Meta announced Muse on September 8, 2026, calling it a personal AI agent that takes action rather than only answering questions. Users tell Muse what needs doing - sending an email, booking travel, filling out a form, negotiating a bill - and it works on their behalf, including in the background, asking for approval before sensitive actions. Muse is powered by Muse Spark, which Meta describes as its most capable model to date, built for real-world agentic work. It launched in the United States on iOS, Android and muse.ai, is reachable in the Muse app or directly in WhatsApp, and Meta says AI glasses support is coming.
The notable engineering choice is where the agent runs. Each Muse gets a Muse Secure VM: an isolated cloud computer with its own browser, a separate "Sentinel" agent that controls internet access, encrypted credential storage that keeps passwords hidden from Muse itself, and an audit trail of every action. Meta says a Muse Confidential VM is coming later in 2026, in which the whole VM, including a person's data and conversations, is encrypted with a key only they hold. Payments go through Link by Stripe, with Shop Pay and 1Password support planned.
On privacy, Meta says users choose which apps connect and at what permission level, that Muse conversations are excluded from Meta's ad systems, that users can opt out of training use, and that a "forget" function removes specific learned information. Pricing is described only as free for most needs, with subscription plans for heavier use.
What the announcement does not establish is how reliably the agent completes open-ended tasks like negotiation, or how the security design holds up under adversarial conditions such as prompt injection from the websites it browses. The sandbox, Sentinel and credential isolation are Meta's own descriptions, not independently audited, and the Confidential VM is a promise rather than a shipped feature.