Skip to content
AI EmployeeSuper-AgentsAgent-to-AgentTutorialsPricingBlogStoryContact

What Is Muse? Meta's Personal AI Agent on Its Own Secure Computer, Explained

At a glanceQuick answers
What is Muse in one sentence?
Meta’s personal AI agent, launched September 8, 2026, that runs on its own dedicated cloud computer, connects to the apps a person chooses, and takes actions on their behalf with approval gates for sensitive steps.
What does it cost?
Free with a weekly usage limit Meta has not published. Power is $20 a month for 500 million Muse tokens a week; Maximum is $100 a month for 3 billion a week, per Meta’s help center as of September 8, 2026.
Where can I use it?
United States only for now, on iOS, Android, muse.ai and inside WhatsApp; AI glasses are ‘coming soon’. Meta describes the whole product as ‘in limited testing’.
Hand-drawn teal sketch of a phone with a chat bubble labeled MUSE, a dotted line to a cloud containing a box labeled SECURE VM with a robot labeled AGENT and a guard labeled SENTINEL beside an amber door, and lines from the door to icons labeled EMAIL, BROWSER and PAY
Fig 0The Muse shape: one person, one agent, one dedicated computer in the cloud, and a second agent standing at the only door out.

Meta launched Muse on September 8, 2026, and called it “the world’s first personal AI agent built for everyone.” Strip the superlative and the description underneath is precise: a personal agent that lives on its own dedicated computer in Meta’s cloud, connects to the apps a person chooses, and does things on their behalf, with a second agent standing at the only door out.

This page keeps to what Meta itself published on launch day: the newsroom announcement and the help center article on subscriptions. It covers what Muse is, the computer it runs on, what it can reach, what it costs, what Meta did not say, and where it sits next to the other per-person agents that shipped this summer.

On this page · 9 sectionsOpen
  1. What Muse is
  2. The computer it runs on
  3. What it can reach today
  4. Pricing and availability
  5. The Muse line so far
  6. What Meta did not say
  7. Muse vs an AI employee
  8. What we are watching for
  9. Sources
Key points7 · 12 min full read
  1. Muse is Meta’s personal AI agent, announced September 8, 2026 as ‘the world’s first personal AI agent built for everyone’. It is not a chatbot: Meta’s line is that it ‘doesn’t just answer questions, it actually does the work’, including sending email, booking travel, filling forms and paying.
  2. Each Muse runs on Muse Secure VM, a dedicated virtual machine in the cloud with its own browser, where the agent and the person’s connected data live. A second agent, Sentinel, runs on the same machine and nothing Muse does reaches the internet unless Sentinel approves it.
  3. Muse never sees passwords or payment methods; credentials go to secure storage. It checks with the person before sensitive actions such as sending an email or making a purchase, and shows a complete audit trail of what it has done and plans to do.
  4. Payments run through Link by Stripe with a one-time-use card; Meta says Muse is the first agent covered by Link’s purchase protections. Shop Pay and 1Password support are ‘coming soon’.
  5. It is free with a usage limit. Paid plans, per Meta’s help center: Power at $20 a month for 500 million Muse tokens a week, and Maximum at $100 a month for 3 billion a week. Muse is ‘in limited testing’ and rolling out in the US on iOS, Android, muse.ai and inside WhatsApp.
  6. Meta’s announcement does not mention Muse Code, does not publish a fixed list of supported apps, and does not disclose the size of the free allowance. Later this year Meta plans Muse Confidential VM, encrypted with a key only the person holds.
  7. Muse is built for one person’s life. An AI employee is hired for a role in a business, with its own inbox, task board and memory, and it works alongside other employees. Same shape, different job.

§ 01What Muse is

Question What Meta says Where
What it is “A personal AI agent. It doesn’t just answer questions, it actually does the work.” Newsroom announcement
What it does Handles tasks “like sending an email or booking travel”, takes on “big audacious goals”, can “open a browser, fill out forms, and negotiate on their behalf” Newsroom announcement
Model “Powered by Muse Spark, Meta’s most capable model to date, built for real-world agentic work like this” Newsroom announcement
Where it runs “Muse Secure VM, a dedicated, virtual machine (VM) that houses both the agent and a person’s data” Newsroom announcement
How you talk to it “In the Muse app or directly in WhatsApp”; it “works just like messaging another person” Newsroom announcement
When it works “Keeps working after people close the app, and comes back when something changes or when it needs approval” Newsroom announcement
Availability “Rolling out in the US on iOS, Android, and muse.ai, and coming soon to AI glasses” Newsroom announcement
Status “In limited testing and aren’t available in all locations yet” Help center
Table 1Muse in Meta’s own words, September 8, 2026

The two things that distinguish it from a chat assistant are in the first and last rows. It acts, and it keeps acting when the app is closed. Meta’s examples are deliberately ordinary: selling a car for more, lowering a bill, turning a saved recipe reel into a grocery list and a dinner-party menu that remembers a friend’s dietary restrictions. Meta’s framing throughout is a product for billions of people with “no learning curve”, which is a different target from the developer-shaped agents of the last two years.

§ 02The computer it runs on

The architectural claim is the one worth reading twice. Meta says personal agents “need a new kind of secure computer, so Meta built one for everyone.” Each person’s Muse runs on its own dedicated cloud computer with its own browser, “contained so no one else’s agent can reach it.” That machine is where the agent lives and where the credentials for any connected service are stored.

Then the part no other launch this summer had: a second agent. “A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level. Nothing Muse does reaches the internet unless the Sentinel approves it, and it asks the person for permission when needed.” The agent that does the work and the agent that decides what may leave the machine are different processes on the same computer.

The rest of the safety list, verbatim in substance:

  • Muse “has no visibility into people’s passwords or payment methods.” Credentials go into secure storage so it can use them without seeing them, including passwords the person types into the browser themselves.
  • It “checks with the person before sensitive actions like sending an email or making a purchase” and “shows people a complete audit trail of everything it has done and plans to do.”
  • People choose which apps it connects to and how much access each gets; for email, whether it can read or also send. Any service can be disconnected at any time.
  • People “can also opt out of their interactions being used to train Meta’s AI models”, and Muse “doesn’t share a person’s conversations or the data in their VM with Meta’s ad systems.”
  • People can tell it to “forget” specific things it has learned.

Later in 2026, Meta says, comes Muse Confidential VM, “where the whole VM, including a person’s data and conversations with Muse, is encrypted with a key only they hold, so not even Meta can access it.” That is a promise about a future product, not a property of what shipped on September 8.

§ 03What it can reach today

Meta does not publish a list of supported apps. It describes a permission model and names a handful of services as examples.

Service What Meta says Status
WhatsApp Talk to Muse “directly in WhatsApp” Live
Email Connectable; the person chooses “whether it reads their mail or can also send on their behalf” Live, provider unnamed
Web browser Muse Secure VM has “its own browser”; it can “open a browser, fill out forms, and negotiate” Live
Instagram Turn “a recipe reel the person saved on Instagram into a grocery list” Live
Link by Stripe Checkout with a one-time-use card; “the first AI agent covered by Link’s purchase protections” Live
Shop Pay “Coming soon as another way to pay” Announced
1Password “So Muse can use logins a person already has” Announced
Table 2Services Meta names in the launch announcement

The payments row is the most concrete piece of infrastructure in the launch. Link’s wallet for agents “generates a one-time-use card so your real card details stay hidden”, and Meta says the purchase protections that come with it, including coverage for damaged or lost items and no-fee returns on eligible purchases, are free. No email provider, calendar, or Meta app beyond WhatsApp and Instagram is named.

§ 04Pricing and availability

Plan Price Weekly allowance
Free $0 “Available with a usage limit” (size not published)
Power $20 a month 500 million Muse tokens
Maximum $100 a month 3 billion Muse tokens
Table 3Muse plans, per Meta’s help center, September 8, 2026
Muse weekly token allowance by paid plan, in millions of Muse tokensBar chart comparing the Power plan at 500 million Muse tokens a week with the Maximum plan highlighted at 3 billionPower ($20)500Maximum ($100)3000Muse weekly token allowance by paid plan, in millions of Muse tokensBar chart comparing the Power plan at 500 million Muse tokens a week with the Maximum plan highlighted at 3 billionPower ($20)500Maximum ($100)3000
Fig 1Muse weekly token allowance by paid plan, in millions of Muse tokens

Two things to know about that table. First, the unit is “Muse tokens”, a Meta unit; the help center does not say how it maps to model tokens or to tasks, so the two paid tiers are comparable with each other and with nothing else. Second, the free tier’s limit is unpublished: “If you reach your free usage limit and want more usage, you can upgrade to a paid subscription or wait until your free usage limit refreshes.” Subscribers must be in a country where Muse is available, be 18 or the age of majority, and sign in with a Meta account. Plans renew monthly and “benefits and availability may vary by region and account.”

§ 05The Muse line so far

Muse is the fifth Muse-branded launch from Meta Superintelligence Labs in five months, and the first one aimed at everyone rather than at developers or at image generation.

Date Launch What it was
April 8, 2026 Muse Spark MSL’s first model, “purpose-built to prioritize people”
July 7, 2026 Muse Image Image generation model
August 5, 2026 Muse Code Terminal coding agent on Muse Spark 1.2
September 2, 2026 Muse Spark 1.3 Model update for agentic and coding tasks
September 8, 2026 Muse The personal agent
Table 4The Muse family, by launch date
The Muse line so far, from the first model to the personal agentTimeline from the Muse Spark model in April 2026 through Muse Image in July, Muse Code in August, Muse Spark 1.3 on September 2, and the Muse personal agent highlighted on September 8Apr 8Muse Spark modelJul 7Muse ImageAug 5Muse CodeSep 2Muse Spark 1.3Sep 8Muse personal agentThe Muse line so far, from the first model to the personal agentTimeline from the Muse Spark model in April 2026 through Muse Image in July, Muse Code in August, Muse Spark 1.3 on September 2, and the Muse personal agent highlighted on September 8Apr 8Muse Spark modelJul 7Muse ImageAug 5Muse CodeSep 2Muse Spark 1.3Sep 8Muse personal agent
Fig 2The Muse line so far, from the first model to the personal agent

Meta’s AI site lists Muse Spark 1.3 as the current model and describes the launch as powered by Muse Spark without a version number; our page on Muse Spark 1.3 has the model details, and What Is Muse Code covers the developer product. The two are separate: the Muse announcement does not mention Muse Code at all.

§ 06What Meta did not say

  • No app list. The permission model is described in full; the catalog of connectable services is not. Expect it to be revealed in onboarding.
  • No free-tier number. “A usage limit” is the whole disclosure.
  • No provisioning detail. Meta says each Muse runs on “its own dedicated computer in the cloud”. Whether that machine is allocated continuously to every account or spun up on demand is not stated.
  • No default on training. People “can opt out” of training use. The announcement does not say whether they are opted in to begin with.
  • “World’s first.” Per-person cloud agents with their own computer already exist: xAI’s Grok Bot, in beta since August 11, 2026, runs on a computer “assigned per user” according to xAI’s own docs, and Spear Street’s Instinct is a consumer agent with app access. Meta’s claim rests on the words “built for everyone”, which is a distribution claim, not an architecture claim.

§ 07Muse vs an AI employee

Muse, Grok Bot and Instinct all converge on one shape: one person, one agent, one computer in the cloud, permissions per connected app. That shape is right for a person’s own life. It is not what a business needs, and the difference is worth stating plainly.

Muse (Meta) Grok Bot (xAI) CellCog AI employee
Built for One person’s own tasks and goals One person’s work, with team plans A role inside a business
Who assigns work The person The person The owner, coworkers, and the employee itself from its task board
Computer One dedicated VM per person, Sentinel-gated One computer per user per xAI’s docs Its own workspace, and its own browser identity and logins, separate per employee
Memory Remembers what matters to the person; can be told to forget Per xAI’s memory advisory Carries what it learns from one working session into the next; team memory shared across employees
Works with others No Limited to sharing with a team Yes: channels, direct messages, delegation between employees, org chart
Sensitive actions Sentinel approval plus person approval before email and purchases Per-command approval settings Every command that reaches your world is classified by the agent before it runs; the platform rejects any command that arrives unclassified, and the owner sets the threshold
Pricing shape Free with limits, $20 and $100 a month Plans from $20 a month as of August 26, 2026 Pay for the work, not the hire; the cost depends purely on how much work you assign (pricing)
Table 5Personal agents and AI employees, September 2026

Meta built the single most careful consumer agent sandbox to date: a gated door, credentials the agent cannot read, a full audit trail. Those are good ideas, and they are also the reason a personal agent stops at one person. The Sentinel answers to its owner; nobody else can hand Muse a task, read its records, or put it on a team. A business role needs exactly those three things. An AI employee has an inbox anyone can write to, a task board a manager can fill, and coworkers it can delegate to, and it produces the same range of work: research, code, dashboards, spreadsheets, PDFs, video, images and audio.

§ 08What we are watching for

  • The connectable-app catalog. The first onboarding screens will show what “the apps they use daily” means in practice.
  • The free limit. How much a free Muse can do per week decides whether it competes with the $20 tier of Grok Bot or sits above it.
  • Muse Confidential VM. Promised for later in 2026; the first agent VM a vendor cannot read would be a new bar for the category.
  • Expansion beyond the US. Meta names no second market.
  • Muse Code. Whether the developer product and the personal agent converge, or stay two products on one model.

§ 09Sources

Meta Newsroom, Introducing Muse: The World’s First Personal AI Agent Built for Everyone, published September 8, 2026. Meta Help Center, About Muse subscriptions, updated September 8, 2026. Meta AI, Muse product page. Meta Newsroom, Introducing Muse Spark, April 8, 2026, and Introducing Muse Image, July 7, 2026. Every quotation on this page is from those pages as read on September 8, 2026.

Frequently asked5 questions

Q1Is Muse the same as Meta AI?

No. Meta AI is the assistant inside Meta’s apps that answers questions. Muse is a separate product that acts: it opens a browser, fills forms, sends email with permission and pays through Link by Stripe. It is powered by Muse Spark, the model line Meta Superintelligence Labs introduced in April 2026, and it has its own app at muse.ai.

Q2What is Muse Secure VM?

A dedicated virtual machine in Meta’s cloud for each person’s Muse. Meta says it ‘houses both the agent and a person’s data’, has its own browser, and is ‘contained so no one else’s agent can reach it’. A separate Sentinel agent runs on the same machine, kept apart at the system level, and approves anything Muse sends to the internet. Meta says a Confidential VM version, encrypted with a key only the person holds, is planned for later in 2026.

Q3Which apps does Muse connect to?

Meta publishes no fixed list. The announcement names WhatsApp as a way to talk to it, email as a connectable service with separate read and send permissions, a browser it controls, Instagram content it can act on, Link by Stripe for checkout, and Shop Pay and 1Password as coming soon. People choose which apps it connects to and how much access each gets, and can disconnect any of them.

Q4Does Meta train on my Muse conversations?

Meta says people ‘can opt out of their interactions being used to train Meta’s AI models’, and that Muse does not share conversations or VM data with Meta’s ad systems. The default is not stated in the announcement, so read the onboarding screens carefully.

Q5Is Muse a good fit for running a business?

It is built for one person’s own life: their email, their purchases, their goals. A business role needs a worker that other people can assign work to, that keeps records the team can read, and that coordinates with other workers. That is what an AI employee is for. CellCog AI employees own a role, carry what they learn from one working session into the next, and every command that reaches your world is classified by the agent before it runs; the platform rejects any command that arrives unclassified. Try it free, no credit card needed.

Published 08 September 2026 All Category basics →