Meta Launches Muse, Its Personal AI Agent: Features, Pricing and the Trust Question
Sana Bano
·September 8, 2026
·7 min read
Meta launched Muse on September 8, 2026: a personal AI agent that books, buys and negotiates for you. Features, pricing, security and open questions.
Meta launched Muse on September 8, 2026, a personal AI agent that takes a goal and carries it out for you: opening a browser, filling forms, booking, buying and negotiating. It is live in the US for users 18 and over, free up to 100 million tokens a week, and runs on Meta's Muse Spark model.
Mark Zuckerberg called it "the start of this journey" toward personal superintelligence. Here is what actually shipped, what it costs, and where the open questions are.
Key Takeaways
- Muse went live September 8, 2026 in the US only, restricted to users 18 and over, on the web at muse.ai plus iOS, Android and WhatsApp. Meta says its AI glasses are coming, without a date.
- The free tier covers 100 million tokens per week. Two paid plans launched alongside it: Power at $20 per month and Maximum at $100 per month.
- It runs on Muse Spark, built by Meta Superintelligence Labs, first shown in April 2026 and now at version 1.3 with a one million token context window.
- Muse connects to email, calendars, payment systems, health apps, smart home services and entertainment platforms, and runs inside an isolated environment Meta calls the Muse Secure VM, monitored by a second agent named Sentinel.
- The launch lands roughly two weeks after Meta settled an $18 billion multistate lawsuit over social media harms to children, which is why most launch coverage led with trust rather than features.
What Muse actually does
Meta's own wording is the clearest description available. Once you share a goal, Muse "helps them develop a personalized plan and coordinate their time and resources, then advances the work on its own. It can open a browser, fill out forms, and negotiate on their behalf."

How Muse gets from your goal to a finished task. The confirmation step at stage four is the only point a human sees the output before it goes out.
Not suggest. Not draft. Advances the work on its own.
The launch examples run from trivial to consequential. Booking a tennis lesson. Buying movie tickets. Turning a recipe video into a shopping list. Sending invitations. Shopping. Lowering a bill by finding subscriptions you pay for but never use. Filling out a permission slip for a class field trip. Adjusting a race training plan when you sleep badly.
The through line is that Muse is not built to answer you. It is built to go do the thing and come back.
What Zuckerberg said
Zuckerberg announced it himself in a video, and his framing was blunter than Meta's press language: "Muse doesn't just answer questions, it gets things done for you."
He described his own use: ordering ingredients so he can bake with his youngest daughter, pulling permits so he can climb mountains with his oldest, monitoring his MMA training and health, and finding researchers he wants to meet. Asked what else, he said "that's classified."
He also set the frame Meta wants for the whole product line. "When I talk about building personal superintelligence, Muse is the start of this journey."
Pricing and availability
Free up to 100 million tokens per week. Past that, Power at $20 per month, Maximum at $100 per month.
The token-based free tier is an unusual choice for a consumer product. Most people have no intuition for what 100 million tokens a week buys, and Meta has not published a translation into everyday tasks. Expect that to be the first thing users complain about.
Availability is US only, 18 and over, via muse.ai on the web, native iOS and Android apps, and inside WhatsApp chats. Meta says the AI glasses are next. No date for that, and no date for other countries.
The security architecture
Meta built the announcement around security, and the specifics are more concrete than usual.
Muse runs inside what Meta calls the Muse Secure VM, described as a private computer holding both the agent and your data. A separate agent called Sentinel monitors it for unsafe behavior. Passwords and card details sit in a dedicated credential store that Zuckerberg says Muse itself cannot read. The agent checks with you before sensitive actions like making a payment or sending a message.
Meta also says Muse conversations are not shared with its advertising systems, and promised a higher security tier for people who want it, where even Meta cannot access what is inside your agent. Zuckerberg said the encryption is modeled on WhatsApp.
Why the coverage led with trust
TechCrunch headlined its piece on whether consumers will trust it, and that instinct drove most of the day's reporting.
The reason is timing and record. Muse asks for your email, your calendar, your payments and your health data, and it arrives roughly two weeks after Meta settled an $18 billion multistate lawsuit over social media harms to children. Meta's privacy history includes the Cambridge Analytica data exposure, a $5 billion FTC settlement in 2019, and the discovery that same year that it had stored hundreds of millions of user passwords in plain text.
None of that makes the Secure VM fake. It does mean Meta is asking for more access than it has ever asked for, from the position of least public trust it has ever held.
Where Muse fits in Meta's AI year
Muse is not a standalone launch. It is the consumer end of a model family Meta has been shipping all year.
Muse Spark appeared in April 2026 as Meta Superintelligence Labs' first model. Version 1.1 landed July 9 with a one million token context window. On August 5, Meta released Muse Code, a terminal-based coding agent, alongside Muse Spark 1.2, aimed squarely at Anthropic and OpenAI in the developer market. Muse Glimmer, a smaller open-weight model, followed on August 10. Muse Spark 1.3 is current.
Read in sequence, the pattern is clear. Meta spent the year proving the models on developers, then pointed the same stack at consumers.
What we still do not know
Meta did not say when Muse reaches other countries, or when the glasses integration ships. It has not translated the 100 million token free tier into anything a normal person can plan around. The Secure VM and Sentinel claims have not been independently audited, and the stronger encryption tier is a promise, not a shipped feature.
There is also no public detail on how Muse handles a task it gets wrong after you have approved it.
What it changes for AI detection
One practical note, because it will affect anyone who reads text for a living.
Muse writes emails, forms, appeals and messages that go out under a human name. Meta does keep a checkpoint here, since Muse asks before it sends, but approving a send is not the same as writing the words. That produces text that is authentic in intent and synthetic in language, with no disclosure attached.
Detection still works on it. Muse Spark is a language model, and its output carries the same statistical patterns as any other model output, which you can check with a free AI detector in about two seconds. We covered the same question when reasoning models started writing differently, and the answer holds: the model is still a model.
If your school or company has no written position on agent-written work, a classroom AI use policy template or an AI disclosure policy for content teams is the fastest way to get one.
FAQ
What is Meta Muse?
Muse is Meta's personal AI agent, launched September 8, 2026. You give it a goal and it builds a plan, then carries it out by opening a browser, filling forms, sending messages and making purchases. It runs on Meta's Muse Spark model.
How much does Meta Muse cost?
Free up to 100 million tokens per week. Beyond that, Power costs $20 per month and Maximum costs $100 per month.
Where can I use Muse?
On the web at muse.ai, through iOS and Android apps, and inside WhatsApp chats. Meta says support for its AI glasses is coming but has not given a date.
Who can use Meta Muse right now?
US-based users aged 18 and over. Meta has not announced an international rollout date.
Is Meta Muse safe to connect to my email and payments?
Meta built real safeguards: an isolated virtual machine, a Sentinel agent monitoring for unsafe actions, a credential store the agent cannot read, and a confirmation prompt before payments or sends. Whether that is enough depends on how much weight you give Meta's record, which includes a $5 billion FTC settlement in 2019. Starting with low-stakes connectors is the sensible approach.
What model powers Muse?
Muse Spark, from Meta Superintelligence Labs. It was introduced in April 2026 and is now at version 1.3, with a one million token context window.
Muse is the biggest consumer bet Meta has made on AI, and the first time a major platform has handed ordinary users an agent that spends money and sends mail on their behalf. Whether people give it their inbox is the question the next few months answer.
You can check any text for AI generation free at gptone.me, no signup required.