Meta has rolled out its most ambitious consumer AI product yet: a personal agent called Muse that can autonomously handle everyday tasks like sending emails, booking travel, filling out forms, and completing purchases. The launch, announced Tuesday, arrives at a delicate moment for the company, coming less than two weeks after Meta agreed to an $18 billion multistate settlement over claims tied to social media’s consumer harms.
What Muse Can Actually Do
Known internally by the code name Hatch, Muse is powered by Meta’s Muse Spark family of AI models. The agent connects to a person’s everyday apps, spanning email, calendars, payments, health, smart home systems, dining, shopping, music, and events, letting it complete both quick one-off tasks and longer-running projects that continue in the background even after a user closes the app.
Beyond sending messages and booking trips, Meta says Muse can lower bills, create plans, turn recipe videos into grocery lists, send party invitations, and check out purchases using Link by Stripe, a system that generates single-use card numbers so a user’s actual payment details stay hidden. Integrations with Shopify’s Shop Pay and 1Password are expected to follow.
Users choose which apps to connect one at a time, and Meta says access can be revoked at any point. Each Muse agent runs on its own dedicated virtual machine, a cloud-based emulation of a personal computer, which is what allows it to keep working on tasks even when someone isn’t actively using the app.
Availability and Pricing
Muse is currently limited to the United States, accessible through a dedicated app on iOS and Android, a standalone website, and WhatsApp. Meta says support for its Ray-Ban smart glasses will follow, though a specific timeline hasn’t been shared.
A free tier will be available to most users, while heavier users can subscribe to paid plans at $20 or $100 a month, according to a company spokesperson. Users must actively opt out if they don’t want their interactions used to train Meta’s AI models. Meta has also confirmed plans to launch an encrypted version of Muse later this year, one where even the company itself would not have access to a user’s data or conversations.
Built-In Safety Measures, According to Meta
Meta says it has designed Muse with multiple layers of protection. A separate monitoring system, referred to internally as Sentinel, runs on the same virtual machine as Muse and oversees what actions the agent is permitted to take, occasionally prompting the agent to seek explicit approval before proceeding with anything sensitive.
Meta AI chief Alexandr Wang told CNBC that the app operates within “its own isolated environment” and “never sees your actual passwords or payment details.” Vishal Shah, Meta’s vice president of AI products, said the company deliberately delayed an earlier planned release in April to strengthen the product’s security, telling Reuters that the extra work helped the team “cross the threshold” needed before making it publicly available.
“It is impossible to say that there is never going to be a mistake, but every single part of the architecture has been designed to make this as safe, as secure, and as private as we can make it,” Shah said.
Internal Testing Told a Different Story
Despite those public assurances, Reuters reported that internal testing at Meta surfaced a mix of glowing feedback and serious concerns. One employee said the tool proved so useful for coordinating vacation logistics that it effectively became “the third participant” during a three-week honeymoon in Indonesia.
Others flagged troubling security gaps. In one instance, the agent bypassed built-in safety guardrails and exposed a user’s personal iCloud photos after being asked to identify toys in birthday party pictures. Meta’s own Chief Technology Officer, Andrew Bosworth, wrote that he was repeatedly logged out of the service, sometimes multiple times within a few minutes. Another staffer who had asked Muse to monitor for limited availability items like concert tickets reported the tool stalling roughly 15 minutes in, silently failing to report other errors, and occasionally disabling monitoring without explanation. Meta did not respond to Reuters’ request for comment on the specific incidents described internally.
More broadly, Meta has seen major technical and security incidents climb 40% compared to the previous year, driven in part by an AI-fueled coding surge and agent-related issues, while time spent by staff resolving those incidents has risen 70%.
A Trust Problem Bigger Than the Product
Whether consumers are willing to hand over this level of access to their personal data may hinge as much on Meta’s track record as on the technology itself. The company has a long history of regulatory run-ins over data privacy, including a 2011 FTC settlement over deceptive handling of private information, a record-breaking $5 billion FTC penalty in 2019, and a follow-up FTC charge in 2023 for violating that earlier order. Separately, Meta discovered in 2019 that a number of user passwords had been stored in readable, unencrypted formats, and the Cambridge Analytica scandal, in which data belonging to millions of users was harvested by a third party without consent, remains a lingering reference point for skeptics.
Meta has also faced repeated congressional scrutiny over its record protecting minors, a pressure line that fed directly into the recent $18 billion multistate settlement, a $942 million judgment in a separate New Mexico lawsuit, and thousands of still-pending personal injury and school district cases.
To help ease those concerns, Meta has leaned on both technical transparency, publishing a detailed post explaining Muse’s security architecture, and product design choices meant to build a more personal connection with users, including letting them name the agent, choose its avatar and adjust how it communicates.
Part of a Broader Industry Shift
Muse reflects a wider pivot happening across the AI industry, moving beyond chatbots that simply answer questions toward agents capable of independently completing tasks. Meta joins companies like OpenAI and Google, along with smaller startups, in building tools designed to act on users’ behalf rather than just respond to them.
CEO Mark Zuckerberg has pointed to this shift as central to Meta’s future, telling investors in July that new personal agents would become “the foundation for our next wave of products and revenue lines in the months and years ahead.” The push is also tied to Meta’s broader effort to diversify revenue beyond digital advertising, particularly as the company’s infrastructure and AI chip spending is projected to surpass $130 billion this year.
Wang acknowledged that Muse is entering unproven territory, describing the broader personal agent category as still being “pretty early” in its development, even as Meta positions its version as more accessible to mainstream users than competing tools. The company has also opened a private bug bounty program, inviting third-party security researchers to probe Muse for vulnerabilities in exchange for financial rewards.



