Future TechnologyFuture Technology
CONSUMER

Meta's Muse agent wants your inbox, your calendar and your card

· 6 min read · By Future Technology

Key takeaways

  • Meta launched Muse on 8 September 2026 as a task-executing personal agent, with apps on iOS and Android and a web version at muse.ai
  • Muse asks for access to email, calendar, payment methods, health services and reminders, a wider permission set than any mainstream consumer agent so far
  • It runs a model called Muse Spark inside an isolated virtual machine, with a separate Sentinel agent that must approve anything sent to the internet
  • Free tier plus $20 and $100 monthly plans, United States only at launch

Meta launched Muse on 8 September 2026, a personal AI agent that sends emails, books travel, fills in forms, negotiates and completes purchases. It asks for access to your email, calendar, payment methods, health services and reminders.

That permission list is the story. Every major lab is shipping agents that claim to complete tasks rather than answer questions. Meta is the first to ask a mainstream consumer audience for this much account access at once.

What it is meant to do

Muse is pitched on task completion, not conversation. It opens a browser, fills forms and checks out on your behalf, working through multi-step goals with limited supervision.

Wired cites selling a car and booking a flight as example tasks. Other coverage lists buying movie tickets, scheduling a tennis lesson and filling in a school permission slip. The common thread is errands with a transaction or a calendar entry at the end, the part of a task that a chatbot has to hand back to you.

It is rolling out in the United States only, on iOS, Android and muse.ai, with support for Meta's AI glasses described as coming. There is a free tier for most uses, plus subscriptions at $20 and $100 per month.

The architecture is the pitch

Meta's answer to the obvious objection is structural. Muse runs on a model called Muse Spark inside an isolated environment Meta calls Muse Secure VM. A separate agent, Sentinel, has to approve anything Muse sends out to the internet.

On top of that, Muse is meant to check with the user before sensitive actions such as sending an email or making a purchase, and it keeps an audit trail of what it has done and what it intends to do next.

This is a reasonable design. A privileged agent that can spend money and read your inbox is exactly the thing prompt injection attacks target, and isolating the model from direct network egress behind a second checker is the standard mitigation. Whether it holds up is an empirical question that will be answered by researchers rather than by launch material.

The reaction was about trust, not capability

TechCrunch framed its coverage around whether consumers will trust it. Android Authority centred on the permissions ask. The Verge described the launch as part of a multi-billion-dollar strategy overhaul aimed at closing Meta's gap in the AI race.

The Hacker News thread drew 395 points and 414 comments within a day, and the discussion was about data access rather than agent quality. That is unusual. Model launches normally get argued about on benchmarks.

The reason is not mysterious, and this part is analysis rather than reporting: an agent with inbox and payment access generates a far richer behavioural record than an ad-tracking pixel ever did, and it generates it for the company whose data practices have been the subject of the longest-running consumer privacy argument in tech. Meta says privacy controls are built in. The coverage suggests that claim starts from further back than it would for a company with a different history.

Two things called Muse

Muse the consumer agent is not Muse Glimmer, the 30-billion-parameter open-weight agentic model Meta released in August. The names overlap and the coverage has occasionally blurred them.

Glimmer is infrastructure for developers. Muse is a product for people who want a flight booked. They share branding and, presumably, research lineage, but they are aimed at different audiences and are evaluated on different things.

What to watch

The interesting metric is not adoption of the free tier. It is what proportion of users grant the full permission set rather than the minimum, and how many of them keep it granted after the first month.

Meta positions Muse against OpenClaw and Instinct, both of which ask for narrower access. If Muse converts on the wider ask, the industry norm moves and every competitor's permission dialog gets bolder. If it does not, the constraint on consumer agents turns out to be trust rather than capability, which is a harder problem to engineer around than a benchmark score.

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.

Enjoyed this? Get the briefing.

One email, every weekday: the top story, a useful tool, and what matters in tech - in under 3 minutes.

More from Future Technology

AI

Anthropic bought $517 billion of compute after warning rivals about the risk

AI

The EU AI Act is enforceable now and the fine is 7 percent of revenue

AI

AI reads brain MRIs in seconds with 97.5% accuracy

AI

Google ships the Gemini 3.6 Flash family and starts Gemini 4