Meta announced Muse on September 8, 2026, introducing a personal AI agent designed to work on ongoing goals rather than wait for individual prompts. It can browse websites, complete forms, manage appointments, contact customer support, prepare purchases, and keep working while its app is closed. The initial rollout started in the United States in English.
The agent is accessible through a dedicated Muse app and directly inside WhatsApp. Underneath that familiar chat interface, Meta has built a more complex system: every Muse agent runs inside a persistent virtual machine containing its browser, working files, memory, and task history.
That architecture is the most important part of the launch. Letting an AI write a summary is relatively low risk. Letting it sign into accounts, manage private information, and make changes on the open web requires a different security model.
Muse Turns an AI Conversation Into Ongoing Work

Muse begins with the same interaction model people already understand from messaging apps. A person describes a task or goal in natural language, and the agent develops a plan, asks for clarification where necessary, and starts working.
A request can be narrowly defined, such as finding an available appointment or completing a return form. Muse can also manage broader goals over days or weeks. Meta says it can track progress, monitor relevant information, and suggest actions based on what it knows about the user. It might follow a school district website, collect important dates, add events to a family calendar, or assemble a shopping cart without requiring the user to direct each browser step.
The Muse design team built dedicated views for goals, activity history, permissions, memory, and ongoing tasks. The app can also produce interactive “artifacts” instead of returning everything as chat text. Depending on the request, an artifact might be a travel itinerary, calendar, comparison table, or other structured result that the user can review and modify.
Muse’s proactive behavior is a meaningful departure from conventional assistants. Instead of requiring a fresh prompt whenever circumstances change, the agent can return with an idea, explain what prompted it, and offer to take the next action. That makes Muse potentially more useful, but it also gives the system more opportunities to misunderstand a goal or act on outdated context.
Muse’s Differentiator Is Persistence, Not Web Browsing
Meta’s launch language positions Muse as a new class of consumer product, but computer-using AI agents have existed for some time. OpenAI introduced a computer-using agent model in January 2025, while Google presented its own personal AI agent in May 2026. Both were designed to interact with software and online services on a user’s behalf.
Muse’s more defensible distinction is the combination of a persistent personal environment, long-running goals, proactive suggestions, and a consumer interface built around messaging. Its virtual machine stays available between conversations, preserving the files and working state needed to continue a task later.
The persistent environment also lets Muse perform several jobs in parallel. A user does not have to keep a browser tab open while the agent waits for an appointment, monitors a website, or works through a multi-stage process.
Muse Secure VM Is the Core Security Bet

Each Muse runs inside a dedicated, persistent virtual machine called Muse Secure VM. The environment includes a Chromium-based browser and a runtime that can execute code, manage files, and communicate with approved external services. Meta describes it as two isolated security domains on one machine: one for the agent’s activity and another for host-side safety systems.
That separation matters because the browser will inevitably encounter untrusted content. A malicious webpage could contain instructions intended to manipulate the model, a technique known as indirect prompt injection. If an agent treats those instructions as legitimate, it could reveal private information or perform an action that the user never requested.
Meta’s technical description of Muse security says sensitive credentials and other protected browser state remain encrypted until delivered inside the isolated runtime. User information stored in host-side databases is not directly readable by the virtual machine or by the underlying model. Higher-risk websites and tools can also be placed in separate sub-runtimes to reduce the possibility of information moving between services.
A separate system called Sentinel monitors the virtual machine from outside the environment. It combines deterministic rules with language-model-based checks to identify suspicious behavior, and it can cut off access to resources when it detects a problem. Meta says users can also pause or cancel work through Muse or activate a broader kill switch from the product’s settings.
These controls make Muse’s architecture more credible than simply giving a chatbot unrestricted browser access. They do not make it invulnerable. Meta explicitly acknowledges that no system is completely secure, and some of the company’s strongest privacy protections are not available at launch.
In particular, Meta operations personnel can access data when necessary to run or secure the service. The company plans to introduce confidential virtual machines later, which would reduce that access by moving encryption keys into attested hardware-isolated environments. Meta also says Muse data is kept separate from users’ social profiles and will not be used to train its models.
The advertising boundary is less absolute. Although Muse does not directly share personal agent data with Meta’s advertising systems, the company says information can still reach those systems indirectly through ordinary web activity. Clicking an advertisement, visiting a business’s website, or using an external provider may generate signals under those services’ existing privacy policies.
Approval Controls Matter More Than the Autonomy Claim

Muse pauses before higher-impact actions such as sending an email or completing a purchase. The user sees the proposed action and decides whether to approve it. Meta also provides an activity log showing what the agent has done, what it is doing, and which permissions have been granted.
Users can choose whether a permission applies once or on a recurring basis. That flexibility is convenient for repeat tasks, but permanent approvals need careful handling. An action that seems harmless in one context may carry different consequences when the underlying website, account, or goal changes.

Payments use external providers rather than storing card details directly inside Muse. Stripe is providing payment infrastructure, with support for Meta Pay at launch and planned integrations with Shop Pay and 1Password. Muse can prepare a transaction, but the user remains responsible for reviewing and approving it.
This human-in-the-loop system may prove more important than the agent’s raw autonomy. The practical challenge is avoiding approval fatigue. If people become accustomed to confirming every request without reading it, a technically sound permission screen offers much less protection.
Muse Spark 1.3 Runs Long-Lived Agent Tasks
Muse is powered by Muse Spark 1.3, which Meta describes as its most capable model for agentic work. The model works with an external tool server that supplies structured instructions for browsing, file management, connected services, and other actions.
The model is designed to operate across a longer time horizon than a typical chat response. It can break a goal into stages, use tools, evaluate intermediate results, and continue from saved context. Meta says Muse can accumulate knowledge about a user’s preferences and circumstances over months, subject to editable memory controls.
The broad consumer rollout will provide a more useful test than isolated model benchmarks. Long-running agents can fail in subtle ways: carrying forward an incorrect assumption, using stale information, repeatedly choosing an unsuitable service, or completing the wrong version of a task. Reliable recovery and clear reporting will matter as much as the model’s ability to operate a browser.
WhatsApp Is Meta’s Distribution Advantage
Muse can be used as a separate app, but WhatsApp may be the more consequential interface. It places an autonomous agent inside a communication tool that many people already check throughout the day, removing the need to learn a new workflow or keep another application open.
Users can message Muse as they would another contact, return later to review progress, and respond when the agent requests approval. That fits naturally with tasks involving coordination, reminders, research, and gradual decision-making. Meta’s announcement says the experience is designed to work through both the Muse app and WhatsApp from the initial rollout.
The same convenience increases the importance of identity and notification design. A proactive message from an agent can look similar to a message from a person, even though it may have been generated from incomplete information. Muse will need to make the distinction between a suggestion, a completed action, and an approval request consistently obvious.
Meta’s existing reach also gives it an advantage that model performance alone cannot provide. If Muse becomes a normal WhatsApp contact, personal agents could move from specialized early-adopter tools into everyday consumer use much faster.
Availability and Pricing Leave Questions
Muse began rolling out in English in the United States on September 8, 2026, through the Muse mobile app and WhatsApp. Meta says it intends to expand to more countries and languages, but it has not announced a detailed international schedule.
The company says Muse will be free for most use and will also offer paid subscriptions. It has not published exact usage limits, plan prices, or a clear explanation of which capabilities require payment. Those details will affect whether persistent agent computing can be offered broadly or becomes a premium service for people with frequent, resource-intensive tasks.
Final Thoughts
Muse is not important simply because it can click buttons on a website. The more substantial development is Meta’s attempt to package persistence, memory, browser automation, permissions, and proactive planning into an agent that feels like an ordinary messaging contact.
Muse Secure VM shows that Meta understands the risks created when an AI gains access to personal accounts and the open web. The remaining question is whether those protections hold up under ordinary use, where users grant recurring permissions, agents encounter hostile content, and long-running plans drift away from their original instructions. Muse will succeed only if people can trust both what it does and what it chooses not to do.
Frequently Asked Questions
5 questions
1What is the Meta Muse AI agent?
Meta Muse is a personal AI agent that can browse websites, complete forms, book appointments, handle customer-service tasks, prepare purchases, and manage longer-term goals. It works through the Muse mobile app and WhatsApp. Unlike a conventional chatbot, Muse can continue working in the background, preserve task context, track progress, and proactively suggest actions based on a user’s goals.
2
Sources
- announced Muse on September 8, 2026about.fb.com
- https://x.com/Muse/status/2097399178376671666x.com
- How We Designed Museintroducing.muse.ai
- computer-using agent modelopenai.com
- personal AI agentblog.google
- How We Built Safety Into Museresearch.meta.ai
- Stripe is providing payment infrastructurestripe.com
- Muse Spark 1.3
