Muse by Meta: A New AI Agent Designed to Manage Email, Shopping, and Travel

Deep News
Sep 09

On September 8th, Meta launched its personal AI agent, Muse, in the United States, making it available to all users aged 18 and above. The product is accessible through a standalone app, its web version, and WhatsApp, and it has the capability to connect with third-party services, operate a browser, and continuously execute multi-step tasks. To position this assistant as a platform for handling personal affairs rather than just a chatbot, Meta is offering a free version alongside two paid subscription tiers.

Developed by Meta Superintelligence Labs and powered by the Muse Spark series of models, Muse features a conversational interface where users can observe the agent navigating a browser, executing tasks, and requesting authorization. Instead of merely answering questions, the focus is on taking action. Users can describe their goals, and the agent will break them down into steps, coordinate time and resources, and perform the tasks once it has the necessary permissions. Initial capabilities include composing and sending emails, scheduling appointments, booking travel, shopping online, filling out forms, and even assisting with selling a car. Muse can also devise long-term plans for objectives like fitness or starting a business, and it proactively offers suggestions based on progress. Unlike chatbots that require step-by-step instructions, Muse can continue to operate even after the application is closed, re-engaging the user for confirmations when task statuses change or before sensitive actions like sending emails or processing payments. It also saves user preferences and context, such as compiling favorite recipes into a shopping list or recalling dietary restrictions when planning a gathering. While this long-term memory expands its utility, it also increases the amount of personal information it processes.

To execute tasks, Muse opens a built-in browser and connects to user-authorized applications. For payments, it initially integrates with Stripe's Link service, which generates a one-time card number so the agent never handles the user's real card details during checkout. Meta says eligible transactions may also come with protection for returns, price drops, or lost and damaged goods. Shop Pay is slated to be added later, and Meta plans to support 1Password so Muse can access login credentials users have already saved. The company states that passwords and payment details are stored in a separate secure area that the Muse model cannot directly read. This design enables tasks on websites without dedicated application interfaces, but it also introduces higher risks of error and security vulnerabilities. For instance, malicious content on a webpage could attempt to alter the agent's instructions or trick it into sending data externally.

Each user's Muse instance operates on a dedicated virtual machine in Meta's cloud, an architecture known as the Muse Secure VM. This isolates the agent, browser, connected credentials, and related personal data from other users' agents. A separate security agent called Sentinel evaluates proposed actions that involve going online or calling external services, determining whether they should be executed, blocked, or require user confirmation. Meta says Sentinel is separated from Muse at the system level to reduce the risk of prompt injection affecting security judgments. Users can also set distinct read and write permissions, such as allowing Muse to read emails but not send them. Authorizations can be limited to specific tasks, transactions, or timeframes and can be revoked at any time. A complete operation log is maintained, showing the steps Muse has taken and is about to take. Meta assures that data from Muse conversations and virtual machines is not used in its advertising system, and users can opt out of having their data used for model training. However, the current Secure VM is not a fully sealed environment that is inaccessible even to Meta. Citing company executives, WIRED reported that while internal policies restrict access, Meta could still technically retrieve the data. Meta is planning to launch a Confidential VM by the end of 2026, which would employ a trusted execution environment and allow users to manage keys on their local devices, aiming to make it impossible for Meta to read the content. The related code, binaries, and transparency logs are intended to be audited by external security firms.

Muse is initially rolling out to iOS, Android, and web users in the US, and it also supports interaction via WhatsApp. Meta states that most daily needs can be met with the free version, while users with higher task volumes or computational needs can choose between subscription plans at $20 or $100 per month. There are currently no ads on Muse. Meta's Chief AI Officer, Alexandr Wang, mentioned that the company is exploring revenue streams centered on e-commerce. The subscriptions are meant to cover the costs of model inference and cloud computing required for continuous operation and to provide Meta with an AI revenue channel outside of advertising. Muse is also expected to integrate with Meta's smart glasses. If this plan materializes, the agent could use visual and voice information from the glasses to perform tasks, creating a more cohesive ecosystem of Meta's software platforms, wearables, and AI services.

The adoption of Muse hinges on data authorization, as the product requires connections to email, calendars, payment systems, and other services containing sensitive information. The more access a user grants, the more complex tasks the agent can perform, but the risks of operational errors, data leaks, and permission misuse also rise in tandem. Meta has included Muse in its public bug bounty program. According to WIRED, valid security vulnerabilities related to Muse can earn up to $300,000, with a maximum reward of $130,000 for a successful prompt injection attack affecting a single user. Ultimately, Muse's entry into the mass market will depend on balancing task reliability against personal data risks. For now, many of the security and privacy effects Meta has announced remain company claims, and stronger protections like the Confidential VM are not yet available.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10