Muse is Meta’s personal AI agent — it carries out tasks in its own secure VM across the apps you connect. What it does and who makes it →
How it works — and where it stands
What it does: you give it a goal or an everyday task and it works across the apps you connect — reading mail, filling forms, watching for changes, carrying a task across days. Meta’s own framing: “It doesn’t just answer questions, it actually does the work.”
How it’s built: agent and your data live together in a dedicated virtual machine — the announcement’s Muse Secure VM — and you reach it through the Muse app, WhatsApp, or muse.ai. You pick which apps it connects to and how much access each gets: read-only, or read plus act. It is designed to ask before sending an email or making a purchase, and payments run through one-time-use cards.
Where it stands after month one: a macOS researcher found a serious 0-day (Meta hotfixed it within roughly twelve hours, per Ars Technica), ZDNET’s head-to-head testing rated Muse worst for privacy, and NPR’s headline asked the question everyone else was asking — “Killer app? Security nightmare? Both?” The dated, source-linked record is on our safety page.
What people use it for
The four uses the product’s own documents point at — each worth copying carefully:
Everyday errands, given as goals
The homepage’s own scope — “from finances and health to shopping and the people you care about.” The boring errands are the point: the agent holds the task so you stop holding it in your head.
Watching things that change
Prices, availability, schedules — the recurring checks an agent can run without you asking each time. The calendar connector even pushes updates to Muse when your schedule changes.
Research with follow-through
It gathers, remembers where it left off, and picks the thread back up — the structural difference from a chat window, which forgets you the moment it answers.
Acting on your behalf — with the leash on
Sending, booking, buying are the features that make it useful and the ones every clause in the terms is about. Keep confirmations on; the September incident reports all involve action authority.
Is it free? How do you get it?
Announced September 8, 2026, rolling out in the US on iOS, Android, and muse.ai — no invite list, unlike rival Instinct . The pricing split is Meta’s own: “It’s free for most of what people need, with subscription plans for people who want to do more.” The Google Play listing (“Muse from Meta”) already shows in-app purchases, and the terms let Meta end free access “at any time and without prior notice” — free is a fact with a date, not a promise. Early adoption is real: 4.9 stars from 62.6K Play reviews, updated October 6, 2026.
Is Muse AI safe? — the clause-by-clause check →
Layered answer: the architecture is unusually strong — credentials Muse cannot see, conversation and VM data walled off from Meta’s ad systems, approval checks that run outside the AI model, and a training opt-out that even applies to past interactions. The first month is also the roughest record in the category: a patched 0-day, a “worst for privacy” verdict from ZDNET’s testing, and reported actions users say they never authorized. Reasonable on a dedicated identity with the eight settings; not yet for your main accounts.