Meta Launches Muse, an AI Agent That Can Act Across Connected Services

The U.S. rollout gives Meta an agent that can take actions, not just answer prompts. Its usefulness will depend on whether users grant access to email, payments and other services.

By 3 min read
Meta Launches Muse, an AI Agent That Can Act Across Connected Services
Meta Launches Muse, an AI Agent That Can Act Across Connected Services

Listen to this story

The audio brief

About 1:33
0:001:33
Read transcript
Meta has launched Muse in the United States, giving its consumer AI the ability to act across services that users choose to connect. Instead of only answering a prompt, Muse can send email, book travel, complete forms, browse, shop, and make purchases on a user’s behalf. It works on the web, iOS, Android, and WhatsApp. Powered by Meta’s Muse Spark model, the agent can keep working after someone closes the app, then return when something changes or a decision is needed. It can also turn a longer-term goal into a personalized plan and continue advancing it over time. The important safety design is a separate permission layer called Sentinel. Muse runs inside an isolated cloud workspace, but Sentinel alone controls network access and actions involving connected services. It can allow, deny, or ask for approval. Sending email and making purchases generally require the user’s approval, while some lower-risk or previously authorized actions can proceed automatically. Users can review planned and completed work, revoke access, disconnect services, and opt out of using their interactions to train Meta’s models. Muse does not see passwords or payment details. For checkout, Stripe Link can create a one-time card number that hides the real details. There’s a free tier, with Power at twenty dollars a month and Maximum at one hundred. Shop Pay, 1Password, and access through Meta’s smart glasses are planned. The constraint is clear: Muse’s usefulness depends on whether people will trust it with email, payments, and private data.

Story brief

3 key points

Meta’s Muse turns its consumer AI into an action-taking agent with persistent workspaces, allowing tasks to continue after a user leaves. Its launch is also a test of whether people will grant Meta access to email, travel, shopping, forms and payments. Sentinel, a separate permission layer, controls network access and higher-risk actions, while credentials stay hidden. Available in the U.S. on major platforms, Muse...

  1. 01

    Muse Spark can advance longer-term plans over time, not just complete one-off browser or form tasks.

  2. 02

    Sentinel is the sole authority for connected-service actions; sending email and purchases generally require user approval.

  3. 03

    Users can review planned and completed work, revoke app access, disconnect services, and opt out of model-training use.

Meta has launched Muse, a personal AI agent for U.S. adults that can work across services a person chooses to connect. The product is designed to send emails, book travel, complete forms and make purchases, moving beyond a chatbot’s answers into actions taken on a user’s behalf.

A task agent that can keep working

Muse is available on the web, iOS, Android and through WhatsApp. Powered by Meta’s Muse Spark model, it can continue a task after a user closes the app, then return when something changes or a decision is needed. Meta also says it can turn a longer-term goal into a personalized plan and advance the work over time.

What Meta says Muse can do

  • Handle discrete work including email, travel booking, browser use and form completion.
  • Negotiate, shop and make purchases through services a user has connected.
  • Help build and carry forward plans for longer-running goals.

A separate gatekeeper for outside actions

Muse runs in a dedicated cloud virtual machine that holds the agent, its workspace and connected-service data. Meta says the core agent operates inside an isolated runtime container, while credential storage, safety systems and Sentinel run separately. Sentinel is the sole permission authority for connected-service actions and network access: it can allow, deny or ask the user to approve a request.

Controls over access and credentials

Users choose which apps connect to Muse and what it can do with each service. They can review an audit trail of completed and planned work, change access or disconnect a service, and opt out of having interactions used to train Meta AI models. Meta says the model cannot see passwords or payment methods; instead, Sentinel inserts real connected-service credentials only after it authorizes a request.

For checkout, Muse supports Stripe’s Link system, which Meta says generates a one-time-use card number that keeps the real card details hidden from both the merchant and agent. Muse has a free tier, plus $20-a-month Power and $100-a-month Maximum plans. Meta says Shop Pay, 1Password support and AI-glasses access are planned for later.

The launch hinges on connected access

Muse can only book, buy and coordinate through services users decide to connect. Meta has made technical controls and permission choices central to the launch, but the unresolved question is whether people will grant a Meta agent access to services containing private data or payment capability.

Story updates

Latest developments

01
Demo#

Demo shared by @alexandr_wang

1/ we’ve built a lot of connectors to make it easier to integrate Muse into your life. Muse runs in a secure VM and we don’t use your data for ads or anything other than to make Muse great for you. you can connect Muse to Gmail, Google calendar, Outlook, Plaid, Opentable, Google Docs, Spotify, Function Health, Withings, Tailscale, Peloton, and more.

Editorial analysis

Our Read

Muse is a bet that consumer agents will be judged less by a single response than by whether people trust them with recurring work. Meta’s design places the agent in a dedicated cloud machine and puts a separate Sentinel component between it and outside actions. That can reduce the practical burden of handing an agent access, but it does not remove the adoption question. The meaningful next signal is whether users grant write or payment permissions after trying the service. Meta’s planned Confidential VM is another concrete checkpoint for its privacy design.

Sources

  1. research.meta.aiHow We Built Safety Into Muse
  2. about.fb.comIntroducing Muse: The World’s First Personal AI Agent Built for Everyone
  3. apnews.comMeta launches personal AI agent, Muse, emphasizes safety and privacy
  4. techcrunch.comMeta debuts its Muse AI agent. Will consumers trust it? | TechCrunch

Loading discussion...