Image credit: Screenshot via Meta composited by ChatGPT
Yesterday, Meta introduced Muse, an AI agent it says can book your travel, negotiate on your behalf, fill out forms, and pay for what it buys, all without your constant supervision. Meta calls it "a secure, private personal AI agent that proactively helps people meet their goals and suggests ideas."
Muse runs on Muse Spark, the company's model built for autonomous work, and Meta says it can keep working after you close the app, then come back to you only when it needs a decision. It can also turn saved content, a recipe reel you bookmarked, for instance, into a shopping list or a set of steps, and it's meant to remember your preferences well enough to suggest things before you ask.
Muse is rolling out now in the United States on iOS, Android, and a new muse.ai site, with support for Meta's AI glasses coming later this year. Basic use is free, and Meta plans paid tiers for expanded capabilities, though it hasn't said what those tiers cost. Alexandr Wang, Meta's chief AI officer, told Axios that the free version should cover most people: "For the vast majority of users, they should be able to do what they need to within the free tier."
An agent that can spend money and act as you is a much bigger risk than an app that just stores your data, and Meta's pitch rests on its security setup. The company says Muse runs inside Muse Secure VM, a dedicated, isolated virtual machine set apart from your phone and Meta's regular cloud infrastructure. A second system called Sentinel sits alongside it, reviewing and approving every internet request Muse makes before it goes out.
The purpose is to wall off what Muse can touch. Meta says your credentials are stored inside that setup in a way that keeps Muse itself from ever seeing your passwords or payment details, even while it's using them to log into a site or complete a purchase through Link by Stripe. You get a notification before anything sensitive happens, and Meta says it keeps a full audit trail of what the agent did. A more locked-down option, Muse Confidential VM, with end-to-end encryption, is coming later.
This is all a big ask considering the company's record of privacy violations. The FTC settled with Meta (then Facebook) in 2011 over charges that it told people they could keep their information private and then repeatedly allowed it to be shared and made public. The FTC fined the company $5 billion in 2019 for violating the consent agreement stemming from the 2011 settlement, and charged Meta again in 2023 with violating that same privacy order, as well as the Children's Online Privacy Protection Act Rule (COPPA Rule). None of that is about Muse specifically, but it's the record Meta wants you to set aside when you consider whether to use Muse.
Muse has another weakness that plagues autonomous AI agents generally, including competitors like Gemini Spark and ChatGPT's agent mode. If an agent asks for your approval before every sensitive action, and you're using it precisely because you want to skip the busywork, the natural response is to click through those requests without reading them closely. Anthropic has already recognized this in its own AI coding tool, Claude Code: users approved 93 percent of permission prompts, a rate the company says leads to what it calls "approval fatigue," a state where people stop paying close attention to what they're approving.
If you want to try Muse, it's available now through the App Store, Google Play, or muse.ai. Start with the free tier, and before connecting anything tied to money or sensitive accounts, check what permissions you're granting. I'd do that before handing over more than the basics, given what you're being asked to trust it with. If things go south, Meta says you can review and revoke Muse's access at any time.