Meta launched Muse, a personal AI agent that runs digital tasks on a user's behalf, releasing it Tuesday on iOS, Android, the web at muse.ai, and inside WhatsApp. Paid tiers start at $20 a month for Power and reach $100 a month for Maximum, with a free tier gated by a usage meter. Meta is also opening Muse to its public bug bounty, offering up to $300,000 for valid vulnerability findings and up to $130,000 for prompt injection attacks that compromise a single user.
Muse is the first mass-market product out of Meta Superintelligence Labs, the unit Mark Zuckerberg formed roughly a year ago to close the gap with OpenAI, Anthropic, and Google. The agent is powered by an in-house model called Muse Spark and was tested internally under the codename Hatch. Support for Meta's AI glasses is planned but not dated.
The pitch is that Muse can send emails, book travel, fill out forms, lower bills, turn recipe reels into grocery lists, and complete purchases. Checkout runs through Stripe's Link, which issues a single-use card number so the agent never handles a user's real payment credentials. Meta says Muse is the first agent covered by Link's agent purchase protections, which guarantee no-fee returns. 1Password and Shopify's Shop Pay integrations are listed as coming soon.
Key facts
- 01Muse launches in the US on iOS, Android, muse.ai, and WhatsApp, with Meta AI glasses support coming later.
- 02Paid tiers are Power at $20/month and Maximum at $100/month; a free tier with a usage meter is the default.
- 03Meta's public bug bounty pays up to $300,000 for Muse vulnerabilities and up to $130,000 for single-user prompt injections.
- 04Checkout runs through Stripe's Link with single-use card numbers; 1Password and Shop Pay integrations are on the way.
- 05Muse is powered by Meta's in-house Muse Spark model and shipped by Meta Superintelligence Labs, formed roughly a year ago.
Users connect apps one at a time — email, calendar, health, smart home, dining, shopping, music, events — and Muse ships with built-in connectors, uses public APIs where available, and falls back to controlling a browser when no API exists. The agent keeps working after the app is closed and pings the user for approval on actions like purchases.
“We know it's really important, if we're going to build a product like this that can access a lot of sources of personal data, that we're really responsible with that, so we've designed this system very deliberately”— David Singleton, VP of Engineering, Meta Superintelligence Labs Consumer Products
The security architecture is where Meta is trying to differentiate. Muse runs inside what Meta calls a Secure VM, a dedicated virtual machine per user that isolates untrusted web data from the code that can act on the user's behalf. A second agent called Sentinel monitors what leaves the VM, matching each outbound action against user-approved policies or presenting a human-in-the-loop prompt. Meta says those approval prompts bypass the model itself, a defense against prompt injection.
David Singleton, VP of engineering for consumer products at Meta Superintelligence Labs, said the Secure VM has been vetted by Meta's human and agentic red teams and through the company's private bug bounty before the public expansion. He also acknowledged the limit: Meta is barred by policy from reading user Muse data, but it remains technically possible. Users can opt out of having their interactions used to train Meta's models and can instruct Muse to forget specific things it has learned.
A stronger tier, Confidential VM, is coming later. It runs each VM inside a trusted execution environment with access keys held locally on the user's device, meaning even Meta cannot reach the contents. Meta is working with Moxie Marlinspike, the creator of Signal, on the design, will publish the Confidential VM binaries and a transparency log, and is giving select security firms source access for ongoing audits.
“Muse is a first step: an agent that takes on more of the work so people can focus on what matters to them”— Meta, Company statement
The competitive frame is crowded. OpenClaw, Instinct, Google's Gemini Spark, Anthropic's Claude Cowork, Microsoft's Copilot Tasks, and the open-source Moltbot are all chasing the same agent-does-the-task pattern. Meta's advantage is distribution — WhatsApp, Instagram, and the Meta AI glasses — and its argument is that consumer agents live or die on trust, and it has engineered accordingly.
Trust is also the problem. Meta announced Muse less than two weeks after agreeing to an $18 billion multistate settlement over social media harms, and was ordered to pay $942 million in a separate New Mexico case involving harms to children. The FTC hit Facebook with a then-record $5 billion privacy settlement in 2019 and charged Meta with violating that order in 2023. Prior AI missteps include a Discover feature that surfaced other users' prompts and a support chatbot that helped attackers take over more than 20,000 Instagram accounts.
The counterweight worth naming: agent-level security is genuinely hard, and a per-user VM with an outbound-action monitor is more disciplined than what most rivals have shipped. But the Secure VM tier available at launch still leaves Meta with theoretical access to user data, and the stronger Confidential VM is dated only as later this year. Users who route email, calendar, payments, and shopping through Muse are extending Meta a level of visibility into their lives that the company's ad business has spent two decades trying to buy.
The market question for Meta is whether Muse converts free users to $20 and $100 subscriptions at a rate that justifies the compute bill from Meta Superintelligence Labs. The distribution edge through WhatsApp is real, and Stripe's single-use card infrastructure removes one of the biggest objections to letting an agent transact. What Meta has not yet proven is that a consumer base burned by Cambridge Analytica and this year's $18 billion settlement will hand a Meta product the keys to its inbox and its wallet on the strength of a white paper.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




