Plain AI Daily

Meta Muse Explained: What It Does, Who Can Get It, and What It Costs

By 7 min read

Meta launched Muse on September 8, 2026, a personal AI agent that books, buys and emails on your behalf from its own cloud computer. It is US-only, on iOS, Android and muse.ai, and works inside WhatsApp. Meta says it is free for most of what people need, with paid plans it has not priced.

Context for this story

Meta launched a personal AI agent called Muse on September 8, 2026, and the pitch is not "a better chatbot." In Meta's words, "it doesn't just answer questions, it actually does the work." Muse gets its own computer in Meta's cloud, its own browser, and permission to act on your accounts: sending email, filling in forms, booking travel and buying things. It is in the United States only, it is free for most uses, and Meta has not said what the paid plans cost.

Key Takeaways

  • It is US-only at launch. Meta: "Muse is rolling out in the US on iOS, Android, and muse.ai, and coming soon to AI glasses." No other country is named and no date is given for one.
  • You can use it inside WhatsApp, which is the detail that decides how many people meet it. Meta says talking to Muse "works just like messaging another person, in the Muse app or directly in WhatsApp."
  • It is free for most things, and Meta has not priced the rest. Its exact words: "It's free for most of what people need, with subscription plans for people who want to do more." No prices are published on any Meta surface we could read.
  • It can spend money, through Link built by Stripe, using a one-time-use card so your real details stay hidden. Meta says Muse is the first AI agent covered by Link's purchase protections.
  • Nothing it does reaches the internet unopposed. A separate Sentinel agent runs alongside it: "Nothing Muse does reaches the internet unless the Sentinel approves it."
  • It keeps working when you close the app, and comes back "when something changes or when it needs approval, like before it sends an email or makes a purchase."
  • Training is opt-out, not opt-in. Meta says "people can also opt out of their interactions being used to train Meta's AI models."
  • Meta says it will still get things wrong: "Muse can and will still make mistakes."
  • Full encryption is not here yet. Meta says Muse Confidential VM, where only you hold the key, arrives "later this year."

What Muse Actually Does

It carries out multi-step tasks on your behalf rather than telling you how to do them. Meta's examples are ordinary errands, not demos: selling a car for more than you would have got, lowering a bill, adjusting a training plan when your week changes, turning a recipe reel you saved on Instagram into a grocery list and remembering your friends' dietary restrictions before it sends the dinner invites.

The mechanics behind that are what separate it from a chatbot. Meta says Muse "can open a browser, fill out forms, and negotiate on their behalf," and that for longer jobs "Muse keeps working after people close the app, and comes back when something changes or when it needs approval." If you want the general version of this idea, our guide to what an AI agent actually is covers how the same pattern shows up in ChatGPT, Gemini and Claude.

The model underneath is Muse Spark, which Meta calls "Meta's most capable model to date, built for real-world agentic work."

Where You Can Get It

The United States, on four surfaces, with a fifth coming. Everywhere else, nothing has been announced.

WhereAvailable?
Muse app on iOSYes, in the US
Muse app on AndroidYes, in the US
muse.ai on the webYes, in the US
Inside WhatsAppYes -- Meta says you can message Muse directly there
Meta AI glasses"Coming soon," no date
Outside the United StatesNot announced. Meta names no other country

What It Costs

Meta has published one sentence about money and no numbers: "It's free for most of what people need, with subscription plans for people who want to do more."

That is genuinely all Meta says. There is no pricing page linked from the announcement, and muse.ai redirected to a sign-in endpoint that returned an error rather than a page when we tried to read it on September 9, 2026. Reports elsewhere name monthly figures; none of them trace to a Meta surface we could open, so this page does not repeat them. If you see a price quoted for Muse, check whether the source is Meta.

What you can act on today: the free tier exists and Meta says it covers most ordinary use, so there is no reason to reach for a card before you have tried it. If you already pay for ChatGPT Plus or Google AI Pro, nothing about this launch tells you to switch, because you cannot yet compare what you would be buying.

The Money and Email Question

This is the part worth reading slowly, because Muse is asking for more access than a chatbot ever has. Meta's own descriptions of the limits are specific, which is a good sign, and they are worth knowing before you connect anything.

What you might worry aboutWhat Meta says
It buys something you did not want"Muse checks with the person before sensitive actions like sending an email or making a purchase"
It sees your card number"Muse has no visibility into people's passwords or payment methods." Payment runs through Link built by Stripe with a one-time-use card
It reads your whole inbox"For things like email, people choose what Muse can do, whether it reads their mail or can also send on their behalf"
You cannot tell what it did"Muse shows people a complete audit trail of everything it has done and plans to do"
It goes off and does something online"Nothing Muse does reaches the internet unless the Sentinel approves it"
Meta uses it to target ads at you"Muse doesn't share a person's conversations or the data in their VM with Meta's ad systems"
Meta trains on your conversationsYou can "opt out of their interactions being used to train Meta's AI models" -- so it is on until you turn it off
Meta can read your dataNot yet ruled out. Muse Confidential VM, "encrypted with a key only they hold, so not even Meta can access it," arrives "later this year"

Two of those rows deserve emphasis because they cut the other way. Training is opt-out. Meta offers the control but does not say it is off by default, so if you care, go and find that setting rather than assuming. And end-to-end encryption is a promise, not a feature: until Muse Confidential VM ships, the VM holding your data and conversations is Meta's to reach.

How Much Should You Trust It

Meta's own answer is the honest one: "Muse can and will still make mistakes, but we expect they'll be much less frequent and cause much less damage due to the safety systems we've built in." That is a fair description of where agents are in September 2026, and it is more candid than most launch posts manage.

The structural protection is the Sentinel: a separate agent running on the same machine, "kept apart from Muse at the system level," that every outbound action has to pass and that Muse cannot override. Credentials go into secure storage rather than to the agent, "including passwords a person types into the browser themselves."

Meta has also put a price on finding holes in it. Its security post opens the Muse bug bounty to anyone and "awards up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user." A six-figure bounty specifically for prompt injection is a company telling you which attack it expects, and prompt injection is exactly the risk that comes with letting software browse the web on your behalf. It is the same warning OpenAI attaches to ChatGPT's Computer History.

Should You Use It

Try it if you are in the US, you already use WhatsApp, and there is a specific errand you keep putting off. The free tier costs nothing and the WhatsApp route means no new app. Start with something reversible.

Connect the minimum. Give it read access before send access on email, and add services one at a time. Meta lets you set this per app, so use that rather than accepting a default.

Turn off training first if that matters to you. Meta says the control exists; it does not say it is on your side by default.

Wait if you want the encryption. Muse Confidential VM is the version where Meta genuinely cannot see your data, and it is not out. "Later this year" is a save-the-date.

Ignore it entirely if you are outside the United States. Meta has named no other country and no timeline, so there is nothing here for you to decide yet.

Sources: Meta's announcement, Introducing Muse: The World's First Personal AI Agent Built for Everyone, published September 8, 2026, and its security and safety post. Every quotation on this page comes from one of those two. Meta publishes no prices for the paid plans, and muse.ai did not return a readable page on September 9, 2026, so no price appears here.

Keep up without the jargon

Frequently Asked Questions

What is Meta Muse?

A personal AI agent Meta launched on September 8, 2026. Meta describes it as software that does the work rather than answers questions: it can open a browser, fill in forms, send emails, book travel and make purchases, checking with you before anything sensitive.

Is Meta Muse free?

Meta says it is "free for most of what people need, with subscription plans for people who want to do more." Meta has not published what the paid plans cost. We could not open muse.ai to check on September 9, 2026, so treat any price you see elsewhere as unconfirmed.

Where can I get Meta Muse?

The United States only, at launch. Meta says Muse is rolling out in the US on iOS, Android and muse.ai, and is coming soon to its AI glasses. You can also talk to it inside WhatsApp, which is the route most people will actually use.

Can Meta Muse spend my money?

Yes, with your approval each time. Meta says Muse checks with you before sensitive actions like sending an email or making a purchase. It pays with Link built by Stripe, using a one-time-use card so your real card details are not exposed.

Can Meta see what Muse does for me?

Partly. Meta says Muse does not share your conversations or your VM data with its ad systems, and has no visibility into your passwords or payment methods. But your interactions are used to train Meta's AI models unless you opt out.

Does Muse read my email?

Only if you connect it and only as far as you allow. Meta says you choose which apps Muse connects to and how much access each gets, and that for email you choose whether it can read your mail or also send on your behalf. You can disconnect any service at any time.

Is Meta Muse safe to use?

Meta has built real guardrails and says plainly that Muse "can and will still make mistakes." Every outbound action passes a separate Sentinel agent, and Meta is offering up to $300,000 for security bugs, including $130,000 for a working prompt injection.

Get the plain-English AI brief

One email. What changed in AI and what it means for you.