- Muse launched in the United States on September 8, 2026, through iOS, Android, the web and WhatsApp, with AI-glasses support planned. <sup>[1]</sup>
- The agent can connect to email, calendars, Instagram and other services; TechCrunch reported that the broader launch also includes potential connections to health and fitness, smart-home, dining, shopping, music and event services. <sup>[2]</sup>
- Muse runs in a dedicated cloud virtual machine, while a separate Sentinel system controls network access and connector actions. Credentials are stored outside the agent’s runtime so the model does not see users’ real passwords or payment details. <sup>[3]</sup>
- Meta says conversations and VM data are excluded from its ad systems, but sanitized interaction data may be used for model training by default unless users opt out. <sup>[3]</sup>
Meta has launched Muse, a personal AI agent that can connect to services such as email and calendars, browse the web and take actions including sending messages, booking travel and making purchases. It became available in the United States on September 8, 2026, through dedicated iOS and Android apps, the web and WhatsApp. Meta says support for its AI glasses is coming. [1]
The launch places Meta alongside consumer-agent competitors including OpenClaw and Instinct, but its main differentiator is the security architecture around delegated access. Muse runs inside a dedicated cloud virtual machine, while a separate system called Sentinel controls network access and actions involving connected services. [3]
What Muse can access and do #
Muse is designed to work across services that contain personal context. Meta’s product and technical materials identify email, calendars, Instagram, Facebook and other third-party systems as potential connectors. TechCrunch reported that the broader product is intended to work with services involving health and fitness, smart-home controls, dining, shopping, music and events, although the exact connector set may vary by service and rollout. [2][3]
The agent can use its own browser to search websites, fill out forms, book appointments, handle customer-service tasks and complete transactions. It can continue working after the user closes the app, return when a task changes or ask for approval before a consequential step. Meta also says Muse can create custom connectors for services with public APIs or command-line interfaces. [1][3]
Email permissions are more granular than a single all-or-nothing connection where the underlying service allows it. Meta says users can choose whether Muse reads email or can also send messages on their behalf. Users can change access, disconnect services and inspect an activity log showing what the agent has done and plans to do. [1][3]
The available material describes access to health and fitness services, but it does not establish that Muse is a medical device, that it can safely interpret clinical data or that it has been independently validated for health guidance. Those uses should be treated as product claims and potential integrations, not medical functionality.
The control layer is separate from the model #
Meta says Muse is powered by its Muse Spark model family. Meta’s latest public model announcement, dated September 2, 2026, identifies Muse Spark 1.3 as a model improved for long-horizon agentic work. The consumer launch announcement does not explicitly state which Muse Spark checkpoint serves every Muse request, so the exact production model configuration remains undisclosed. [1][4]
The core agent runs inside an isolated Linux container on a dedicated virtual machine. Credentials and authentication tokens sit outside that runtime in a separate store. Host-side services mediate access to connectors, the browser and external infrastructure. Meta says the model receives surrogate credentials rather than users’ real passwords or tokens. [3]
Sentinel is the permission authority for network egress and connector actions. It evaluates the destination, request and scope, then allows, blocks or sends an approval request directly to the Muse client. The approval does not travel through the conversational model, a design intended to reduce the chance that malicious web content or prompt injection can manipulate a confirmation. [3]
Meta says routine, read-only or previously authorized actions may proceed without a new prompt, while higher-risk actions can require one-time, task-scoped, time-bounded or continuing permission. Users therefore do not necessarily approve every action individually; the behavior depends on the connector policy and permission scope. [3]
For purchases, Muse uses Stripe Link at launch. Meta says the system generates a single-use card number tied to a merchant, amount and limited validity period. The user must approve checkout actions, and eligible purchases receive Link’s stated protections. Shop Pay and 1Password support are planned. [1][3]
What Meta retains and what remains unresolved #
Meta says files placed in the VM, generated files and the agent’s memory remain there and can be inspected, edited and downloaded. The VM is continuously backed up. Meta also says Muse conversations and VM data are not shared with its advertising systems, although browsing and transactions carried out by the agent can still create activity that influences advertising elsewhere. [3]
The training policy is less restrictive than the advertising boundary. Meta says conversations, tool calls and subagent handoffs may be sanitized to remove key personally identifying information and used to train future model checkpoints. Users can opt out through a setting, but the default is participation. [3]
The launch system isolates users’ data and restricts Meta personnel through operational policies, but Meta’s technical documentation explicitly says those controls do not prevent Meta from accessing data when necessary to support, secure or operate the service. A planned Muse Confidential VM is intended to encrypt the environment with a key controlled by the user so Meta cannot access its contents. Meta says that system is being tested and is planned for later in 2026. [3]
That distinction leaves Muse’s strongest privacy promise partly in the future. At launch, the product offers granular permissions, credential separation and action confirmations, but users still have to trust Meta’s infrastructure and policies with email, calendar, health-related and financial context. Meta also acknowledges that prompt injection remains an open problem and that Muse will sometimes make mistakes. [3]
TechCrunch reported two paid tiers at launch: Power at $20 per month and Maximum at $100 per month, with higher usage limits for delegated tasks. Meta’s own launch announcement confirms free access with subscription plans but does not list those prices. [1][2]
Muse’s security model is therefore best understood as containment and permission management rather than proof that the agent cannot be compromised or that Meta cannot access data. Meta has opened a bug bounty offering up to $300,000 for qualifying reports, including prompt-injection findings, but independent researchers had not yet publicly validated the full production system at launch. [3]
Companies mentioned #
Further sources #
[\[1\] Meta’s September 8, 2026 launch announcement describes Muse’s U.S. availability… ↗](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/)
[\[2\] TechCrunch reported Muse’s connected app categories, health and fitness use cas… ↗](https://techcrunch.com/2026/09/08/meta-debuts-its-muse-ai-agent-will-consumers-trust-it/)
[\[3\] Meta’s technical security post describes the Secure VM architecture, Sentinel, … ↗](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse)
[\[4\] Meta’s September 2, 2026 model announcement describes Muse Spark 1.3’s agentic … ↗](https://research.meta.ai/blog/introducing-muse-spark-1-3)
The stories that matter, in one email. Free — unsubscribe anytime.