A hands-on review published September 20 found that Meta Muse could help with web tasks while repeatedly suggesting that the user connect sensitive information. In the several-day test, Muse added a bakery order to a pickup cart and searched for couches on Facebook Marketplace; it also prompted the user to connect financial accounts, email, documents, and identity information.
Meta announced Muse on September 8, 2026, describing it as a personal AI agent and announcing an initial U.S. rollout through iOS, Android, and the web.
What Muse did in the hands-on test
Muse added a bacon, egg, cheddar, and garlic-aioli biscuit sandwich to a Kahnfections pickup cart. The checkout process paused for final approval. In a separate task, Muse found local couches on Facebook Marketplace and followed up about a listing the user liked.
Those examples show the appeal of delegating steps to an agent: it can browse and prepare an action, rather than just suggest what you could do. In the test, the user still had to approve the checkout.
The prompts reached into sensitive categories
The test recorded repeated suggestions to connect checking and savings accounts, scan an inbox, provide documents, and share passport or driver’s license expiration details. The prompts were observed; they do not mean every account or document mentioned was connected.
That distinction matters when an agent’s usefulness depends on access to personal context. A suggested connection is not the same as a completed connection, but it can still shape what information a user considers sharing.
Meta’s controls have different jobs
Meta says each user’s Muse runs in an isolated cloud virtual machine, or VM. The company describes Sentinel as a separate system that governs permissions for connected services and outbound network activity. It also says credentials are stored apart from the agent’s runtime, so the main agent does not see real credentials.
Meta’s description of the launch architecture also says the company can access VM data when needed to operate, support, or secure the service. Isolation and permission checks are part of Meta’s stated design; they do not prevent that operational access.
Meta says Muse conversations and VM data are not shared with its advertising systems. Browsing or shopping through Muse can still affect ads indirectly through ordinary web-tracking signals.
Training data and Memory are separate controls
Meta says the setting that allows Muse interactions to be used to develop and improve AI models is on when someone first uses Muse. Users can turn it off under Data controls, and Meta says the change also applies to previous interactions.
Memory is a different feature: it retains information and preferences for future tasks. In the tested version, the Memory document could be edited or cleared by asking Muse, but the reviewer found no switch to disable Memory altogether. Meta’s help guidance says deleted content may remain in learned memories until the user uses Muse’s forget function.