Meta Muse: The AI Agent That Actually Does Things

Abstract illustration of Meta Muse, a personal AI agent

Last updated: October 8, 2026

Meta launched Muse on September 8, 2026, calling it a "personal AI agent": software that doesn't just answer your questions but runs errands for you. Shopping, booking travel, filling out forms, chasing tasks while you do something else. About two weeks later, Sensor Tower estimated downloads had passed 2.5 million (via CNBC; Meta hasn't published its own figure, so treat that as an estimate).

Downloads measure curiosity, not usefulness. The better question: what does it mean to hand software the keys to act in your name, and what does Meta charge for the privilege?

Our verdict

Meta Muse is the most serious consumer AI agent yet: serious architecture, fair pricing, real gaps. An agent that acts while you are not watching is either leverage or risk. The Secure VM and approval cards push it toward leverage, but only if you actually manage the permissions.

Try it if you are in the US and drowning in digital errands. Skip it if you are outside the US, or will not connect an agent to your inbox and wallet.

Pros

  • Generous free tier: 100M tokens/week
  • Serious security design: Secure VM + Sentinel + approval cards
  • Keeps working after you close the app
  • Paid tiers buy headroom, not features

Cons

  • US-only, 18+, no international timeline
  • Free tier still requires a payment card
  • Token allowances do not translate to task counts
  • WhatsApp version is cut down

How we researched this. ai2si does not have US-based test accounts, so this is desk research, not hands-on testing: Meta's official announcements and help center, launch reporting from Reuters, CNBC, and TechCrunch, plus third-party data (Sensor Tower via CNBC). Every fact was checked against at least two sources. Where we could not verify something, we said so.

What Muse actually is

Give Muse a goal and it makes a plan, then works through it: opening its own browser, comparing options, filling in forms, messaging on your behalf. You talk to it the way you'd message a person, in the Muse app or inside WhatsApp.

Muse AI agent completing a stroller purchase in its own browser
Muse placing a stroller order in its own browser, down to the card on file. Image: Meta

Underneath is Meta's Muse Spark model family (version 1.3), running in what Meta calls a Secure VM: a dedicated virtual machine in the cloud, assigned to you, with its own browser. Because it has its own computer, it keeps working after you close the app. Watching a price. Finishing a booking. Following up.

This is a different animal from Meta AI, the assistant baked into Facebook, Instagram, and WhatsApp. Meta AI answers questions and helps with research and planning inside Meta's apps. Muse acts outside them. Same company, same model family, completely different trust implications.

The distinction matters more than any feature list. A chatbot is a reference librarian. You ask, it answers, and the worst case is a wrong answer you can check. An agent is a house-sitter. It walks through your rooms, opens your mail, spends your money, whether or not you're watching. With a chatbot you ask "what can it say?" With an agent you ask "what can it do as me?" The security design, the approval flows, the pricing: all of it only makes sense through that lens.

How it works, and the security pitch

Meta leads with security, which tells you where the anxiety really sits. Two pieces do the heavy lifting.

Illustration of AI agent security: a shield guarding data

The Secure VM. Your agent and its data live on an isolated virtual machine. A second system has to sign off before anything Muse does touches the internet.

Sentinel. A separate agent on the same machine, walled off from Muse at the system level, decides which sites and actions Muse may touch. A bouncer between your agent and the outside world.

Muse AI agent finding and filling out a permission slip from email
Muse finding a permission slip in your email and filling it out. Image: Meta

Anything sensitive comes to you first as an approval card in the app. Payments, emails, anything that spends money or speaks in your name. Meta says Muse can't see your passwords or payment details, and that nothing in the VM feeds its ad systems. That last claim deserves a long look. It's a promise from a company whose business is advertising, not a law of physics. The architecture looks sound. Treat the pledge the way you'd treat any corporate privacy promise: provisionally.

You choose which apps to connect and can revoke access anytime. Sensible. Whether anyone will actually manage those permissions instead of tapping "allow all" is another question entirely.

Pricing: free, $20, $100

Plan Price Weekly usage
Free $0 Up to 100M tokens/week (Zuckerberg, via CNET)
Power $20/mo 500M tokens/week (Meta help center)
Maximum $100/mo 3B tokens/week (Meta help center)

The free tier is genuinely generous. Meta calls Muse "free for most of what people need," and 100 million tokens a week backs that up. The paid tiers buy headroom, not features. Same agent, bigger token pool, nothing unlocks.

The catch nobody can clear up: Meta doesn't say how tokens convert into finished tasks. Does 500 million tokens a week buy fifty errands or five hundred? Without that number, the $20-versus-$100 decision is guesswork. You're buying a bigger bucket with no markings on the side.

And "free" has fine print. Signing up takes a payment card, an 18+ confirmation, and US location, before the agent does a single thing. A lot of trust to extend to software you haven't tried.

Where you can use it

US only, 18 and up. Five surfaces: iOS, Android, muse.ai on the web, WhatsApp, and a native Mac client added September 17. At Connect on September 24, Meta previewed what's next: a real-time avatar for video calls with your agent, smart glasses integration, and full Mac desktop control. That last one puts Muse directly against computer-use agents from OpenAI and Anthropic.

Two footnotes. The WhatsApp version is cut down; the real agent lives in the standalone app. And outside the US, all of this is spectator sport. No international timeline announced.

Muse for small business

On September 29, Meta pointed Muse at small businesses (Reuters): integrations with Shopify, QuickBooks, Stripe, and Canva, plus Instagram analytics, Facebook Pages, and Meta ad accounts. Connect your storefront, books, and customer records, and the agent runs parts of the operation.

The commitment worth noting: Meta says the business version will not publish content, send messages, or make purchases without explicit approval. For an agent product, that's the whole ballgame. It's now the standard every competitor gets measured against.

Five honest limitations

  1. US-only. No international timeline. Reading this elsewhere? File it under "later."
  2. Free isn't frictionless. Card upfront, 18+, US location, before you've seen it do anything.
  3. You can't do cost-per-task math. Token allowances without task conversions make pricing directional at best.
  4. WhatsApp users get the lite version. Hundreds of millions of people live in WhatsApp. They don't get the full agent.
  5. The trade itself. An agent's power is its access, and its risk is the same access. Secure VM, Sentinel, approval cards: genuinely thoughtful design. You're still giving software your email, calendar, and payment rails, built by an ad company. Architecture you can audit. Incentives you watch over time.

Who should try it

Try it if you're in the US and drowning in small digital errands. Bookings, comparisons, forms, price-watching. The free tier is big enough for a real experiment.

Pay for it if you'd run it continuously. A small business piping it into Shopify and QuickBooks. Anyone who wants background errands as a daily utility.

Skip it if you're outside the US, won't connect an agent to your inbox and wallet, or just want a chatbot. ChatGPT or Claude already answer questions without asking for your credit card.

Muse is the industry's clearest bet that consumer AI moves from answering to doing. Serious architecture, fair pricing, real gaps. Whether an agent that acts while you're not watching feels like leverage or like risk, that's the actual decision. No download chart makes it for you.

This review was written with AI assistance; all facts were independently verified.

About ai2si

ai2si (“AI to Super Intelligence”) is an independent publication covering AI tools, workflows, and trends. No hype, no jargon walls — just clear, useful signal.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top