Meta has launched Muse, a personal AI agent for US adults that connects to a person’s email, calendar, payment methods and other services to complete multi-step tasks like booking travel, buying tickets, filling out forms or building a longer-term plan, rather than simply answering questions in a chat window. The agent runs inside a dedicated “Muse Secure VM,” a virtual machine meant to isolate each user’s agent and data, and is available through a standalone app, the web, or WhatsApp, with a free tier plus $20 and $100 monthly paid plans. Meta describes the launch in its official announcement.
A real product test of whether people trust Meta with more data
Muse is Meta’s most concrete answer yet to the “agents that act, not just chat” push already underway at OpenAI, Google and Anthropic, and the company is leaning hard on distribution: putting the agent inside WhatsApp gives it a messaging surface with billions of existing users that none of its rivals can match. Powered by Meta’s Muse Spark model, the pitch is straightforward, hand off errands like grocery lists, appointments and travel bookings and let the agent work in the background.
The harder question is trust, and the timing makes that unavoidable: Muse arrived less than two weeks after Meta agreed to an $18 billion multistate settlement over allegations that Instagram and Facebook were designed in ways that harmed teenagers. Asking the same company to now manage email, payment credentials and health-app connections is a meaningfully bigger ask than a social feed, and Meta clearly knows it, emphasizing a private bug-bounty program, single-use payment tokens issued through Stripe Link so the agent never sees a real card number, and a human-approval step before any purchase completes.
Reasonable caveats apply. Muse is US-only and restricted to users 18 and older at launch, with no announced timeline for wider availability. Security researchers have already surfaced concerns about agents that can act across a person’s inbox, calendar and wallet, since a single successful prompt-injection attack has a much larger blast radius than it would against a plain chatbot, and Meta itself acknowledges the system needed extensive red-teaming before release. Whether Muse becomes a genuinely useful daily tool or a cautionary tale will depend less on the pitch than on how it holds up once millions of people start pointing it at their real inboxes and bank accounts.

Leave a comment