Meta Launches Muse, an AI Agent That Can Act Across Connected Services
The U.S. rollout gives Meta an agent that can take actions, not just answer prompts. Its usefulness will depend on whether users grant access to email, payments and other services.
Meta’s Muse turns its consumer AI into an action-taking agent with persistent workspaces, allowing tasks to continue after a user leaves. Its launch is also a test of whether people will grant Meta access to email, travel, shopping, forms and payments. Sentinel, a separate permission layer, controls network access and higher-risk actions, while credentials stay hidden.
01
Muse Spark can advance longer-term plans over time, not just complete one-off browser or form tasks.
02
Sentinel is the sole authority for connected-service actions; sending email and purchases generally require user approval.
03
Users can review planned and completed work, revoke app access, disconnect services, and opt out of model-training use.
Meta has launched Muse, a personal AI agent for U.S. adults that can work across services a person chooses to connect. The product is designed to send emails, book travel, complete forms and make purchases, moving beyond a chatbot’s answers into actions taken on a user’s behalf.
A task agent that can keep working
Muse is available on the web, iOS, Android and through WhatsApp. Powered by Meta’s Muse Spark model, it can continue a task after a user closes the app, then return when something changes or a decision is needed. Meta also says it can turn a longer-term goal into a personalized plan and advance the work over time.
What Meta says Muse can do
Handle discrete work including email, travel booking, browser use and form completion.
Negotiate, shop and make purchases through services a user has connected.
Help build and carry forward plans for longer-running goals.
A separate gatekeeper for outside actions
Muse runs in a dedicated cloud virtual machine that holds the agent, its workspace and connected-service data. Meta says the core agent operates inside an isolated runtime container, while credential storage, safety systems and Sentinel run separately. Sentinel is the sole permission authority for connected-service actions and network access: it can allow, deny or ask the user to approve a request.
Controls over access and credentials
Users choose which apps connect to Muse and what it can do with each service. They can review an audit trail of completed and planned work, change access or disconnect a service, and opt out of having interactions used to train Meta AI models. Meta says the model cannot see passwords or payment methods; instead, Sentinel inserts real connected-service credentials only after it authorizes a request.
For checkout, Muse supports Stripe’s Link system, which Meta says generates a one-time-use card number that keeps the real card details hidden from both the merchant and agent. Muse has a free tier, plus $20-a-month Power and $100-a-month Maximum plans. Meta says Shop Pay, 1Password support and AI-glasses access are planned for later.
The launch hinges on connected access
Muse can only book, buy and coordinate through services users decide to connect. Meta has made technical controls and permission choices central to the launch, but the unresolved question is whether people will grant a Meta agent access to services containing private data or payment capability.
Meta’s Muse automatically includes users’ agent interactions in AI-model training unless they opt out, according to a new WIRED review. The finding matters because Muse is built to handle personal online errands by connecting to the accounts and information behind them.
Meta launched Muse in the U.S. on September 8 as a personal AI agent available through iOS, Android, the web and WhatsApp. Meta says it can work in the background on tasks such as browsing, filling out forms, sending email and making purchases, returning when it needs approval for a sensitive action.
WIRED found that users can disable training use in Muse’s Data controls. Meta says data used for training is sanitized to remove identifying information, but WIRED reported that the sanitization process is unclear. The app also keeps a long-term Memory document with interaction details and preferences; users can edit it or request deletion, but cannot currently disable the feature entirely.
Meta says Muse runs in a dedicated cloud virtual machine and stores credentials separately, so the main agent does not see passwords or payment methods. A separate system, Sentinel, governs outgoing network requests and actions through connected services; Meta says sensitive approvals are presented in the app rather than handled as conversational instructions.
Choose which services connect to Muse and, for email, whether it can read messages or send them.
Approve sensitive actions such as sending email or making purchases, and review an audit trail.
Tell Muse to forget specific remembered information and disconnect services when desired.
Meta says conversations and data in Muse’s virtual machine are not shared with its advertising systems, although browsing performed by the agent can indirectly affect ads when websites treat its visits as user activity. Later this year, Meta plans a Confidential VM that it says will encrypt the entire machine with a key held only by the user, preventing Meta from accessing the data inside.
That protection is not available today. For now, Muse users can decide how much account access to grant and can turn off training use, while the product’s always-on memory remains a feature they can manage but not fully disable.
1/ we’ve built a lot of connectors to make it easier to integrate Muse into your life. Muse runs in a secure VM and we don’t use your data for ads or anything other than to make Muse great for you. you can connect Muse to Gmail, Google calendar, Outlook, Plaid, Opentable, Google Docs, Spotify, Function Health, Withings, Tailscale, Peloton, and more.
Editorial analysis
Our Read
Muse is a bet that consumer agents will be judged less by a single response than by whether people trust them with recurring work. Meta’s design places the agent in a dedicated cloud machine and puts a separate Sentinel component between it and outside actions. That can reduce the practical burden of handing an agent access, but it does not remove the adoption question. The meaningful next signal is whether users grant write or payment permissions after trying the service. Meta’s planned Confidential VM is another concrete checkpoint for its privacy design.
Reader comments
Newest comments first. Replies stay oldest first.