Meta on September 8, 2026 introduced Muse, a general-purpose personal AI agent that Mark Zuckerberg is betting will be one of the most-used consumer products the company has ever shipped. Muse runs on Muse Secure VM — a dedicated cloud virtual machine that houses both the agent and the user's data — and is powered by Muse Spark, Meta's newest agentic model. It is available in the United States on iOS, Android, muse.ai and WhatsApp, with a free tier plus $20/month and $100/month subscriptions.
What Muse Actually Does
Meta pitched Muse as an agent that doesn't just answer questions but does the work: sending email, booking travel, filling forms, negotiating on the user's behalf, turning a recipe reel saved on Instagram into a grocery list, and continuing tasks after the app is closed. It asks for approval before sensitive actions like sending mail or making a purchase, and surfaces a full audit trail of what it has done.
Security Architecture
Meta built a separate Sentinel agent that runs on the same VM but is isolated at the system level — nothing Muse does reaches the internet unless Sentinel approves it. Muse cannot see the user's passwords or payment methods; credentials go into a secure store. Later this year Meta plans a Muse Confidential VM tier where the entire VM is encrypted with a user-held key, so "not even Meta can access it," according to the launch post.
Agentic Commerce And The Competitive Frame
Muse is the first AI agent covered by Stripe Link's purchase protections, generating one-time-use cards so real card details stay hidden. Shopify's Shop Pay is coming soon as another checkout option, alongside 1Password support for existing logins. That plants Meta in the same agentic-commerce race as OpenAI and Anthropic, but with the distribution advantage of WhatsApp and 3 billion Meta users.
Reporting based on coverage from Meta Newsroom, Bloomberg, Axios, TechCrunch and PBS News.
