Meta announced Meta Muse on September 8, 2026 as a personal AI agent designed to do more than answer questions: it can browse the web, fill out forms, send emails, book travel, make purchases and work toward longer-running goals. That convenience comes with a sharper question than “Is the chatbot smart?”—who can access the environment where the agent is acting, and when does a human get the final say?

The initial U.S.-focused rollout was announced for iOS, Android, muse.ai and WhatsApp. Meta presents Muse as a way to delegate chores; its security design shows why delegation is also a privacy decision.

Muse turns chat into delegation

A conventional assistant gives you an answer. Muse is designed to take a request, operate a browser and move through several steps on your behalf. Meta says the system can research information, complete forms, handle email, organize travel, shop online and monitor goals over time.

The underlying model is Muse Spark, which Meta describes as its most capable model for real-world agentic work. In plain English, “agentic” means the software is expected to choose and carry out intermediate actions rather than waiting for you to spell out every click.

That distinction matters. Asking for a list of flights is one thing; asking an agent to find an itinerary, open a booking site and prepare the reservation is another. The latter requires access to a browser, personal context and potentially a payment flow.

The tasks and interfaces Meta is promising

Watch the official Muse product tour, including Chat, Feed, Ideas, Goals and Library.

Muse is presented through a dedicated app, its website and WhatsApp. The official product tour organizes the experience around five areas: Chat, Feed, Ideas, Goals and Library. The tour shows examples such as ordering movie tickets, planning a family trip, summarizing chess games and tracking longer-term tasks.

Meta also describes Muse as able to continue working after you close the app, returning when something changes or when it needs permission. A status view is intended to show what the agent is doing, what it has completed and what it plans to do next.

That does not mean every advertised workflow is a guaranteed outcome. The product tour is a curated presentation of the interface and intended use cases. A separate walkthrough shows browser research and a shopping flow that pauses for approval before payment, but it does not complete a real transaction. The useful takeaway is the workflow: Muse can prepare an action and stop at a checkpoint. The videos do not establish general reliability, security or successful purchases across the service.

Secure VM is isolation, not magic

Meta Muse acts for you—but trust comes first

Muse runs in a dedicated cloud environment called Muse Secure VM, with its own browser and user data. The goal is to separate the agent’s activity, credentials and data from other agents and the surrounding infrastructure.

A second layer, Sentinel, watches activity leaving that environment. It can match an action to an existing permission or ask the user to approve a sensitive step. This is the difference between containing an agent and letting it operate without supervision: Secure VM is the workspace; Sentinel is the gatekeeper for outbound activity.

Capability or controlWhat Muse is described as doingUser checkpoint or boundary
Web and app tasksBrowsing, filling forms, handling email, booking travel, shopping and managing goalsSensitive actions may require approval
Background workContinuing a task after the app is closed and returning when a change or decision is neededThe user can review the task status and respond to requests
Muse Secure VMRunning the agent in a dedicated cloud virtual machine with its own browserIsolation is not the same as cryptographic inaccessibility
SentinelReviewing activity sent from the VM to the internetIt can block or escalate an action for human approval
CredentialsKeeping passwords and payment methods in secure storage that Muse is not supposed to seeMeta’s stated policy does not by itself prove that the surrounding VM is technically inaccessible to Meta

This last distinction is the heart of the story. Meta’s policy can prohibit access to user data while the infrastructure still technically permits access under the initial design. David Singleton, Meta’s vice president of engineering for consumer products, described Secure VM as deliberately restricted, but not as a cryptographic lockbox that Meta could never open.

Meta has described Muse Confidential VM as a stronger planned architecture. It is intended to use a trusted execution environment and user-controlled access keys so that Meta itself would not be able to access the user’s virtual machine in the same way. On September 11, 2026, that remained a planned distinction—not a generally available guarantee to treat as part of the launch product.

Payments, permissions and the final checkpoint

Watch a Muse walkthrough showing browser research, Stripe Link and approval before the payment step.

Muse can use Stripe Link to generate a one-time-use card for purchases. Meta also describes Link’s agent purchase protections and says support for Shop Pay and 1Password is forthcoming.

The practical model is not “the AI has your credit-card number.” Meta says Muse cannot see passwords or payment methods stored in the secure credential system. Instead, the agent can prepare a purchase through an agent wallet or one-time card, while Sentinel and the approval flow are meant to stop sensitive actions from quietly going through.

The walkthrough shows this checkpoint in action: Muse researches a product, navigates toward checkout and displays a request for approval. The payment is not completed in that demonstration. That is an important boundary. A visible approval dialog proves that the workflow includes a human checkpoint; it does not prove that every purchase will be accurate, safe or successful.

Meta also says users can change permissions, disconnect services, inspect an audit trail, delete memories and opt out of using Muse interactions to train AI systems. Those controls make the product easier to manage, but they do not eliminate the underlying trade-off: an agent is more useful when it can reach more of your digital life.

U.S. access and reported pricing

The confirmed launch market in the supplied evidence is the United States, where Meta announced access through iOS, Android, muse.ai and WhatsApp on September 8, 2026. That does not establish a worldwide rollout or a release date for other countries.

The reported U.S. subscription structure includes a free tier and two paid plans at $20 per month and $100 per month. The free tier has a usage limit, but the quota is not specified here, and the available evidence does not establish what each paid plan includes.

Access or planU.S. marketReported price or channelReader-relevant condition
Free tierUnited StatesFreeUsage is limited; the quota is not specified
Paid planUnited States$20 per monthReported launch subscription tier; included limits are not specified
Paid planUnited States$100 per monthReported launch subscription tier; included limits are not specified
App and web accessUnited StatesiOS, Android, muse.ai and WhatsAppThese are the announced access points for the U.S.-focused rollout

For American early adopters, the immediate decision is therefore less about picking the right plan than deciding how much access to grant an agent whose strongest features depend on personal data, browser activity and connected services.

Why trust is the product’s hardest problem

The public reaction around Muse has focused heavily on Meta’s privacy reputation. Some users welcome the idea of an assistant that can monitor goals, search email or watch for useful opportunities. Others question whether a cloud-hosted agent can earn enough trust to handle communications, shopping and personal context—especially when the initial privacy promise rests partly on policy restrictions rather than a cryptographic barrier.

Those reactions are opinions, not evidence of a breach or misuse. They do, however, identify the product’s real adoption hurdle. Muse is not asking only whether you trust an AI model to write a paragraph. It is asking whether you trust an agent to act inside a browser, preserve context over time and stop when an action needs your approval.

The security vocabulary can obscure that choice. “Isolated” does not automatically mean “inaccessible to the provider.” “Human approval” does not mean the system cannot make mistakes before it reaches the approval screen. And a planned Confidential VM is not the same thing as a live feature.

What to consider before handing over access

If you are evaluating Muse in the U.S., separate five questions instead of collapsing them into one trust score:

  1. Capability: Does the task involve genuine delegation—research, monitoring or a sequence of web actions—or would a normal chatbot be enough?
  2. Permission scope: Which services, accounts and personal data must Muse reach for that task?
  3. Approval behavior: What actions require your confirmation, and can you see what the agent has done before approving the next step?
  4. Technical privacy: Is the protection based on policy and service controls, or on hardware-backed and user-controlled access that prevents the provider from entering the environment?
  5. Market and price: Is the service actually available to you, and do the reported plan limits justify the cost?

Meta Muse makes the personal AI agent concrete: it is designed to browse, prepare actions and keep working after a conversation ends. Its controls—Muse Secure VM, Sentinel, credential separation and human approval—address important risks, but the initial architecture does not turn policy into cryptographic impossibility. For now, the central product feature is not simply autonomy. It is the checkpoint where you decide how much autonomy to allow.