Meta launched Muse yesterday — a personal AI agent that runs in its own dedicated virtual machine, opens a browser, fills out forms, books appointments, shops, and negotiates on your behalf. It keeps working after you lock your phone. It’s live now for US users on iOS, Android, and muse.ai. And it’s built by the same company that two months ago pulled its Muse Image feature three days after launch for silently training on your Instagram photos without asking.
What Muse Actually Does #
Muse is not a chatbot with memory. It’s a browser agent with a dedicated Linux VM in Meta’s cloud — your own isolated virtual machine with storage, CPU, and a visible browser. You give it a goal; it works the problem. It books a restaurant, fills out your kid’s school permission slip, reschedules a tennis lesson, or negotiates a price on your behalf. It integrates with your email, calendar, Instagram, financial accounts, and smart home. It runs asynchronously, so while you’re in a meeting, Muse can be three tabs deep in a ticket-buying flow.
Payments work through Stripe Link, which issues a single-use card number per transaction. Muse never sees your actual payment credentials. That’s not a small detail — it’s the difference between an agent you can hand a task and one you have to babysit.
The Security Model: Secure VM and Sentinel #
The architecture is worth understanding if you build on agents. Every user gets a Secure VM — an isolated container that holds the agent and your connected data. A separate process called Sentinel runs at the system level and acts as a gatekeeper for all outbound actions. Muse proposes something; Sentinel decides whether it’s allowed or whether to ask you first. As Tarek Sheasha, VP of Meta Superintelligence Labs, put it: “The harness runs in its own isolated cell, it doesn’t see real credentials, and every interaction with the outside world runs through a Sentinel which the agent can’t override.”
Meta also says Muse data is not fed into its ad systems, and a Confidential VM version is planned for later this year — where even Meta cannot access your environment, cryptographically verified. That would be a meaningful privacy guarantee if they ship it. You can read Meta’s technical writeup on the Sentinel safety architecture for the full implementation details.
Pricing: Free Is the Real Story #
Three tiers: free, $20/month (Power), and $100/month (Maximum). The free tier comes with roughly 100 million tokens per week — approximately 400 million characters. Meta’s AI chief says the free tier covers the “vast majority” of users. Paid plans buy more agent cycles, not extra features, which is an interesting model choice. At $20, you’re competitive with other productivity subscriptions. At $100, you’re in territory where the automation needs to justify the cost in saved time.
The Part Meta Needs You to Forget #
In July 2026, Meta launched Muse Image — a feature that let any user generate AI images by tagging a public Instagram account, drawing on that account’s published photos without notifying the owner. It was pulled three days later after an immediate backlash from creators, privacy groups, and talent agencies. A Reuters test found Meta’s own watermark detector missed 55% of cropped outputs. Meta said they “missed the mark.”
Now they want you to give Muse access to your email, calendar, payments, and smart home. The Secure VM architecture is a genuine attempt to address this, and Confidential VM would go further. But architecture promises and shipping behavior are different things. Meta’s ad-based business model does not go away because Muse says it isolates data.
The Strategic Signal: Meta Goes Closed #
Muse runs on Muse Spark — Meta’s first closed frontier model. After years of open-sourcing Llama and building credibility in the developer community, Meta has decided the personal AI layer is too valuable to give away. Zuckerberg’s stated goal is “personal superintelligence” for every user, and Spark is the model powering it. Muse is also coming to Meta AI glasses, setting up a hardware integration play. Separately, Muse Code — a coding agent competing with Cursor and Claude Code — has its own pricing at $5–$50/month or pay-as-you-go rates.
The personal AI agent market now has credible entries from Meta, OpenAI (ChatGPT Work), and Google. The technical differentiation is real: Meta’s Sentinel gatekeeper model and VM isolation are thoughtful. Whether developers build on it — and whether users trust it — depends on whether Meta’s behavior matches its architecture promises. The engineering here earns respect. The trust has to be earned back.