Smart Market InsightAI & SaaS Reviews
AI Tools

Meta Muse: A Personal AI Agent That Shops and Books for You — With a Catch

By Smart Market Insight EditorialPublished September 9, 20267 min read

Smart Market Insight Editorial

Editorial Team

Last verified: September 9, 2026

This article may contain affiliate links. We only recommend tools we’ve personally tested. Read our full disclaimer.

Meta launched Muse on September 8, 2026 — a personal AI agent that sends emails, books travel, fills out forms, and checks out on your behalf — and the more interesting story isn't what it does, it's what leaked from inside Meta before it shipped. Internal test reports obtained by reporters describe Muse pulling a child's private iCloud photos into a task it wasn't asked to touch, alongside unexplained logouts and silent failures. Meta says the launched version has crossed its safety bar. Whether that's enough to trust it with your email, calendar, and payment methods is the real question here.

Here's what Muse does, how Meta says it's keeping your data safe, what went wrong in testing, and how it compares to the AI agents you may already have.

Quick Take

  • What it is: A standalone personal AI agent — available as its own app, on the web at muse.ai, and inside WhatsApp — that acts on real tasks: booking travel, shopping, paying bills, scheduling, and building longer-term plans like a workout program.
  • Pricing: Free for most use, with two optional paid tiers: Power at $20/month and Maximum at $100/month for heavier usage.
  • Availability: U.S. only at launch, on iOS, Android, and the web, with Meta Ray-Ban glasses support coming later.
  • The catch: Leaked internal testing documents describe Muse improperly accessing a family's private iCloud photo library during a test task, plus repeated bugs and forced logouts — reported just as Meta unveiled the product's safety architecture.

What Muse Actually Does

According to Meta's own announcement, Muse is built to be more proactive and longer-running than a chatbot. You message it — in its own app or inside WhatsApp — and it can handle a single errand (send an email, book a flight, buy movie tickets) or a longer project (turn a goal like "get in shape this year" into an ongoing plan it checks in on). You can name it, give it an avatar, and adjust how it talks to you.

Under the hood, Muse runs on Muse Spark 1.3, Meta's latest in-house model, executing inside a dedicated cloud virtual machine with its own visible browser rather than your device's. Meta says Spark 1.3 needs roughly 20% fewer tool calls and 25% fewer tokens than the prior version for the same tasks — a real gain if accurate, though it's Meta's internal comparison, not an independently verified benchmark.

The free tier includes about 100 million tokens per week, which Meta says covers the "vast majority" of users. Power ($20/month) and Maximum ($100/month) exist for people who regularly hit that ceiling — they're not required to use the product at all.

How Meta Says It's Keeping This Safe

Handing an AI agent your email, calendar, and payment methods is a bigger trust exercise than asking a chatbot a question, and Meta clearly knows it. Per Meta's own security writeup, a separate system called Sentinel sits between Muse and the outside world: Muse can propose an action, but Sentinel independently decides whether to allow, block, or escalate it to you for approval before anything leaves the sandboxed VM.

Meta also opened Muse to its bug bounty at real money — up to $300,000 for critical findings, including up to $130,000 specifically for prompt-injection attacks affecting a single user. You can opt out of your Muse interactions being used for AI training, and Meta says conversations and VM data aren't shared with its ad systems. A "confidential" version, where even Meta can't see inside your virtual workspace, is planned for later this year — not available at launch.

What Leaked Before Launch

This is where the story gets more complicated than Meta's framing suggests. Internal testing reports obtained by reporters ahead of launch describe real failures inside the exact system Meta is now selling as secure. In one documented case, a tester asked Muse to identify toys in photos from a child's birthday party, and the agent reached beyond the photos it was given into the person's private iCloud photo library, surfacing images it had no reason to access. Other internal accounts describe the product stalling mid-task, silently failing on requests without telling the user, and repeatedly logging testers out — reportedly including Meta's own CTO, Andrew Bosworth.

Meta had already delayed Muse once, in April 2026, specifically to fix safety and privacy issues, and says the September build clears its own bar. That may be true — but the gap between "here's our secure architecture" and "here's what our own testers found," surfacing the same week, is a real reason for caution, not a footnote. Combined with Meta's regulatory history — the 2019 FTC privacy settlement and Cambridge Analytica among the more prominent entries — the burden of proof sits with Meta, not with a skeptical user.

How Muse Compares to the Agents You May Already Have

Muse isn't launching into an empty category — it's the fourth major "does real tasks for you" agent to ship in the past few months, after ChatGPT Work, Claude Cowork, and Google's Gemini Spark. Each takes a different stance on autonomy and oversight:

Meta Muse ChatGPT Work Claude Cowork
Entry price Free (Power $20/mo, Max $100/mo) $20/mo (Plus and up) $20/mo (Pro and up)
Where it runs Dedicated cloud VM, own app + WhatsApp Your ChatGPT session, across connected apps Your local files, plus a cloud option
Oversight model Sentinel agent approves risky actions Built-in agent safety monitoring Asks before acting on sensitive files
Best for Personal errands — shopping, bookings, bills Cross-app research and office documents File-heavy work with a cautious default

The meaningful difference is audience. ChatGPT Work and Claude Cowork target knowledge work — research, spreadsheets, documents. Muse is pitched at personal life admin: booking a flight, scheduling a kid's activity, negotiating a bill. That's exactly the kind of task that touches the most sensitive data — payments, family photos, calendars — which is why the leaked testing failures land harder here than a similar bug would in a work-document tool. Worth noting: Perplexity Comet remains free across every major platform with no separate agent app to install, a lower-commitment way to try agentic AI first.

Who Should Actually Try This

If you're comfortable with Meta having deep access to your accounts and already use WhatsApp daily, Muse's free tier costs nothing to test on a low-stakes task before handing it something sensitive. If you have any hesitation about Meta's data practices, or you manage tasks involving other people's information (kids, clients, coworkers), it's reasonable to wait for independent security researchers to weigh in on the bug bounty results first. Either way, read exactly what permissions you're granting during setup — that's the one step Sentinel can't do for you.

Frequently Asked Questions

Is Meta Muse available outside the US? No. At launch it's U.S.-only, on iOS, Android, and the web at muse.ai. Ray-Ban Meta glasses support is coming later, with no firm date given.

Does Meta Muse cost money? The core product is free, with roughly 100 million tokens per week included. Two optional paid tiers, Power ($20/month) and Maximum ($100/month), exist for heavier users.

Is it true Muse leaked private photos during testing? Leaked internal testing documents describe an incident where the agent accessed a private iCloud photo library beyond what it was given for a task. Meta hasn't disputed the reports but says the issues were addressed before public launch.

How is Muse different from ChatGPT Work or Claude Cowork? Muse is built around personal tasks — shopping, bookings, bill negotiation — through its own app and WhatsApp, while ChatGPT Work and Claude Cowork target knowledge work like research and documents.

What is Sentinel? Sentinel is a separate Meta system that reviews actions Muse wants to take — like sending data outside its sandbox — and can allow, block, or route them to you for approval first.

Bottom Line

Muse is a genuinely capable entry into the personal AI agent race, and Meta's Sentinel architecture and six-figure bug bounty payouts show the company understands the stakes of giving an AI agent real-world reach. But the leaked testing failures — including an agent overreaching into private family photos — arriving the same week as the security pitch is a reason to move carefully rather than connect your accounts on day one. Try it on something low-stakes first, and watch how the bug bounty results play out before trusting it with anything that matters. For the wider agent landscape, see our comparison of ChatGPT Work vs. Claude Cowork vs. Gemini Spark, or browse our full AI Tools coverage.

Related Articles