Meta has launched Muse, a personal artificial intelligence agent designed to carry out tasks across connected apps rather than only answer questions. The company said the service can work in the background, return when it needs a decision and seek approval before taking sensitive actions.

Muse is rolling out in the United States through a dedicated app, WhatsApp and the web, according to Meta’s September 8 announcement. The Associated Press reported that the initial release is for people aged 18 and older. Meta has not announced availability or a launch timetable for Asia-Pacific markets.

An agent built to act across services

Users can give Muse a task or broader goal, after which the agent can make a plan, open a browser, fill out forms and coordinate steps across connected services. Meta said examples include sending emails, booking travel, managing schedules, making purchases and developing longer-term plans. It can continue working after the user closes the app and return when circumstances change or an approval is required.

The service is powered by Muse Spark, which Meta describes as its most capable model for agentic work. Muse can connect to categories of apps including email, calendars, payments, health, shopping and smart-home services, Reuters reported. Users choose which services to connect and can revoke access.

For checkout, Meta said Muse can use Stripe’s Link wallet, which generates a one-time-use card so the agent does not receive the underlying card number. Shop Pay and 1Password support are planned, but Meta did not give release dates. The company also said the product will later come to its AI glasses.

A basic tier is free. Paid plans for heavier usage cost $20 and $100 a month, according to Reuters, citing a Meta spokesperson. Meta’s announcement did not specify task limits or explain how the two subscriptions differ beyond additional usage.

Security architecture faces an early test

Each user receives a dedicated cloud computer called Muse Secure VM, where the agent, connected data and credentials are housed. Meta said the agent cannot see passwords or payment details stored for its use. A separate Sentinel system reviews actions before they reach the internet and can require user approval, including before an email is sent or a purchase is made.

Meta said users receive an audit trail of completed and planned activity, can control app permissions and may opt out of having interactions used to train its AI models. The company also says conversations and data stored in the virtual machine are not shared with its advertising systems. These are company claims and have not yet been independently tested at scale.

In a technical account of the system, Meta acknowledged that an agent can still make mistakes or be manipulated by untrusted information. It said Muse isolates the agent runtime from security-sensitive services and keeps connector credentials outside the agent’s reach. Meta also opened a public bug bounty for Muse, offering rewards of up to $300,000 for qualifying reports.

The launch nevertheless follows concerns found during internal testing. Reuters reported that employees encountered reliability problems and incidents involving unauthorized exposure or transmission of sensitive data. Meta did not address the specific incidents cited by Reuters. Vishal Shah, Meta’s vice president of AI products, told the news agency that an earlier planned April release was delayed for additional security work and that the product had reached the company’s minimum bar for launch.

A US-first test of personal agents

The Associated Press described Muse as part of a broader industry shift from chatbots that retrieve information toward agents that take actions on a user’s behalf. For Meta, distribution through WhatsApp could place that model inside an established messaging channel, although its reach outside the United States remains uncertain.

Meta plans to introduce a version called Muse Confidential VM later in 2026. The company says it will encrypt the entire virtual machine with a key held only by the user, preventing even Meta from accessing its contents. No precise launch date was disclosed.

AI agents will not just support customer journeys in Southeast Asia; they will redesign them