Muse AI, explained

Muse is Meta’s personal AI agent — announced September 8, 2026, rolling out free across the US, and instantly the loudest privacy debate in consumer AI. It runs your tasks in a dedicated secure VM across the apps you connect. Here is what it is, where it stops, and the questions everyone asks.

What it is
A personal AI agent from Meta that carries out tasks across connected apps, in its own secure VM
Made by
Meta Platforms, Inc. — named in the terms and on the Google Play listing
Access
Rolling out in the US on iOS, Android, and muse.ai — no invite list announced
Cost
Free for most tasks; subscription plans for more — terms allow free access to end at any time
The debate
A patched 0-day, ZDNET’s “worst for privacy” verdict, and the strongest written privacy commitments in the category — all in month one
Our take
Strongest architecture on paper of any agent we’ve covered, roughest first month — set the eight safety switches before you connect anything

Muse is Meta’s personal AI agent — it carries out tasks in its own secure VM across the apps you connect. What it does and who makes it →

How it works — and where it stands

What it does: you give it a goal or an everyday task and it works across the apps you connect — reading mail, filling forms, watching for changes, carrying a task across days. Meta’s own framing: “It doesn’t just answer questions, it actually does the work.”

How it’s built: agent and your data live together in a dedicated virtual machine — the announcement’s Muse Secure VM — and you reach it through the Muse app, WhatsApp, or muse.ai. You pick which apps it connects to and how much access each gets: read-only, or read plus act. It is designed to ask before sending an email or making a purchase, and payments run through one-time-use cards.

Where it stands after month one: a macOS researcher found a serious 0-day (Meta hotfixed it within roughly twelve hours, per Ars Technica), ZDNET’s head-to-head testing rated Muse worst for privacy, and NPR’s headline asked the question everyone else was asking — “Killer app? Security nightmare? Both?” The dated, source-linked record is on our safety page.

What people use it for

The four uses the product’s own documents point at — each worth copying carefully:

Everyday errands, given as goals

The homepage’s own scope — “from finances and health to shopping and the people you care about.” The boring errands are the point: the agent holds the task so you stop holding it in your head.

Watching things that change

Prices, availability, schedules — the recurring checks an agent can run without you asking each time. The calendar connector even pushes updates to Muse when your schedule changes.

Research with follow-through

It gathers, remembers where it left off, and picks the thread back up — the structural difference from a chat window, which forgets you the moment it answers.

Acting on your behalf — with the leash on

Sending, booking, buying are the features that make it useful and the ones every clause in the terms is about. Keep confirmations on; the September incident reports all involve action authority.

Is it free? How do you get it?

Announced September 8, 2026, rolling out in the US on iOS, Android, and muse.ai — no invite list, unlike rival Instinct . The pricing split is Meta’s own: “It’s free for most of what people need, with subscription plans for people who want to do more.” The Google Play listing (“Muse from Meta”) already shows in-app purchases, and the terms let Meta end free access “at any time and without prior notice” — free is a fact with a date, not a promise. Early adoption is real: 4.9 stars from 62.6K Play reviews, updated October 6, 2026.

Is Muse AI safe? — the clause-by-clause check →

Layered answer: the architecture is unusually strong — credentials Muse cannot see, conversation and VM data walled off from Meta’s ad systems, approval checks that run outside the AI model, and a training opt-out that even applies to past interactions. The first month is also the roughest record in the category: a patched 0-day, a “worst for privacy” verdict from ZDNET’s testing, and reported actions users say they never authorized. Reasonable on a dedicated identity with the eight settings; not yet for your main accounts.

Frequently asked questions

What is Muse AI?

A personal AI agent from Meta that carries out tasks across the apps you connect — announced September 8, 2026, reached through the Muse app, WhatsApp, or muse.ai. The full definition, in Meta’s own words, is on our What is Muse AI page.

Is muse.ai the same product — or a different company with the same name?

Same product. muse.ai is Meta’s own domain for Muse: the announcement’s rollout sentence names it, the app’s privacy policy links to it, and the login flow runs through Meta. The name collisions that do exist are with unrelated products — the Muse meditation headband and MuseScore, the music software.

Who makes Muse AI?

Meta Platforms, Inc. — named as the developer on the Google Play listing and as the counterparty in the Muse Supplemental Terms of Service.

Is Muse AI free?

Free for most tasks, with subscription plans for more — that split is Meta’s own wording. The terms reserve the right to end free access at any time without notice, and the Play listing already shows in-app purchases.

Is Muse AI available outside the US?

Not yet, per the announcement: the rollout covers the US on iOS, Android, and muse.ai, with AI glasses “coming soon” and no dates for other regions.

How does Muse compare to Instinct AI?

Both are personal AI agents that act across apps; the differences are structural. Muse ships from Meta with a VM-based architecture, public apps, and a freemium roadmap — Instinct is an invite-based free beta from a startup whose terms cap liability at $100 where Muse’s say $250. Our full head-to-head comes as its own page; for now the honest one-liner is that Instinct’s safety record is quieter and Muse’s privacy commitments are stronger on paper.

Is Muse AI safe?

That question has its own page, and the first month of coverage is why: a patched 0-day, a “worst for privacy” rating, and unusually strong written commitments in the same documents. The clause-by-clause check — with the settings that change the answer — is on the safety page.

Latest