Meta launched Muse on September 8, 2026, and called it “the world’s first personal AI agent built for everyone.” Strip the superlative and the description underneath is precise: a personal agent that lives on its own dedicated computer in Meta’s cloud, connects to the apps a person chooses, and does things on their behalf, with a second agent standing at the only door out.
This page keeps to what Meta itself published on launch day: the newsroom announcement and the help center article on subscriptions. It covers what Muse is, the computer it runs on, what it can reach, what it costs, what Meta did not say, and where it sits next to the other per-person agents that shipped this summer.
On this page · 9 sectionsOpen
- Muse is Meta’s personal AI agent, announced September 8, 2026 as ‘the world’s first personal AI agent built for everyone’. It is not a chatbot: Meta’s line is that it ‘doesn’t just answer questions, it actually does the work’, including sending email, booking travel, filling forms and paying.
- Each Muse runs on Muse Secure VM, a dedicated virtual machine in the cloud with its own browser, where the agent and the person’s connected data live. A second agent, Sentinel, runs on the same machine and nothing Muse does reaches the internet unless Sentinel approves it.
- Muse never sees passwords or payment methods; credentials go to secure storage. It checks with the person before sensitive actions such as sending an email or making a purchase, and shows a complete audit trail of what it has done and plans to do.
- Payments run through Link by Stripe with a one-time-use card; Meta says Muse is the first agent covered by Link’s purchase protections. Shop Pay and 1Password support are ‘coming soon’.
- It is free with a usage limit. Paid plans, per Meta’s help center: Power at $20 a month for 500 million Muse tokens a week, and Maximum at $100 a month for 3 billion a week. Muse is ‘in limited testing’ and rolling out in the US on iOS, Android, muse.ai and inside WhatsApp.
- Meta’s announcement does not mention Muse Code, does not publish a fixed list of supported apps, and does not disclose the size of the free allowance. Later this year Meta plans Muse Confidential VM, encrypted with a key only the person holds.
- Muse is built for one person’s life. An AI employee is hired for a role in a business, with its own inbox, task board and memory, and it works alongside other employees. Same shape, different job.
§ 01What Muse is
| Question | What Meta says | Where |
|---|---|---|
| What it is | “A personal AI agent. It doesn’t just answer questions, it actually does the work.” | Newsroom announcement |
| What it does | Handles tasks “like sending an email or booking travel”, takes on “big audacious goals”, can “open a browser, fill out forms, and negotiate on their behalf” | Newsroom announcement |
| Model | “Powered by Muse Spark, Meta’s most capable model to date, built for real-world agentic work like this” | Newsroom announcement |
| Where it runs | “Muse Secure VM, a dedicated, virtual machine (VM) that houses both the agent and a person’s data” | Newsroom announcement |
| How you talk to it | “In the Muse app or directly in WhatsApp”; it “works just like messaging another person” | Newsroom announcement |
| When it works | “Keeps working after people close the app, and comes back when something changes or when it needs approval” | Newsroom announcement |
| Availability | “Rolling out in the US on iOS, Android, and muse.ai, and coming soon to AI glasses” | Newsroom announcement |
| Status | “In limited testing and aren’t available in all locations yet” | Help center |
The two things that distinguish it from a chat assistant are in the first and last rows. It acts, and it keeps acting when the app is closed. Meta’s examples are deliberately ordinary: selling a car for more, lowering a bill, turning a saved recipe reel into a grocery list and a dinner-party menu that remembers a friend’s dietary restrictions. Meta’s framing throughout is a product for billions of people with “no learning curve”, which is a different target from the developer-shaped agents of the last two years.
§ 02The computer it runs on
The architectural claim is the one worth reading twice. Meta says personal agents “need a new kind of secure computer, so Meta built one for everyone.” Each person’s Muse runs on its own dedicated cloud computer with its own browser, “contained so no one else’s agent can reach it.” That machine is where the agent lives and where the credentials for any connected service are stored.
Then the part no other launch this summer had: a second agent. “A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level. Nothing Muse does reaches the internet unless the Sentinel approves it, and it asks the person for permission when needed.” The agent that does the work and the agent that decides what may leave the machine are different processes on the same computer.
The rest of the safety list, verbatim in substance:
- Muse “has no visibility into people’s passwords or payment methods.” Credentials go into secure storage so it can use them without seeing them, including passwords the person types into the browser themselves.
- It “checks with the person before sensitive actions like sending an email or making a purchase” and “shows people a complete audit trail of everything it has done and plans to do.”
- People choose which apps it connects to and how much access each gets; for email, whether it can read or also send. Any service can be disconnected at any time.
- People “can also opt out of their interactions being used to train Meta’s AI models”, and Muse “doesn’t share a person’s conversations or the data in their VM with Meta’s ad systems.”
- People can tell it to “forget” specific things it has learned.
Later in 2026, Meta says, comes Muse Confidential VM, “where the whole VM, including a person’s data and conversations with Muse, is encrypted with a key only they hold, so not even Meta can access it.” That is a promise about a future product, not a property of what shipped on September 8.
§ 03What it can reach today
Meta does not publish a list of supported apps. It describes a permission model and names a handful of services as examples.
| Service | What Meta says | Status |
|---|---|---|
| Talk to Muse “directly in WhatsApp” | Live | |
| Connectable; the person chooses “whether it reads their mail or can also send on their behalf” | Live, provider unnamed | |
| Web browser | Muse Secure VM has “its own browser”; it can “open a browser, fill out forms, and negotiate” | Live |
| Turn “a recipe reel the person saved on Instagram into a grocery list” | Live | |
| Link by Stripe | Checkout with a one-time-use card; “the first AI agent covered by Link’s purchase protections” | Live |
| Shop Pay | “Coming soon as another way to pay” | Announced |
| 1Password | “So Muse can use logins a person already has” | Announced |
The payments row is the most concrete piece of infrastructure in the launch. Link’s wallet for agents “generates a one-time-use card so your real card details stay hidden”, and Meta says the purchase protections that come with it, including coverage for damaged or lost items and no-fee returns on eligible purchases, are free. No email provider, calendar, or Meta app beyond WhatsApp and Instagram is named.
§ 04Pricing and availability
| Plan | Price | Weekly allowance |
|---|---|---|
| Free | $0 | “Available with a usage limit” (size not published) |
| Power | $20 a month | 500 million Muse tokens |
| Maximum | $100 a month | 3 billion Muse tokens |
Two things to know about that table. First, the unit is “Muse tokens”, a Meta unit; the help center does not say how it maps to model tokens or to tasks, so the two paid tiers are comparable with each other and with nothing else. Second, the free tier’s limit is unpublished: “If you reach your free usage limit and want more usage, you can upgrade to a paid subscription or wait until your free usage limit refreshes.” Subscribers must be in a country where Muse is available, be 18 or the age of majority, and sign in with a Meta account. Plans renew monthly and “benefits and availability may vary by region and account.”
§ 05The Muse line so far
Muse is the fifth Muse-branded launch from Meta Superintelligence Labs in five months, and the first one aimed at everyone rather than at developers or at image generation.
| Date | Launch | What it was |
|---|---|---|
| April 8, 2026 | Muse Spark | MSL’s first model, “purpose-built to prioritize people” |
| July 7, 2026 | Muse Image | Image generation model |
| August 5, 2026 | Muse Code | Terminal coding agent on Muse Spark 1.2 |
| September 2, 2026 | Muse Spark 1.3 | Model update for agentic and coding tasks |
| September 8, 2026 | Muse | The personal agent |
Meta’s AI site lists Muse Spark 1.3 as the current model and describes the launch as powered by Muse Spark without a version number; our page on Muse Spark 1.3 has the model details, and What Is Muse Code covers the developer product. The two are separate: the Muse announcement does not mention Muse Code at all.
§ 06What Meta did not say
- No app list. The permission model is described in full; the catalog of connectable services is not. Expect it to be revealed in onboarding.
- No free-tier number. “A usage limit” is the whole disclosure.
- No provisioning detail. Meta says each Muse runs on “its own dedicated computer in the cloud”. Whether that machine is allocated continuously to every account or spun up on demand is not stated.
- No default on training. People “can opt out” of training use. The announcement does not say whether they are opted in to begin with.
- “World’s first.” Per-person cloud agents with their own computer already exist: xAI’s Grok Bot, in beta since August 11, 2026, runs on a computer “assigned per user” according to xAI’s own docs, and Spear Street’s Instinct is a consumer agent with app access. Meta’s claim rests on the words “built for everyone”, which is a distribution claim, not an architecture claim.
§ 07Muse vs an AI employee
Muse, Grok Bot and Instinct all converge on one shape: one person, one agent, one computer in the cloud, permissions per connected app. That shape is right for a person’s own life. It is not what a business needs, and the difference is worth stating plainly.
| Muse (Meta) | Grok Bot (xAI) | CellCog AI employee | |
|---|---|---|---|
| Built for | One person’s own tasks and goals | One person’s work, with team plans | A role inside a business |
| Who assigns work | The person | The person | The owner, coworkers, and the employee itself from its task board |
| Computer | One dedicated VM per person, Sentinel-gated | One computer per user per xAI’s docs | Its own workspace, and its own browser identity and logins, separate per employee |
| Memory | Remembers what matters to the person; can be told to forget | Per xAI’s memory advisory | Carries what it learns from one working session into the next; team memory shared across employees |
| Works with others | No | Limited to sharing with a team | Yes: channels, direct messages, delegation between employees, org chart |
| Sensitive actions | Sentinel approval plus person approval before email and purchases | Per-command approval settings | Every command that reaches your world is classified by the agent before it runs; the platform rejects any command that arrives unclassified, and the owner sets the threshold |
| Pricing shape | Free with limits, $20 and $100 a month | Plans from $20 a month as of August 26, 2026 | Pay for the work, not the hire; the cost depends purely on how much work you assign (pricing) |
Meta built the single most careful consumer agent sandbox to date: a gated door, credentials the agent cannot read, a full audit trail. Those are good ideas, and they are also the reason a personal agent stops at one person. The Sentinel answers to its owner; nobody else can hand Muse a task, read its records, or put it on a team. A business role needs exactly those three things. An AI employee has an inbox anyone can write to, a task board a manager can fill, and coworkers it can delegate to, and it produces the same range of work: research, code, dashboards, spreadsheets, PDFs, video, images and audio.
§ 08What we are watching for
- The connectable-app catalog. The first onboarding screens will show what “the apps they use daily” means in practice.
- The free limit. How much a free Muse can do per week decides whether it competes with the $20 tier of Grok Bot or sits above it.
- Muse Confidential VM. Promised for later in 2026; the first agent VM a vendor cannot read would be a new bar for the category.
- Expansion beyond the US. Meta names no second market.
- Muse Code. Whether the developer product and the personal agent converge, or stay two products on one model.
§ 09Sources
Meta Newsroom, Introducing Muse: The World’s First Personal AI Agent Built for Everyone, published September 8, 2026. Meta Help Center, About Muse subscriptions, updated September 8, 2026. Meta AI, Muse product page. Meta Newsroom, Introducing Muse Spark, April 8, 2026, and Introducing Muse Image, July 7, 2026. Every quotation on this page is from those pages as read on September 8, 2026.
Q1Is Muse the same as Meta AI?
No. Meta AI is the assistant inside Meta’s apps that answers questions. Muse is a separate product that acts: it opens a browser, fills forms, sends email with permission and pays through Link by Stripe. It is powered by Muse Spark, the model line Meta Superintelligence Labs introduced in April 2026, and it has its own app at muse.ai.
Q2What is Muse Secure VM?
A dedicated virtual machine in Meta’s cloud for each person’s Muse. Meta says it ‘houses both the agent and a person’s data’, has its own browser, and is ‘contained so no one else’s agent can reach it’. A separate Sentinel agent runs on the same machine, kept apart at the system level, and approves anything Muse sends to the internet. Meta says a Confidential VM version, encrypted with a key only the person holds, is planned for later in 2026.
Q3Which apps does Muse connect to?
Meta publishes no fixed list. The announcement names WhatsApp as a way to talk to it, email as a connectable service with separate read and send permissions, a browser it controls, Instagram content it can act on, Link by Stripe for checkout, and Shop Pay and 1Password as coming soon. People choose which apps it connects to and how much access each gets, and can disconnect any of them.
Q4Does Meta train on my Muse conversations?
Meta says people ‘can opt out of their interactions being used to train Meta’s AI models’, and that Muse does not share conversations or VM data with Meta’s ad systems. The default is not stated in the announcement, so read the onboarding screens carefully.
Q5Is Muse a good fit for running a business?
It is built for one person’s own life: their email, their purchases, their goals. A business role needs a worker that other people can assign work to, that keeps records the team can read, and that coordinates with other workers. That is what an AI employee is for. CellCog AI employees own a role, carry what they learn from one working session into the next, and every command that reaches your world is classified by the agent before it runs; the platform rejects any command that arrives unclassified. Try it free, no credit card needed.
