Meta Launches Muse, an AI Agent That Can Email, Book Travel and Pay With Your Card Meta launched Muse, an AI agent that can connect to a user's email and accounts, fill out forms, negotiate and complete purchases using a linked payment method, on September 8 in the United States across iOS, Android, the web and WhatsApp for users 18 and older. Meta built Muse around Stripe's Link wallet, which issues a single-use card number tied to a specific merchant, dollar amount and time window so the agent never sees the user's actual card number, and Meta says every payment requires the user's explicit approval. A free tier is available alongside paid plans at $20 and $100 a month, with support for Meta's AI glasses planned for a later date. Meta introduced a new AI agent called Muse on September 8, expanding the company’s consumer AI lineup into territory that goes well beyond chat. Unlike a typical assistant that answers questions, Muse can connect to a user’s email and other accounts, fill out forms, negotiate on someone’s behalf and complete purchases using a linked payment method. The launch matters now because it pushes the debate over AI-agent accountability out of niche financial products and into everyday consumer spending. Meta is rolling Muse out in the United States across iOS, Android, the web and WhatsApp, with access limited to users 18 and older. A free tier is available alongside paid plans priced at $20 and $100 a month for users who need heavier usage, and support for Meta’s AI glasses is planned for a later date. For tasks that take time to complete, Muse can keep working even after the user has closed the app. What makes Muse notable is not the subscription pricing but the scope of authority Meta is granting the agent. It can operate across a person’s inbox, browser and travel bookings, then move all the way through to checkout, a level of autonomy that turns a chatbot launch into a payments story with real dispute and liability questions attached. Muse Ties an AI Agent Directly to a Payment Card Meta has built Muse around Stripe’s Link wallet for checkout. According to Meta, the agent itself never sees a user’s actual card number. Instead, when a purchase requires payment credentials, Link issues a single-use card number tied to a specific merchant, a set dollar amount and a limited time window. Meta says every payment still requires the user’s explicit approval before it goes through. The same safeguard applies when a retailer already has a user’s card on file. Meta says Muse recognizes when it has reached a checkout page and surfaces the full transaction details, including price and merchant, for the user to confirm before anything is charged. What the Safeguards Do and Do Not Solve Restricting the agent to single-use, merchant-locked credentials removes one of the more obvious dangers of letting an autonomous system handle payments: an AI model holding an unrestricted, reusable card number. It does not resolve the more complicated question underneath it. By the point a user taps approve, Muse has typically already picked the merchant, negotiated any terms, filled out the necessary forms and interpreted what the user actually wanted. If that judgment goes wrong somewhere upstream, the resulting dispute looks different from an ordinary case of an unauthorized card charge. Stripe Link offers purchase protections on eligible Muse transactions, covering situations like damaged or lost goods, post-purchase price drops and returns. Those protections address the mechanics of the payment itself. They do not settle who is responsible when the underlying problem was a bad decision the agent made earlier in the process rather than a flawed transaction. Muse Runs Inside an Isolated Cloud Environment | Component | Function | |---|---| | Muse Secure VM | Dedicated virtual machine in Meta’s cloud holding the agent and the user’s connected data | | Muse Spark | Meta’s underlying model built specifically for agentic tasks | | Sentinel | Separate agent that reviews actions and internet access before they execute | Each instance of Muse operates inside what Meta calls a Muse Secure VM, a virtual machine dedicated to that user’s session and connected accounts. The agent itself runs on Muse Spark, a model Meta built for agentic work rather than general conversation. A separate system, Sentinel, reviews the actions Muse wants to take and the internet access it requests before allowing them to proceed. User Controls Over Permissions Users choose which services Muse is allowed to connect to and how much access each one gets, down to whether the agent can only read an inbox or also send messages from it. Meta says those permissions can be revoked at any time, and Muse is designed to ask for confirmation before sensitive actions such as sending an email or completing a purchase. Why the Architecture Is Arriving Now Financial platforms have been building toward similar constraints from a different angle. FinanceFeeds reported on September 1 that MoonPay’s PayBox connects to Grok through a custom connector that users must add and authorize themselves before the assistant can prepare supported crypto and payment actions. Two days later, Binance extended its own approach with Agent OS, letting AI agents trade through dedicated subaccounts with defined permissions instead of granting direct access to a user’s primary account. Muse applies that same permissioned-access logic to a far larger, mainstream audience. Where the earlier examples involved trading accounts and crypto subaccounts, Meta is now putting an AI agent between an everyday user’s inbox, browser, travel bookings and payment card. The Unresolved Question Behind the Approvals Meta has built explicit approval steps and single-use payment credentials around the moment money actually changes hands. What remains unsettled is what happens one step before that: when a human clicks approve on a transaction, but an AI agent made most of the choices, the merchant, the terms, the interpretation of what was wanted, that led to that transaction existing in the first place. As agentic commerce tools like Muse reach more users, that liability gap is likely to become the central issue regulators and payment providers have to work out.