Meta's Muse personal AI agent debuts in the US; hands-on privacy concerns and a new biometric training-data lawsuit follow
Meta launched Muse on 2026-09-08, a US-only, 18+ personal AI agent that emails, books travel, shops and negotiates inside a per-user Secure VM with a Sentinel gatekeeper and Stripe Link one-time cards; The Verge's hands-on found it surfacing Instagram-derived…
Meta introduced Muse on 2026-09-08 (SecurityWeek dates the launch to Tuesday), a consumer personal AI agent from Meta Superintelligence Labs (WIRED) that Meta bills as the world's first personal AI agent built for everyone. It is initially available in the US to users 18 and over via iOS, Android, muse.ai and WhatsApp (TechCrunch also cites web; The Verge's platform list omits WhatsApp), with Meta AI glasses support planned. Muse plans and executes long-horizon tasks — sending email, managing calendars, booking travel, online shopping, bill negotiation, browser automation and form-filling — keeps working after the app closes, requests approval for purchases and sensitive actions, and offers per-app access scopes users can revoke anytime; The Verge's hands-on also confirms media generation (podcasts, images, videos, artifacts) and reports it refused some copyrighted-character and Apple-CEO requests. Architecturally, Muse runs in Muse Secure VM, a dedicated per-user virtual machine where the agent operates in a systemd-nspawn cell (MarkTechPost); a separate Sentinel agent is the sole approver of network egress at layer 4/7, injects real credentials only at the network boundary via surrogate tokens, and routes human-in-the-loop approval prompts directly to users rather than through the model (WIRED), keeping untrusted web content away from the action layer. Muse is powered by Muse Spark — Meta's most capable model to date; MarkTechPost identifies the shipping version as Muse Spark 1.3 (~20% fewer tool calls and ~25% fewer tokens vs 1.2, near state-of-the-art prompt-injection resistance, live via the Meta Model API with open weights planned), while The Decoder relays a reported 44-48 on the Artificial Analysis Intelligence Index v4.3, up from 31 in April and near GPT-5.6 Sol's 47. Payments run through Stripe Link with one-time-use virtual cards and no-fee return protections — which Meta calls a first for an AI agent — with Shop Pay and 1Password integration planned. A free tier is confirmed by all sources, but paid pricing is reported inconsistently: TechCrunch names Power at $20/month and Maximum at $100/month, The Verge cites unspecified tiers, and The Decoder relays earlier reports of a paid product costing up to $200/month. Meta added Muse to its public bug bounty with payouts up to $300,000, including up to $130,000 for single-user prompt-injection findings, and a Muse Confidential VM — co-developed with Moxie Marlinspike, running in trusted execution…
- Meta launched Muse on 2026-09-08, a US-only personal AI agent for users 18+, on iOS, Android, muse.ai and WhatsApp, with Meta AI glasses support planned (TechCrunch also cites web; The Verge omits WhatsApp).
- Muse executes email, calendar, travel booking, shopping, bill-negotiation, browsing and form-filling tasks, continues after the app closes, and asks approval before purchases and sensitive actions; per-app access scopes are revocable…
- Runs in a dedicated per-user Muse Secure VM (systemd-nspawn cell) with a separate Sentinel agent that is the sole approver of network egress at layer 4/7 and injects real credentials only at the network boundary via surrogate tokens.
- Sentinel routes human-in-the-loop approval prompts directly to users — not through the model — to resist prompt injection, and the Secure VM isolates untrusted web and integration data from the action-taking component.
- Powered by Muse Spark 1.3: ~20% fewer tool calls and ~25% fewer tokens vs 1.2, near state-of-the-art prompt-injection resistance, live via the Meta Model API with open weights planned; reportedly scored 44-48 on the Artificial Analysis…
- Payments use Stripe Link one-time-use virtual cards with no-fee return protections — billed as the first AI agent covered by Link purchase protections; Shop Pay and 1Password support planned.
- Free tier confirmed by all sources; paid tiers reported inconsistently: Power at $20/month and Maximum at $100/month (TechCrunch), unspecified paid tiers (The Verge), and up to $200/month per earlier reports (The Decoder).
- Public bug bounty payouts up to $300,000, including up to $130,000 for single-user prompt injection; a Muse Confidential VM in trusted execution environments with user-held keys, co-developed with Moxie Marlinspike, is promised later this…
Coverage timelineoldest first · each row is one article
- · 7d agoMeta debuts its Muse AI agent. Will consumers trust it?
TechCrunch · AI· 74
Meta launched Muse, a consumer AI agent powered by Muse Spark that connects to users' apps to execute tasks like emailing, booking travel, and payments.
- · 7d agoMeta bets on AI agent Muse to catch up in AI race
The Verge · AI· 72
Meta launched Muse, a free personal AI agent in the US that autonomously shops, emails, and plans trips, powered by its in-house Muse Spark model.
- · 7d agoIntroducing Muse: The World’s First Personal AI Agent Built for Everyone
Meta Newsroom· 78
Meta launches Muse, a personal AI agent running in a dedicated Secure VM and powered by its Muse Spark model, with payments via Stripe Link.