Meta launches Muse, a personal AI agent that connects email, payments and more, putting its consumer AI strategy against a difficult test of trust.

Meta has introduced Muse, a personal AI agent designed to carry out tasks across users’ everyday services, from sending email and booking travel to making purchases. The product is initially aimed at consumers in the United States and marks Meta’s most ambitious consumer AI push yet—but it also asks users to grant the company access to some of their most sensitive digital workflows.
Muse can connect to email, calendars, payment services, health and fitness apps, smart-home systems, shopping, dining, music and event platforms. Meta says users will choose which services to connect individually. That permission model is central to the product’s pitch, but it does not remove the larger question surrounding the launch: whether consumers are willing to let Meta act on their behalf after years of privacy controversies and regulatory scrutiny.
Meta is positioning Muse as an action-oriented assistant rather than a chatbot that only answers questions. The company says it can send emails, book trips, lower bills, fill in forms, create plans, convert recipe videos into grocery lists and send invitations. It can also complete purchases, using Link by Stripe for checkout. Meta says Shopify’s Shop Pay and 1Password integrations are planned for a later stage.
The agent is powered by Meta’s Muse Spark model and will be available through the web, iOS and Android applications, and chats in WhatsApp. Meta also says Muse will eventually reach its AI glasses. The service will have a free tier, with paid plans for heavier use: Power at $20 per month and Maximum at $100 per month. Users will need to provide a payment card when starting, even though Meta expects most people to remain on the free plan.
Muse can continue working after users leave the application, according to Meta. The company also says it can learn from conversations to identify what matters to an individual and make suggestions without being directly prompted. That persistent behavior could make the system more useful, but it also raises the stakes around data retention, unintended actions and how much control users have over the agent’s memory.
Meta says Muse will provide built-in connectors for a selection of services and will add more over time. If a preferred service has a public API, users can provide credentials so Muse can establish a connection. Where no API exists, the agent may interact with the service through a browser.
This gives Muse broad potential coverage, but it creates different security and reliability questions for each connection. An API-based action, a browser-driven form submission and a purchase all carry different risks. For builders and enterprise buyers, the important issue will not only be whether Muse can complete a task, but whether it can explain what it is about to do, stop at sensitive steps and recover safely when a website changes.
Meta says purchases made through Link by Stripe include purchase protections, which could help reduce concern about allowing an agent to check out. That safeguard may address disputes after a transaction, but it does not by itself resolve questions about incorrect orders, unauthorized purchases or the agent’s interpretation of a user’s instructions.
Meta says Muse operates inside a dedicated environment called Muse Secure VM, with its own browser and protections intended to isolate customer data. A separate system, the Sentinel agent, runs on the same virtual machine but is kept apart from Muse at the system level, according to the company.
Meta also claims Muse will not have visibility into users’ passwords or payment methods, and that conversations and other data will not be shared with Meta’s advertising systems. Those are vendor claims based on the company’s technical documentation; the available reporting does not include an independent security audit or outside testing that verifies them.
That distinction matters because the agent will sit close to information that is more sensitive than the data required for a conventional conversational assistant. The launch follows a long record of privacy disputes involving Meta, including a 2019 Federal Trade Commission penalty and earlier allegations that the company misled users about privacy controls. The Cambridge Analytica scandal and past exposure of readable passwords also remain part of the context in which users will assess Muse.
The timing adds another layer. TechCrunch reported that Meta unveiled Muse less than two weeks after agreeing to an $18 billion multistate settlement over alleged social-media consumer harms. The settlement and Muse are separate matters, but together they make the product’s request for access to email, payments and health-related services especially conspicuous.
Muse reflects a broader shift from generative AI that produces content toward AI agents that execute multi-step workflows. For product teams, that changes the design problem. A useful agent needs permissions, connectors, identity management, transaction controls and clear confirmation flows—not only a capable model.
The product’s opt-in connections could give users a more understandable way to manage access than a single, broad authorization. At the same time, the ability to connect services without native integrations, including through browser access, may make behavior harder to standardize and audit. Reliability will be as important as raw model performance: a missed email, incorrect form entry or mistaken purchase can create immediate real-world costs.
Meta’s subscription structure also offers an early signal about the economics of consumer agents. The company is charging for greater usage rather than limiting Muse to a one-time assistant experience. Whether consumers pay $20 or $100 per month will depend on how consistently Muse can save time and how confidently it can handle tasks without supervision. There is no independent adoption data in the available evidence, and Meta’s expectation that most users will remain on the free tier is a company projection rather than a measured market result.
The first signal will be the quality of Muse’s permission and confirmation controls. Users will need to see exactly which services are connected, what data the agent can access and when a task requires explicit approval.
Security researchers should examine Muse Secure VM and the separation between Muse and Sentinel, including how credentials, browser sessions, logs and long-running tasks are handled. Independent testing will be more informative than Meta’s launch documentation alone.
The market should also watch whether Meta expands native connectors, how often browser-based actions fail, and whether the service reaches its promised AI glasses integration. Pricing, usage limits and the treatment of sensitive categories such as health, finance and household access will help determine whether Muse becomes a practical assistant or remains a high-profile experiment.
Muse is significant because it turns trust into a product requirement. A chatbot can be useful while remaining outside a user’s most consequential workflows. An agent that sends messages, changes subscriptions or buys goods cannot avoid responsibility for permissions, mistakes and recovery.
Meta has presented technical boundaries and a granular opt-in model, but those protections remain primarily company-stated until independent experts test them and users see how Muse behaves in ordinary life. For AI builders, the launch is a reminder that agent adoption will depend as much on controllability and accountability as on what the underlying model can do.