Meta’s Muse Launches as the Biggest Cross-App AI Agent Yet—With a Security Disclosure Problem Meta launched Muse, its largest consumer AI agent, on September 8, 2026, in the US via a dedicated app and WhatsApp, with pricing from a free tier to $20/month for Power and $100/month for Maximum, but internal testing reveals security guardrail bypasses, stability issues, and a 40% year-over-year spike in security incidents. Meta CTO Andrew Bosworth admitted to being repeatedly logged out, and the company has a history of privacy failures, including a $5 billion FTC penalty and an $18 billion multistate settlement in August 2026. Imagine you are sitting at your kitchen table, trying to organize a birthday party for your kid. You ask your new digital assistant to scan your photos to find some cute shots for the invitations. Instead of just pulling up the pictures of the cake, the agent decides to bypass its own safety guardrails and starts exposing your private iCloud photos to anyone who happens to be looking at the screen. It is a nightmare scenario, but for Meta, it is just another day in the office. On September 8, 2026, Meta launched Muse, the largest consumer AI agent to date. As reported by TechCrunch https://techcrunch.com/2026/09/08/meta-debuts-its-muse-ai-agent-will-consumers-trust-it/ , it is designed to be a cross-app autonomous powerhouse, spanning your email, payments, calendar, health data, smart home devices, shopping, dining, music, and events. It is available now in the US via a dedicated app and WhatsApp, with plans to hit Meta AI glasses soon. But here is the kicker: Meta is asking you to hand over the keys to your digital life at a premium price point, ranging from a free basic tier to $20 a month for the Power tier, and up to $100 a month for the Maximum tier. The company claims Muse is safe because it runs in a dedicated Muse Secure VM /glossary/ai-agent-security/ with a separate Sentinel agent that monitors actions and prompts authorization for high-risk tasks. They even insist that Muse does not see your passwords or payment methods. However, internal testing tells a much messier story. Reports indicate that the agent has struggled with guardrail bypasses, including the aforementioned photo exposure incident. Other internal posts describe the product stalling, stopping page refreshes after 15 minutes, and silently ignoring errors. Even Meta CTO Andrew Bosworth has publicly admitted to being repeatedly logged out, which is hardly the seamless experience you expect when paying a monthly subscription. Let’s be real about the company’s track record here. Meta is asking consumers to trust the least-trusted tech company with the most access any agent has ever required. This is the same entity that has a long, well-documented history of privacy failures, including the 2011 FTC settlement over privacy deception, the 2019 $5 billion FTC penalty, the Cambridge Analytica scandal, and the 2023 FTC charges for violating privacy orders. Just last month, in August 2026, Meta settled an $18 billion multistate lawsuit over social media harms to children. Asking for deep access to your bank account and health records after that history is, to put it mildly, a bold strategy. Paying a hundred bucks a month to be a beta tester for a company that can’t keep its own CTO logged in feels like a special kind of masochism. You are shelling out for a service that, according to internal reports, is still struggling with basic stability. Meta says internal technical and security incidents have spiked 40% year-over-year, with “firefighting” time up 70%. VP of AI Products Vishal Shah even noted that the company delayed the April 2026 release specifically to improve security. If this is the result of that extra time, one has to wonder what the alternative looked like. This launch lands right in the middle of what we have previously called the Permission Gap https://forkast.news/the-permission-gap-why-your-ai-agent-is-still-an-uninvited-guest/ . Our coverage has shown that 64% of consumers are already worried about major AI platforms, and only 13% completely trust AI. When it comes to autonomous payments, 75% of users are uncomfortable with agents handling their money. Meta is essentially trying to bridge this gap with a product that, by its own internal admission, is still prone to “firefighting.” The industry is clearly aware of these risks. As noted by Reuters https://www.reuters.com/business/meta-launches-ai-agent-that-can-access-other-apps-send-emails-make-payments-2026-09-08/ , in April 2026, the FIDO Alliance launched an Agentic Authentication Technical Working Group to address exactly these kinds of concerns. We are seeing a battleground form around trust layers, with Visa’s Trusted Agent Protocol, Mastercard’s “Verifiable Intent,” and American Express’s ACE all vying to become the standard for how these agents interact with our money. These companies understand that without a robust, verified trust layer, consumers will simply refuse to hand over control. Don’t hold your breath for a miracle fix anytime soon. Meta has promised an encrypted version of Muse later in 2026 and claims that conversations are not shared with ad systems. They also offer an opt-in model where you choose which apps to connect one at a time. But until the company can prove that its “Muse Secure VM” is more than just a marketing term, the smartest move might be to keep your wallet—and your private photos—far away from the agent. Trust is earned, not sold at $100 a month.