Quick Facts

  • Meta launched Muse, a personal AI agent, on iOS, Android, and web on September 8, 2026, available to U.S. users 18 and older.
  • Muse runs on a freemium model with paid tiers at $20 and $100 per month, and Meta is exploring commissions on AI-facilitated shopping.
  • Internal testers reported security failures before launch, including an agent that accessed iCloud photos outside its intended scope and stopped working after 15 minutes.

Meta launched Muse, a personal AI agent, on September 8, 2026. The agent connects to a user’s email, calendar, financial accounts, health apps, and smart home devices to automate tasks like booking travel, sending email, shopping, and negotiating on the user’s behalf.

The app is available on iOS and Android and through Muse.ai on the web. Users can also reach Muse through WhatsApp. Meta plans to extend access to its AI glasses soon.

The Security Architecture

Meta built Muse around what it calls a “secure by design” model. Each user gets a dedicated cloud virtual machine, called Muse Secure VM, that holds the agent, its data, and credentials for connected services. A separate Sentinel agent monitors actions and requires user authorization for high-risk tasks.

Credentials are handled through a system Meta calls surrogation. The agent never sees real passwords or payment details. Instead, it works with placeholder tokens, and real credentials are injected only at the network boundary. The browser sub-agent reads an accessibility tree rather than raw page code and cannot execute JavaScript. The email connector filters out one-time passcodes and password reset links by default.

Meta also states that Muse conversations and VM data are not shared with its ad systems, a notable departure from how the company has historically handled user data.

Internal Failures Before Launch

Despite those claims, Meta shipped Muse while its own employees were still reporting failures. Meta CTO Andrew Bosworth wrote in an internal post that he was repeatedly logged out and had to re-authenticate multiple times within minutes.

A separate internal test found the agent stopped refreshing web pages after roughly 15 minutes when tasked with monitoring inventory, and failed to report errors. Another test found the agent accessed iCloud photos outside its intended scope after being asked to find toys in pictures from a child’s birthday party.

Meta’s VP of Superintelligence Labs acknowledged the company can technically access Secure VM data today. A Confidential VM roadmap is meant to close that gap, but it is not yet in place.

The initial release was delayed from April 2026 to improve security and meet minimum product safety requirements. The internal testing reports suggest those problems were not fully resolved before launch.

Pricing and Business Model

Muse follows a freemium structure. The free tier is designed to cover most everyday use. Paid plans cost $20 and $100 per month for users who need more compute capacity. Meta’s chief AI officer Alexandr Wang said the paid tiers exist primarily to cover compute costs for heavy users.

Meta is also exploring commissions on shopping transactions completed through Muse, which would create a direct revenue line tied to agent activity.

To encourage outside security research, Meta expanded its public bug bounty program to cover Muse. Payouts reach up to $300,000 for valid findings, including up to $130,000 for successful prompt injection attacks affecting a single user.

Competitive Context

Muse runs on Muse Spark 1.3, Meta’s latest model. Internal comparisons show it uses roughly 20% fewer tool calls and 25% fewer tokens than its predecessor, Muse Spark 1.2.

The launch puts Meta directly against OpenAI, Google, and Microsoft in the race to build agents that take action on a user’s behalf rather than just answer questions. Wang described Muse as an early step toward what Meta calls personal superintelligence.

For software and technology executives, the Muse launch raises a concrete question: how much security liability comes with an agent that holds shell access, inbox permissions, and financial credentials, and what standards should vendors be held to before those products ship?

Read more: Meta debuts its ‘secure by design’ personal AI agent Muse

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.