Meta Brings Muse to Mac, Giving Its AI Agent Access to Native Apps
The desktop release puts Meta’s personal agent beside everyday communications and work files, making the boundaries on its access central to the product.
Listen to this story
The audio brief
Story brief
3 key pointsMeta has extended Muse from mobile and web to macOS, where the agent can operate across files, email, calendars, notes, messages, and connected services. The product’s value now depends on desktop permissions: users choose which apps to connect, while confirmations and an action audit trail are intended to limit risky behavior. Sentinel separately governs internet access and external actions. The setup could make...
- 01
Alexandr Wang announced the Mac release on September 17, after Muse launched on mobile and web earlier this month.
- 02
Users can select connected apps, adjust access, or disconnect services, including third-party systems and Meta properties.
- 03
Muse asks before sensitive actions such as sending email or making a purchase, and maintains an action audit trail.
Meta’s personal AI agent can now work inside a Mac user’s files, messages, calendar, notes and mail. The company has released Muse as a Mac app, extending an agent built to take actions beyond a chat window into native desktop applications.
Muse launched on mobile and the web earlier this month and quickly reached the top of the U.S. App Store charts, according to TechCrunch. Alexandr Wang announced the Mac version on September 17.
Desktop access makes permissions more consequential
This is more than a larger interface. Muse can work within applications holding personal information and communications, so the access choices determine what parts of a person’s Mac the agent may reach. Meta says Mac access is opt-in and that Muse asks before sensitive actions.
The controls Meta describes
- Users choose which apps Muse connects to and how much access it receives.
- Sensitive actions include sending an email or making a purchase.
- Muse provides an audit trail of actions it has taken and plans to take, Meta says.
The agent and its safeguards are separated
Meta’s earlier launch materials say Muse runs in a dedicated cloud virtual machine with its own browser. The company says users select connected apps and can change access or disconnect a service, while Sentinel operates separately from Muse as the permission authority for outside actions.
Meta says its safety work focuses on prompt injection, long-horizon instruction following and coordination among multiple agents. Those are the company’s descriptions of its safeguards, not independent evidence that Muse will prevent every error or attack.
The tradeoff moves onto the desktop
Muse’s desktop appeal depends on the same access that creates its risk. Working across files, mail and calendars could remove steps a chat-only assistant cannot, but useful access requires people to understand what they are granting. Meta says Muse has connectors for third-party systems as well as Meta apps including Instagram and Facebook, broadening the set of services those choices can cover.
Sources
- research.meta.aiHow We Built Safety Into Muse
- about.fb.comIntroducing Muse: The World’s First Personal AI Agent Built for Everyone
- techcrunch.comMeta's Muse hits Mac, letting the AI take actions on your computer | TechCrunch
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.