost items, price-drop protection, and no-fee returns. Support for Shop Pay and 1Password is expected later.
- Make phone calls to US businesses — booking a haircut, checking store inventory, or collecting quotes. After each call, Muse provides a detailed summary and a full transcript in the app.
- Create documents, PDFs, web pages, and interactive artifacts such as spending trackers or study guides.
- Remember things that matter to you — details mentioned once, friends' dietary restrictions, a recipe reel you saved — and make suggestions without being prompted. You can also tell it to forget specific information.
For longer tasks, Muse breaks goals into plans, monitors progress, and comes back when it needs a decision. Users can customize it by naming it, choosing an avatar, and adjusting how proactive it should be. Meta has also expanded the Muse lineup with Muse Voice Transcribe, which adds real-time multilingual speech recognition and speaker labeling, according to TechRepublic.
Pricing: free tier, plus two paid plans
Muse is free for most usage, but Meta is introducing two subscriptions, per TechRepublic's launch reporting: Power at $20 per month and Maximum at $100 per month. The company expects most people to stay on the free tier, with paid plans aimed at users who need higher usage limits or additional capabilities.
For everyday users, the practical takeaway is simple: the core agent experience — tasks, memory, the app and WhatsApp access — is free, and the paid tiers are about raising ceilings rather than unlocking the product itself. Pricing details can change, so check muse.ai for the current plans before subscribing.
Under the hood: the Secure VM and Sentinel
The most interesting part of Muse may be what sits underneath it. Meta built the agent around a dedicated cloud virtual machine — the Muse Secure VM — so each user gets an isolated environment containing the agent and its connected data. A separate system-level agent called Sentinel controls what Muse can send to the internet and connected services, and must approve actions such as sending emails or making purchases. Users decide which services Muse can access, can review an audit trail of its actions, and can disconnect services at any time. Meta says it keeps credentials in secure storage, keeps them from the agent itself, and does not share Muse data with its advertising systems.
There are caveats worth knowing. WIRED reported that Meta acknowledges the Muse Secure VM is not technically inaccessible to Meta itself, even though company policy bars the company from accessing users' Muse data. In response, Meta plans a more locked-down option later this year — Muse Confidential VM — in which the entire virtual machine would be encrypted using a key held by the user, which would prevent even Meta employees from accessing its contents.
Muse's biggest advantage is also its biggest tension: it is asking people to hand an AI access to email, calendars, payments, and other personal services. The security architecture is genuinely more serious than what most assistants offer — but with Meta's history of privacy controversies, consumers may judge those promises skeptically.
The human concierge: Meta's quiet experiment
One of the more surprising post-launch developments, reported by Reuters via LiveMint, is that Meta is testing a "human concierge" feature in which trained human contractors quietly handle some of Muse's phone calls. According to internal company posts seen by Reuters, Meta began internal "dogfood" testing of the phone-calling capability in August, then gradually rolled it out to Muse users. The human-agent fallback was enabled for about half of employees shortly after Muse's public debut, with an opt-out option for employees who were uncomfortable.
Some employees raised privacy concerns — sensitive information could reach human contractors unintentionally. Meta spokesperson Daniel Roberts responded that employee feedback had been "overwhelmingly positive," and said the purpose of the test was to "get feedback so we can implement safety and privacy protections and improve features before we release them publicly." Meta added that it will only roll the feature out publicly when it's ready and with proper disclosures.
The episode is a useful reminder of where agentic AI still stands in 2026: for tasks where an AI call might fail or a merchant might push back, Meta is hedging with actual humans. That pragmatism is reassuring in the short term — but it also means early users should understand that a "call placed by Muse" may, during testing, involve a person.
Who it's for — and who should wait
Worth trying now: People with US accounts who want to offload routine digital chores — scheduling, form-filling, bill-lowering, travel research, call-heavy errands like getting contractor quotes. The free tier makes experimentation cheap, and the WhatsApp integration lowers the barrier further.
Worth waiting on: Anyone outside the US, where Muse hasn't rolled out yet; people uncomfortable granting an agent access to email and payments; and anyone who needs guaranteed transparency about when a human is involved in a task. If Meta's privacy history gives you pause, waiting for the Confidential VM option later this year is a reasonable call.
Verdict
Muse is the most ambitious consumer AI agent launch of 2026 so far: a genuine attempt to move from chatbots that answer to agents that act, wrapped in a security architecture — Secure VM plus Sentinel — that takes the trust problem seriously. The free tier, the Stripe-powered payment protections, and the real-world traction (2.5 million downloads in two weeks) suggest Meta has a serious product on its hands.
The open questions are the ones that matter most: whether the automation saves enough time to justify the access it requires, whether the privacy architecture survives contact with Meta's business model, and how transparent the human-concierge fallback will be. If you're curious, the free tier is a low-risk way to test it — just read the permissions screen carefully before you connect your inbox.
References
- TechRepublic, "Meta Muse AI Agent Launches With Shopping, Travel Tools" (Sep 9, 2026): https://www.techrepublic.com/article/news-meta-muse-ai-agent-us-launch/
- Neowin, "Meta's new Muse AI agent can shop, send emails, and negotiate on your behalf" (Sep 9, 2026): https://www.neowin.net/news/metas-new-muse-ai-agent-can-shop-send-emails-and-negotiate-on-your-behalf/
- LiveMint (via Reuters), "Muse AI now hands over phone calls to human agents: Meta tests new feature in its personal assistant": https://www.livemint.com/ai/muse-ai-now-hands-over-phone-calls-to-human-agents-meta-tests-new-feature-in-its-personal-assistant-11790099365768.html