The GenAI Field Guide · Trending

Meta Muse

Meta's consumer personal agent: a Muse Spark model running in your own cloud VM, with a separate guard agent that must approve anything leaving the machine.

Muse is a personal agent from Meta that works in the background on errands and goals, reachable from its own app, the web, WhatsApp and a Mac app, and free for most use in the US. Its most interesting part for engineers is the security design: a per-user VM, a second agent called Sentinel that gates all network egress, surrogate credentials and single-use payment cards. Anyone designing agents that act on a user's accounts should read how it is built, and anyone in IT should expect staff to connect it to work apps.

What it is

Meta announced Muse on 8 September 2026 as a personal AI agent that, in its words, does the work rather than only answering questions. You give it tasks such as sending an email, booking travel, filling a form or lowering a bill, or a larger goal that it turns into a plan. It keeps working after you close the app and comes back when it needs your approval. You message it like a person, in the Muse app, on muse.ai, or directly in WhatsApp, and you can give it a name and an avatar. Under the marketing it is a long-running agent loop with a browser, a filesystem, memory and a connector layer, sold as a consumer app rather than an API.

It runs on Muse Spark, Meta's agentic model; the model post dated 2 September 2026 describes version 1.3 and says it is also available through Muse Code and the Meta Model API, with open weights only on the roadmap. Meta has extended Muse quickly since launch: a Mac app around 17 to 18 September (sources differ on the day), a connector platform for developers, retail and productivity connectors announced at Connect on 23 September, glasses support promised for the coming months, and Muse for Small Business on 29 September, which connects to Facebook and Instagram business accounts, ad accounts and tools such as Shopify, QuickBooks, Slack and Stripe.

TechCrunch framed the launch around trust: Meta is asking for access to email, calendars, payments and health apps while carrying a record that includes FTC settlements and stored-password failures. Meta's answer is architectural, which is why most of what follows is about the security model rather than features.

How it works

Each user gets a Muse Secure VM, which UploadVR describes as a private persistent Linux machine in Meta's cloud with its own browser, filesystem and terminal. Meta's safety post says the agent daemon runs inside a systemd-nspawn container where root is mapped to an unprivileged host user, and the security services run outside that container so a compromised agent cannot switch them off. Meta calls this two isolated security domains on one box.

The second domain is Sentinel, a separate agent on the same machine. Nothing Muse does reaches the internet unless Sentinel approves it. For each connector action or network request it decides allow, deny or ask the user, looking at hostname, resolved and final IP, port, protocol, HTTP method, path and the decoded request. Credentials (OAuth tokens and website passwords) stay in the user's VM; the agent only ever holds surrogate tokens, and Sentinel swaps in the real credential at the network boundary. Purchases go through Link by Stripe with a single-use card number, and every payment needs human approval showing the exact details.

Approvals are bound to a connector and a use case and can be one-time, session, task, time-bounded or perpetual; read-only and low-risk actions proceed on their own. Against prompt injection Meta lists model training, an ensemble of injection classifiers, harness rules that mark external data as untrusted, and browser classifiers that inspect the page DOM and images. The design notes add an activity log, a permissions view, readable memory files, structured approval cards for hard-to-undo actions, and a forget command.

Meta is explicit that the Secure VM isolates users from each other, not from Meta. A Muse Confidential VM, where the VM and conversations are encrypted with a key only the user holds, is promised for later in 2026. Meta also says Muse data is not shared with its advertising systems and that you can opt out of training on your interactions. There is no developer API for Muse itself; developers can submit connectors (an MCP server or a REST API, according to secondary coverage) for review through the Muse connector platform.

How to use it

You need to be in the US and, per secondary coverage, 18 or older. The base product is free; paid plans buy more weekly usage. Muse for Small Business is available in the US and Canada.

  1. Install Muse on iOS or Android, or sign in at muse.ai. You can also message it in WhatsApp once set up.
  2. Connect only the apps the first task needs, and set each connection's access level. Meta lets you change or disconnect any service at any time.
  3. Before giving it real errands, open the permissions view and decide which approvals stay one-time. Keep sending, sharing and paying on one-time approval until you trust its behaviour.
  4. If you want it to buy things, use Link by Stripe so purchases go through single-use cards; leave other payment routes off until they are documented.
  5. On a Mac, install the Mac app only if a task needs local files or Mail and Notes, and leave Full Disk Access off unless you need it.
  6. Review the activity log and memory after the first few tasks, and use forget on anything it learned that you do not want kept.
  7. For a business, start at muse.ai/business and connect your Facebook or Instagram business account plus one tool such as QuickBooks or Shopify.

Use cases

Sources

  1. Introducing Muse, your personal AI agent, Meta, 2026-09-08
  2. Security and safety for AI agents: our approach with Muse, Meta, 2026-09-08
  3. How we designed Muse, Meta, 2026-09
  4. Introducing Muse Spark 1.3, Meta, 2026-09-02
  5. The Biggest News From Connect 2026, Meta, 2026-09-24
  6. The Future Is for Everyone: Muse for Small Business, Meta, 2026-09-29
  7. Muse connector platform, Meta, 2026-09
  8. Meta debuts its Muse AI agent. Will consumers trust it?, TechCrunch, 2026-09-08
  9. Meta is expanding its AI agent Muse to small businesses, TechCrunch, 2026-09-29
  10. Meta's Muse agent has some new skills targeting small businesses, Engadget, 2026-09-29
  11. Meta gives small businesses an AI agent that knows their work, Help Net Security, 2026-09-29
  12. Meta's Smart Glasses Are Getting Its Muse AI Agent, UploadVR, 2026-09-28
  13. Meta Launches Muse for Mac, MarkTechPost, 2026-09-19
  14. Meta expands Muse agent connections, launches Muse for Mac, Social Media Today, 2026-09-20
  15. Meta's Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool, Cyber Security News, 2026-09-22
  16. Meta Muse review: what the personal AI agent can and can't do, eesel AI, 2026-09-09
  17. Meta Muse Pricing 2026: Free, Power $20, Maximum $100, Carly, 2026-09-30