Meta Launches Muse, an AI Agent That Books Trips and Pays Bills for You

News Summary
Meta officially launched Muse on September 8, 2026, an AI agent designed to carry out everyday personal tasks — booking travel, sending emails, filling out forms, lowering bills, turning a recipe video into a grocery list, and even completing purchases on a user's behalf. Unlike a chatbot that mainly answers questions, Muse is built to take action inside a person's own digital life, which means connecting to email, calendars, payment tools, health and fitness apps, smart home systems, and shopping or dining platforms. That scope of access has made trust the central question surrounding the launch, even as Meta says it has built new safeguards specifically to address it.
What Muse Can Do
Meta describes Muse as a proactive assistant rather than a passive one. Beyond answering questions, it can open a browser, fill out forms, negotiate on a user's behalf, and keep working on long-running tasks even after the person closes the app. Example use cases Meta has highlighted include converting a recipe reel into a shopping list, drafting and sending party invitations, comparing and lowering recurring bills, and organizing multi-step travel bookings. Purchases can be completed using Link by Stripe, which Meta says carries standard checkout protections.
Users connect their own services one at a time rather than granting blanket access up front, and they can personalize the agent by giving it a name, choosing an avatar, and adjusting how it communicates.
Availability and Pricing
Muse is rolling out first in the United States, accessible through the web at muse.ai, native apps on iOS and Android, and directly inside WhatsApp chats. Meta says support for its AI glasses hardware is coming soon.
The service uses a freemium model: a free tier includes a weekly token allowance intended to be generous enough for regular use, while two paid tiers, Power at $20 a month and Maximum at $100 a month, unlock higher usage limits for people who rely on the agent more heavily. A payment card is required to begin using the service even on the free tier.
The Security Architecture Behind Muse
To address the obvious risk of handing an AI agent access to sensitive accounts, Meta built what it calls the Muse Secure VM — a dedicated, isolated virtual computer in the cloud for each user, complete with its own Chromium-based browser. Credentials and data for any connected service are stored inside that sandboxed environment rather than being visible to the Muse model itself. According to Meta, the agent has no direct visibility into a user's passwords or payment methods; any credentials entered are routed into secure storage that Muse can use without ever seeing the raw values.
A second, separate system called the Sentinel agent runs alongside Muse on the same virtual machine but is kept isolated from it at the architecture level. Meta says Sentinel acts as the sole gatekeeper for any action that reaches the outside world: nothing Muse proposes — no network request, no third-party connector call — goes through unless Sentinel independently approves it. Meta has also said it is developing a "confidential computing" version of the service, aimed for release before the end of 2026, in which even Meta itself would not be able to see activity inside a user's virtual workspace. The company has also stated that conversations and data passed through Muse are kept separate from its advertising systems.
Why Trust Is the Central Question
The launch lands awkwardly in time: it comes less than two weeks after Meta agreed to an $18 billion multistate settlement over allegations that its social media products caused harm to young users. That timing has sharpened scrutiny of a product asking consumers to link financial accounts, health data, and daily communications to a Meta-run system.
Meta's broader privacy record adds to the skepticism. The company reached a settlement with the U.S. Federal Trade Commission in 2011 over allegations it deceived consumers about privacy practices, paid a $5 billion FTC penalty in 2019 following multiple privacy violations, and faced further FTC charges in 2023 for allegedly breaching an existing privacy order. Separately, a 2019 report found that some user passwords had been stored internally in a readable format, and the company's handling of user data was central to the Cambridge Analytica controversy years earlier. Meta has also faced congressional hearings and lawsuits from school districts and individuals over child safety on its platforms.
Meta is not alone in pushing this category. Google has been developing its own agentic assistant under the Gemini Spark banner, and Anthropic has introduced an agent-style product referred to as Claude Cowork, while messaging platforms including iMessage and WhatsApp continue to add their own AI features. Reporting on rival agent products has also surfaced friction points around data licensing: testers of at least one competing agent reportedly balked at terms requiring a "perpetual and irrevocable" license to use uploaded materials, including for model training, underscoring that consumer wariness about data rights extends across the emerging agent category, not just to Meta.
What to Watch Next
Analysts and reporters covering the launch broadly agree that Muse's technical safeguards — the isolated Secure VM, the Sentinel permission layer, and the promised confidential-computing mode — represent a meaningful architectural effort to separate the AI agent from raw credentials and payment data. Whether that technical design translates into consumer confidence is a separate question, one that will likely be shaped less by Meta's engineering claims and more by how the company has handled personal data in the past. Early usage patterns, any reported security incidents, and the pace of the promised confidential-computing rollout are likely to be the clearest signals of whether trust follows adoption in the months ahead.