Meta debuts Muse this week, a personal AI agent that can read your email, manage your calendar, book travel, and make purchases on your behalf, launching in the U.S. on September 8, 2026. It's Meta's biggest consumer AI bet yet, and it asks people to hand over more of their digital life than any Meta product has before, less than two weeks after the company agreed to pay up to $18 billion to settle a child-safety lawsuit brought by 29 states.

I've watched a lot of companies launch AI agents this year, and the pitch is always some version of the same thing: connect your accounts, and the AI will handle the busywork. What's different about Muse is the sheer breadth of what Meta is asking for, email, calendars, payments, health apps, and the smart home, combined with the fact that it's Meta doing the asking, a company whose privacy record is exactly the kind of thing this product needs people to forget.

Here's what Muse actually does, how Meta says it's keeping your data safe, and where the company's own admissions leave real gaps in that promise.

Quick Take

  • What happened: Meta launched Muse on September 8, 2026, a personal AI agent for U.S. users 18 and older that can send emails, book travel, make purchases, and manage tasks across connected apps including email, calendars, payments, health, and the smart home.
  • Who it affects: Any U.S. adult weighing whether to hand an AI agent access to their most sensitive accounts, and anyone factoring Meta's privacy track record into that decision.
  • Why it matters now: The launch lands less than two weeks after Meta agreed to pay up to $18 billion to settle a child-safety lawsuit brought by 29 states, and Meta's own security documentation admits the current version can't yet stop Meta itself from accessing user data when needed.

Background

Muse is the product version of a vision Mark Zuckerberg laid out in "The Future Is for Everyone," a 6,500-word essay published August 10, 2026, arguing that superintelligent AI should sit in individuals' hands rather than a handful of labs. Meta has been building toward that for over a year, since its $14.3 billion investment in Scale AI in mid-2025 brought over CEO Alexandr Wang to lead what's now called Meta Superintelligence Labs.

Wang's team shipped the underlying Muse Spark model line starting in April 2026, iterating quickly through versions 1.1, 1.2, and, as of September 2, 1.3, which Meta's own benchmarks pit against GPT-5.6 Sol and Opus 5. Muse itself, internally code-named Hatch and reportedly modeled in part on the open-source OpenClaw agent framework, was originally due for an April release. Meta VP of AI products Vishal Shah told BetaNews the company held it back to work through security concerns first.

What Muse Actually Does

According to Meta's own product post, written by designers Mona Sarantakos and Christine Awad, and corroborated by TechCrunch's Sarah Perez, Muse connects to a user's apps one at a time, an opt-in structure Meta says is meant to keep permissions transparent. Built-in connectors exist for email, calendars, payments, health and fitness apps, the smart home, dining, shopping, and music and events, with more planned. If a service isn't natively supported but has a public API, Muse can build its own connection; without an API, it falls back to browsing the site directly.

Muse can send emails, book travel, lower bills, fill out forms, turn a saved recipe reel into a grocery list, and make purchases through Stripe's Link, with Shopify's Shop Pay and 1Password integrations coming. It keeps working after you close the app, follows up on long-running goals unprompted, and remembers context across conversations. Access starts through the web at muse.ai, iOS and Android apps, and WhatsApp, with Meta's Ray-Ban glasses coming later. Pricing is a free tier plus two paid plans, Power at $20 a month and Maximum at $100, though Meta has said it expects most people to stay on the free tier. The system prompt Meta describes in its design post starts simply: “Your purpose is to make your user's life better.”

How Meta Says It's Keeping Your Data Safe

The technical case is laid out in a 20-minute engineering post by Tarek Sheasha, a software engineer and VP at Meta Superintelligence Labs. Each user's Muse runs inside its own isolated cloud virtual machine, split at the system level into an untrusted runtime cell where the agent operates and a set of security services, including credential storage, a Postgres database, and a permission authority called Sentinel, that the agent cannot see or override. Sentinel approves or blocks every connector action and every network request; the agent itself never receives real passwords or payment credentials, only single-use “surrogate” tokens swapped for the real thing at the network boundary. In the browser, Muse works from an accessibility-tree view of a page rather than raw code, and it filters one-time passcodes and password-reset links out of connected email by default. Meta opened its bug bounty program to the public alongside the launch, offering up to $300,000 for valid reports and up to $130,000 for a successful prompt-injection attack. On CNBC, Wang summarized the pitch: Muse “never sees your actual passwords or payment details and asks before doing anything sensitive.”

Reality Check: What Meta's Own Admissions Leave Open

Meta's own security post contains a caveat worth sitting with. Today's architecture, Sheasha writes, “does not prevent Meta from accessing data when necessary” to support, secure, or operate the service. The fully private version, called Muse Confidential VM and designed so that Meta itself cannot see inside a user's workspace, is not what shipped this week. It's still in testing with a small group and won't arrive until “later this year,” per Meta's own timeline. Until then, the privacy promise is closer to a policy Meta has chosen to follow than a technical limit the system enforces.

Meta’s internal testing also surfaced real problems before launch, a pattern that’s already played out with other companies’ agents this month too. BetaNews reported the agent disconnected mid-task in some cases without explanation, and in one instance pulled a user's personal iCloud photos after being asked only to identify toys at a child's birthday party. Separately, Axios reported that a Meta researcher's own test run with an agent ended in deleted files, and that Resy has told customers not to point automated agents at its platform, the same enforcement that got a venture investor's account briefly deactivated last month for using the rival Instinct assistant to snipe a reservation.

Instinct is itself a useful comparison. Early testers of that agent found it retained a user's Gmail data after being told to delete it and continued summarizing an inbox hours after being disconnected, prompting one investor, Moxxie Ventures founder Katie Jacobs Stanton, to write that with agents like these, “one unauthorized action can reset that trust to zero.” That's the bar Muse has to clear, on top of Meta's own history: a 2011 FTC deception settlement, a record $5 billion FTC fine in 2019, a 2023 FTC finding that Meta violated that same order regarding youth data, a 2019 discovery that hundreds of millions of passwords sat in plaintext on internal systems, the Cambridge Analytica scandal that cost Meta $725 million in a class settlement, and now the $18 billion child-safety settlement from two weeks ago.

Who This Affects

Muse lands in a field that's filling up fast. TechCrunch notes Google’s Gemini Spark and Anthropic’s Claude Cowork are chasing the same shift from chatbots to agents that act, and OpenAI, Google, and Anthropic have all shipped competing products this year. For ordinary users, the calculation is a direct trade: convenience against the scope of access Muse requests, evaluated against a company that profits from knowing what people want. For security researchers, the newly public bug bounty is an open invitation to test Meta's specific claims rather than take them on faith. For platforms like Resy that are already blocking automated agents, Muse's arrival means more of that traffic to sort out.

What's Next

Watch for Muse Confidential VM's actual ship date, since that's the point at which Meta's privacy promise becomes something enforced by the system rather than a policy the company could change. Watch, too, whether the reliability problems found in internal testing, like the iCloud photo overreach, keep surfacing now that Muse is in the hands of the public, and whether the open bug bounty turns up findings serious enough to slow further rollout, including the planned expansion to Ray-Ban glasses and beyond the U.S.

Frequently Asked Questions

Does Meta AI use Muse Spark?
Yes. Muse, the personal agent, runs on Meta's Muse Spark model family; the version powering it at launch is Muse Spark 1.3, released September 2, 2026, according to Meta's own research blog.

Is Meta Muse good?
There's no independent review data yet, since Muse only launched September 8, 2026. What's confirmed is an unusually detailed security architecture and a broad feature set; what's unconfirmed is real-world reliability, and Meta's own internal testing already found problems, including an agent that overstepped its instructions to pull photos it wasn't asked for.

How much does Muse Spark cost?
Muse Spark itself is Meta's underlying model, available to developers through Muse Code and the Meta Model API; it isn't sold separately to consumers. The consumer product, Muse, has a free tier plus two paid plans, Power at $20 a month and Maximum at $100 a month.

How do I stop Facebook from using my photos for AI?
There's no full opt-out for U.S. users. Meta uses public posts and photos from adult accounts to train its AI, and in the U.S. you can only submit an objection request through Facebook or Instagram's Privacy Center, under “How Meta uses information for generative AI,” which Meta reviews but doesn't guarantee it will honor. Users in the EU, UK, and a handful of other regions have a formal right to object under privacy law. Setting an account to private limits what's used going forward, though it won't remove content already used for training, and private messages aren't used regardless of region.

Key Takeaways

  • Meta launched Muse on September 8, 2026, a personal AI agent that connects to email, calendars, payments, and other apps to handle tasks and make purchases on a user's behalf.
  • Meta's own security documentation admits the launch version does not prevent Meta itself from accessing user data when necessary; a fully private version, Muse Confidential VM, isn't shipping until later this year.
  • Internal testing before launch found reliability problems, including an instance where the agent pulled a user's personal iCloud photos after being asked only to identify toys at a birthday party.
  • The launch comes less than two weeks after Meta agreed to pay up to $18 billion to settle a child-safety lawsuit brought by 29 states, adding to a privacy track record that includes the Cambridge Analytica settlement and a record 2019 FTC fine.

FAQ

Does Meta AI use Muse Spark?

Yes. Muse, the personal agent, runs on Meta's Muse Spark model family; the version powering it at launch is Muse Spark 1.3, released September 2, 2026.

Is Meta Muse good?

There's no independent review data yet since Muse only launched September 8, 2026. Meta's security architecture is unusually detailed, but the company's own internal testing already found reliability problems before the public launch.

How much does Muse Spark cost?

Muse Spark is Meta's underlying model for developers, not sold directly to consumers. The consumer product, Muse, offers a free tier plus Power ($20/month) and Maximum ($100/month) subscription plans.

How do I stop Facebook from using my photos for AI?

There's no full opt-out for U.S. users; you can only submit an objection through Facebook or Instagram's Privacy Center, which Meta reviews but doesn't guarantee will be honored. EU, UK, and some other regions have a formal legal right to object.