Muse operates within your applications under the supervision of a second agent
Meta launches Muse in the US, a personal agent that browses, emails, and pays, featuring a dedicated virtual machine and human validations.
Closing the app does not necessarily stop the task. Muse can continue monitoring a website, organizing a trip, or preparing a sale, then return to the user when something changes or approval is required. With this new personal agent, Meta wants to move beyond an assistant that answers questions to one that takes action.
Muse is rolling out in the United States on iOS, Android, and the web. Users can also message it directly through WhatsApp. The service is restricted to people aged 18 and over and is expected to reach Meta’s AI glasses at a later date, although no specific timeline has been provided.
A basic version is free. Meta mentions subscription plans for heavier use but does not list their prices in its launch announcement. A spokesperson told Reuters that two plans would cost $20 and $100 per month. The company has not yet publicly detailed their computing allowances, task limits, or exact differences.
Muse does more than draft a message or suggest a list of steps. The user gives it an objective, and the agent searches for the necessary information, uses authorized services, and continues working toward the result. Meta cites sending emails, booking travel, negotiating bills, selling a car, and adjusting a training plan as possible uses.
The product can also handle longer-term objectives. It develops a plan, tracks its progress, and distributes the work over time. A dedicated section displays ongoing projects, upcoming actions, and items awaiting a response. Several requests can move forward simultaneously without forcing the user through a rigid sequence of questions and answers.
This continuity depends on persistent memory. Muse stores preferences, goals, scheduled tasks, and selected information drawn from conversations or connected services. It could, for example, retrieve a recipe Reel saved on Instagram, prepare a grocery list, and account for a dietary restriction mentioned several weeks earlier.
The agent is also proactive. It can send a message without a new request when it detects a deadline, a calendar change, or an opportunity related to a goal. Users can reduce, increase, or disable these interventions. Meta says it has tried to avoid unnecessary notifications, although the system itself is responsible for deciding which updates are worth surfacing.
The browser is a central part of the product. Muse can open pages, conduct searches, fill out forms, compare offers, and complete transactions. Users can watch what it is doing and take direct control of the browser. When they do, the agent is paused so that it cannot act at the same time.
Muse also has a file system and a terminal. It can write code, create a tool for a specific task, and build custom connectors when a service provides an API or command-line interface. It can also produce documents, PDFs, trackers, web pages, and interactive interfaces that Meta calls “Artifacts.”
These capabilities do not mean the model can freely modify its own parameters. The documentation describes the creation of code, tools, and skills within the user’s personal environment. It does not describe autonomous retraining of the foundation model.
The product uses Muse Spark, Meta’s family of models designed for agentic work. The launch announcement links to Muse Spark 1.3, released six days earlier. Meta says it trained the model to sustain long-running tasks, coordinate multiple workflows, use tools, request help when it encounters an obstacle, and better recognize actions that may be difficult to reverse.
The company compares Muse Spark 1.3 with several competing models across evaluations covering professional work, computer use, web research, programming, and long-context tasks. Its methodology report notes that some results come from Meta, while others were taken from official leaderboards or competing providers. The tools, execution environments, and settings are therefore not always identical.
Muse’s autonomy does not come from the model alone. Each user receives a separate Linux virtual machine in the cloud called Muse Secure VM. It contains the browser, workspace, files, and services required to execute tasks. The machine remains active even when the phone or app is no longer in use.
Meta’s technical description separates the environment where the agent works from the components responsible for protecting data. Muse operates inside a container with restricted system privileges and network access. More sensitive information, including credentials for connected services, is stored outside this runtime environment.
OAuth tokens, passwords, and payment methods are not directly shown to the model. When an action requires authentication, Muse handles a substitute credential. The real secret is inserted only when the authorized request leaves the machine. This separation reduces the risk of a malicious web page or document coercing the agent into revealing a password.
Email access receives additional protections. Meta says it filters out one-time passcodes, password reset links, and automatic login links. Without these filters, an agent authorized to read an inbox could theoretically use it to take control of other accounts.
A second agent called Sentinel controls interactions with connected services and outbound internet traffic. Muse proposes an action, but Sentinel decides whether to approve it, reject it, or request the user’s permission. It can inspect the destination, protocol, HTTP method, requested path, and content of the request.
Approvals do not pass through the regular conversation. Sentinel displays a separate card in the app describing the exact action under review. Permission can apply to one operation, a session, a task, a limited period, or indefinitely. This distinction is intended to stop Muse from rephrasing an approval request itself or interpreting an ambiguous response as authorization.
Not every request triggers an alert. Previously approved access or an action considered low-risk may proceed automatically. Users can also assign