Trending

Meta's Muse Wants Your Inbox and Your Credit Card. Its Real Product Is the Guard.

Meta's Muse Wants Your Inbox and Your Credit Card. Its Real Product Is the Guard.

On 8 September 2026, Meta launched Muse, which it calls “the world’s first personal AI agent built for everyone.” Muse isn’t a chatbot. You give it a goal and it goes and does the work: sending the email, filling out the form, booking the trip, checking out the cart.

Three weeks in, it’s a hit. Muse reached the top spot on both the App Store and Google Play, and Sensor Tower put it at 560,000 daily active users after 11 days. It’s also the first time most people have been asked to hand an AI the keys to their inbox and their credit card. Here’s what shipped, what it costs, and what you’re actually agreeing to.

View Muse by Meta on appz.com

What actually shipped

Muse works like a text thread. You name your agent, pick an avatar (reviewers ended up with names like Marley, Pip and Scout) and message it like a person. Behind the chat, each user gets Muse Secure VM, a dedicated cloud computer with its own browser, file system and task state. That’s why Muse can keep working after you close the app and check back in when something changes or when it needs your approval.

It connects to the services you already use one at a time: email, calendar, payments, health and fitness, smart home, dining, shopping and more. When there’s no built-in connector but a public API exists, Muse can set up a connection with credentials you provide. When there’s no API at all, it just uses the website in its browser. Per TechCrunch, checkout runs through Link by Stripe, which comes with purchase protections.

The model underneath is Muse Spark, the proprietary model family from Meta Superintelligence Labs that also powers Muse Code. Unlike Llama, you can’t download or self-host it.

View Muse Spark on appz.com

Price and availability

PlanPriceWhat you get
Free$0 (card required)Weekly usage allowance that refreshes
Power$20 / monthMore usage for everyday hand-offs
Maximum$100 / monthThe highest allowance, for heavy parallel use

The tiers differ in usage, not features. Alexandr Wang told Axios that “for the vast majority of users, they should be able to do what they need to within the free tier.” The catch is that even the free tier asks for a payment card at signup. There are no ads in Muse, but Meta has said it’s exploring commerce revenue, so read “free” with that in mind.

Muse is available to adults 18 and over on iOS, Android, the web at muse.ai and inside WhatsApp. The WhatsApp version skips the app’s feed and ideas features. It launched in the US and reached Canada on 18 September. Meta says support for its AI glasses is coming soon. It hasn’t given dates for other countries, and Meta’s terms say you have to be in a supported country to use it, so a VPN puts your linked Meta accounts at risk.

The real product is Sentinel

Every agent company says its agent is safe. Meta published the architecture, and it’s the most interesting part of the launch. According to Meta’s engineering write-up, the system is designed on the assumption that the agent will sometimes make mistakes or get attacked through the pages it reads:

  • The agent never sees your passwords. Logins and OAuth tokens live in a separate credential service. The agent works with stand-in tokens, and the real credential is only inserted at the network boundary after a request is approved. Asking Muse to “print the API key” fails because the key isn’t anywhere it can reach.
  • Sentinel has the final say. Muse can propose an action, but a separate system called Sentinel decides whether it goes ahead, gets blocked or goes to you for approval. The agent can’t override it, and approval prompts go to your app, not through the chat, where an injected message could fake them.
  • Scoped permissions. You can grant read access without write access (read email but not send it), and grants can cover one action, one task, a time window or be permanent.
  • Taint tracking. Once a process has read your data, its outbound traffic loses automatic approval, which makes quiet data leaks harder.

Meta also admits the design has a weakness: if you’re asked to approve every small step, you start tapping “yes” without reading. Testers didn’t hit much friction. The Verge’s headline was that Muse is “great at spending my money.”

Yes, it’s basically OpenClaw

Early users kept noticing that Muse felt familiar. Its workspace files, including a SOUL.md that sets the agent’s personality and boundaries, had the same names as OpenClaw’s, and nearly the same contents. On 21 September, Nat Friedman, head of product at Meta Superintelligence Labs, confirmed it: “We built Muse from scratch, but it is definitely heavily inspired as a product by OpenClaw.” He said the team bought hundreds of Mac minis so staff could use OpenClaw first, and that they “thought that Peter got those things exactly right,” meaning OpenClaw creator Peter Steinberger.

OpenClaw is open source, so there’s no clear legal issue here. What matters for users is the trade: OpenClaw gives you the same agent approach on hardware you control, and Muse gives you a polished, managed version running on Meta’s servers.

View OpenClaw on appz.com

The trust question

Muse asks for more personal access than any Meta product before it, and it launched less than two weeks after Meta agreed to an $18 billion multistate settlement over social media’s harms. There are three things to know before you connect your accounts:

  • Training is on by default. Meta can use your Muse conversations to improve its models unless you opt out. Meta says it scrubs “critical personally identifying information” first. A confidential mode, where Meta can’t see inside your VM, is promised before the end of the year.
  • Internal testing found problems. Reuters reported that pre-launch tests showed the agent stalling and exposing sensitive data without authorization. MetaMeta’s own post says giving the agent unattended access to an inbox and a shell “did not always go as planned” while staff were testing it.rsquo;s own engineering post acknowledges that early internal testing with unattended inbox and shell access didn’t always go as planned.
  • Your VM runs on Meta’s servers. It’s isolated per user, but it isn’t on your device.

Should you try it?

If you’re in the US or Canada and have a backlog of small chores (follow-up emails, bill disputes, appointment booking, comparison shopping), the free tier is an easy, low-risk way to see what a personal agent can do. Start with read-only access, connect one service at a time, and turn off training in settings before you connect anything sensitive.

If you’d rather keep your data on your own hardware, OpenClaw is the same idea, self-hosted. And if your work depends on shared company knowledge like CRM history, team threads or pricing docs, Muse isn’t built for that yet. It only sees one person’s accounts.

Personal agents have arrived for regular consumers, and Meta got there first with a real safety design. Whether people keep trusting it with their inbox and their credit card will come down to Meta’s track record, not the model.

View Muse by Meta on appz.com