Meta Muse agent is launching in the United States as a personal assistant that can act across email, travel, shopping and payment services. Meta is moving beyond answers and drafts toward software that can keep working in the cloud, open websites and carry out approved transactions.

 

The launch combines three consequential elements:

  • Autonomous work across connected apps and websites
  • A dedicated Secure VM monitored by a separate Sentinel agent
  • Free access plus paid plans for heavier use

 

Meta Muse Agent Connects to Everyday Apps

Meta says Muse is rolling out on iOS, Android and muse.ai, with access also available through WhatsApp. The initial release is limited to adults in the United States, while support for Meta's AI glasses is planned for a later stage.

 

The agent can send email, arrange travel, fill out forms and help negotiate on a user's behalf. Meta also presents Muse as a longer-running system: after receiving a goal, it can develop a plan, coordinate time and resources, and continue advancing work after the app closes.

 

That persistence separates Muse from a conventional chatbot session. Each agent operates inside a cloud-hosted virtual computer with its own browser, allowing tasks to continue in the background until circumstances change or the system needs the user's approval.

 

Meta says most usage will be free. Reuters reported two subscription tiers priced at $20 and $100 per month for people who want higher usage, adding a direct revenue model to a product that also extends Meta's wider personal-superintelligence strategy.

 

Muse Secure VM and Sentinel Control Sensitive Actions

The central architecture is Muse Secure VM, a dedicated environment where an individual agent runs and where connected-service data and credentials are stored. Meta says one user's agent cannot reach another user's environment, limiting the blast radius if a task encounters malicious content.

 

A separate Sentinel agent evaluates activity leaving the virtual machine. According to Meta, Sentinel either matches an action to an existing permission or presents an approval request directly to the user, including before sensitive actions such as sending an email or completing a purchase.

 

Muse is designed not to see passwords or payment credentials directly. Meta says account secrets remain in secure storage, while Stripe's Link system can generate a single-use card number for purchases so a user's actual card details are not entered across merchant websites.

 

Users choose which services to connect and whether Muse receives read-only or action-taking access. They can disconnect services, inspect an activity trail, tell Muse to forget information and opt out of having interactions used to train Meta's models. Meta says VM data is not shared with its advertising systems.

 

A stronger Confidential VM option is planned for later in 2026. Meta says that version will use a key controlled locally by the user, with the aim of preventing even Meta from accessing the agent's environment, conversations and stored data.

 

More on This Story

 

Internal Tests Complicate Meta's Security Pitch

The release arrives with unresolved reliability questions. Reuters reported that internal testers saw frequent logouts, silent failures during monitoring tasks and an incident in which an agent exposed personal iCloud photos while responding to a request about images from a child's birthday party.

 

Meta did not respond to Reuters' request for comment on those specific incidents. The company said it had delayed Muse from an earlier April release to improve security and had concluded that the product reached the minimum threshold needed for public use.

 

Those accounts do not establish that every user will encounter the same failures, but they sharpen the risk inherent in personal agents. A chatbot error can produce a bad answer; an agent error can send information, alter an account, make a purchase or silently stop a time-sensitive task.

 

The approval boundary will therefore be as important as the model itself. Muse must distinguish routine delegated work from actions that deserve a fresh human decision, while also resisting instructions hidden inside web pages, emails or documents that the agent encounters during a task.

 

Meta Moves From Chatbots to Delegated Work

Muse places Meta in direct competition with personal agents built to operate browsers and third-party services. Reuters reported that the product, previously known internally as Hatch, was modeled on the open-source OpenClaw agent, while Meta's Muse Spark model supplies its planning and tool-use capabilities.

 

The launch also turns security design into a consumer feature. Secure VMs, permission controls and Sentinel approvals are not background infrastructure in Meta's pitch; they are the reasons users are being asked to trust an autonomous system with calendars, inboxes, purchases, health information and smart-home services.

 

Early adoption will show whether that argument is persuasive. The clearest signals will be task-completion reliability, how often approval prompts interrupt useful automation, the severity and transparency of disclosed incidents, and whether people grant Muse the broad app access needed to deliver its promised convenience.

 

For Meta, the technical milestone is not simply producing another assistant. It is putting a persistent agent in front of mainstream users with permission to take real-world digital actions. The product's success will depend on whether its control systems prove as capable as the agent they are meant to contain.