

Meta Muse Can Act. The Question Is What You Will Allow It to Touch
Meta has given its agent hands, not just a voice. For a regulated buyer, the launch that matters is not the magic, it is the gate: who approves, who pays, and who can undo.
By Katie Delaney / 2026-09-09 / 16 min read

What Meta Muse actually shipped#
The patient prowl always starts with confirmed scent, so here is what Meta itself published on 8 September 2026. meta muse is a personal ai agent that does not merely answer questions but takes action across the services a person connects: email, calendars, shopping, bookings and forms. It lives in a dedicated app for iOS and Android, on the web at muse.ai, and inside WhatsApp chats, with Meta AI glasses named as coming soon. Access is limited to people aged 18 and over in the United States, and the engine underneath is Muse Spark, the model built by Meta Superintelligence Labs for agentic work.
The money shape is simple at launch. A free tier covers most of what people need, with a usage meter that warns before paid use begins, and a reported allowance of up to 100 million tokens a week. Two subscriptions sit above it: Power at $20 a month and Maximum at $100 a month, both for heavier everyday use, and launch reporting notes that a payment card is required to get started.
That meter matters more than it looks, because an ai agent for business lives or dies on whether finance can see the bill before it lands. If your pilot cannot show the meter to the person who signs the budget, you do not have a pilot, you have a hobby with invoices.
What the agent can actually do reads like a careful custodian's job sheet. It sends email, books flights and bus tickets, reserves tables, pays for things, fills in forms, opens a browser and negotiates on a person's behalf. It keeps working after the app is closed and returns when something changes or when it needs approval, like before sending an email or making a purchase. It learns preferences from conversation, the way any personal ai assistant claims to, except here the learning ships with a forget switch, and reflects on what matters, and accepts a plain instruction to forget anything it has learned.
People connect services one at a time, choose read-grade or send-grade access per service, and can disconnect whenever they like. They can opt out of training use, and Meta states that conversations and vault data are not shared with its advertising systems.
Read that catalogue the way a fox reads a hedgerow, not as a list of tricks but as a map of doors. Every door meta muse can open is a door your policy must already have named, with a lock you have tested and a keyholder you can point to. That is the whole posture of folkfox AI consultancy: the client stays the hero of the story, and the agent stays on a leash the client holds.
| Item | Value |
|---|---|
| Messaging surfaces | 4 to 5 |
| Payment rails | 1 to 2 |
| Login stores | 0 to 1 |
| Confidential VMs | 0 to 1 |
| Paid tiers | 2 to 2 |
For buyers outside the United States, the honest reading is that this launch is a preview with a policy homework list attached. The homework transfers perfectly: approval gates, payment rails and audit trails work the same in every jurisdiction, and the only thing that changes across borders is which regulator reads the log. The EU AI Act already sorts general purpose models into duties that touch exactly this kind of system, described in the European Commission's official framework pages, so a European buyer gets a head start by mapping each Muse control to an Act obligation now, while the product is still an ocean away.
Where the approval line sits#
The sharp scent in this launch is architectural, and it answers to the name Sentinel. Each person's meta muse runs on its own Muse Secure VM, a dedicated cloud computer with its own browser, and the agent code itself is caged inside a runtime cell built from Linux isolation primitives: its own filesystem, filtered system calls, stripped capabilities, no host root. Outside that cage sit the grown-ups, in Meta's own telling: separate services for safety screening, scoped connector code, credential storage, and the Sentinel, which Meta calls the sole permission authority for connector actions and every byte of network exit. Nothing the agent does reaches the internet unless the Sentinel allows it.
Here is the detail that makes security folk sit up like foxes at a rustle in the brush, and it is what separates a clever personal ai assistant from a governable one. The agent never sees real passwords or payment tokens. Credentials rest in a guarded store, the agent handles only surrogate tokens, and the Sentinel swaps in the real secret at the network boundary after approval. A prompt injection attack that sweet-talks the agent into revealing a password finds nothing to reveal, because the agent holds confetti, not keys.
A separate safety layer screens requests and responses from outside the cage, so the thing under attack cannot switch off its own guard. Taint tracking follows user data through tool processes, and anything tainted loses its silent auto-allow and falls back to asking the human. That is defence with depth rather than decoration.
When policy cannot decide, execution stops and a human is asked, and the design point is worth repeating slowly. The approval dialog travels straight from the Sentinel to the client screen, never through the chat with the agent, so a compromised conversation cannot forge consent.
Grants are strict capabilities bound to one connector, one destination and one use, in flavours from one-time to session, task, time-boxed or perpetual. The Sentinel chooses which flavours to offer, and later invocations must match the granted scope exactly. And everything lands in a complete audit trail of what the agent did and plans to do, which is the buyer's best friend in the whole building. Steady scrutiny beats blind speed, every single time.
Two honest footnotes before anyone applauds. Meta bars itself by policy from peering into the vault, but reporting confirms it remains technically possible today; the fix is the promised Confidential VM, where the customer holds the keys and even Meta is locked out, currently with trusted testers and external auditors, with binaries and a transparency log promised for public checking, per Wired's technical reporting. And first-of-its-kind is a vendor's boast until independent experts have their say; Meta has put Muse inside its public bounty with payouts up to $300,000 including rewards for single-user prompt injection. Trust the cage, verify the lock, and let the bounty hunters earn their supper.
The person links one service at a time and picks read-grade or send-grade access. Nothing arrives pre-connected.
The agent drafts the action inside its cage: which connector, which method, which scope, and why the person asked.
The silent sentry matches the proposal against policy. Clean, narrow requests may pass; tainted or wide ones never do silently.
Where policy cannot decide, execution halts and a dialog goes straight to the person's screen, outside the chat, for a scoped yes or no.
Every proposal, grant and refusal is written to the trail the buyer can export. What is written can be reviewed; what is reviewed can be trusted.
An agent that can act is a parlour trick. An agent that must ask is a colleague.
That colleague framing is the buying lens for an ai agent for business. You are not hiring genius, you are hiring a tireless junior with the company credit card, and juniors with credit cards get limits, receipts and spot checks. The Sentinel is the spot check made structural. Your remaining job, and it is entirely yours, is to decide the limits before Monday, write them where the agent's policy can read them, and rehearse the revoke the way a fire drill is rehearsed: calmly, in daylight, before anything is burning.

Promise versus proof#
Every launch carries two cargos, and the vulpine habit is to separate them before counting. Cargo one is demonstrated product behaviour, things Meta documented and reporters watched work. Cargo two is positioning, things Meta believes about the future and would like you to believe already arrived. meta muse ships with plenty of both, and a buyer's budget should only ever pay for cargo one.
Start with what is nailed down. The Secure VM, the Sentinel, surrogate credentials, scoped grants, the audit trail, per-service connect and disconnect, training opt-out, the forget instruction, the Link checkout and the tier prices: all of it appears in Meta's own announcement or its technical safety post, and launch reporting from multiple newsrooms describes the same working surface. That is a solid, checkable foundation, and it is more structural honesty than most agent launches have offered. Then mark what is not. Personal superintelligence is Meta's stated direction for meta muse, named in the announcement's closing lines, and it is a prophecy, not a product. Judge the prophecy by all means, but never put it in a business case.
The most useful sentence in the whole launch corpus is also the most boring: most people will stay on the free tier. It tells you Meta expects ordinary use to fit inside the meter, and it tells a buyer exactly where to draw the pilot boundary, at the meter's edge, watching what happens when real workload meets it. Mundane numbers outrank moonlit visions whenever money is near.
| Meta says | Status | What it means for a buyer |
|---|---|---|
| Muse runs each user in a dedicated Secure VM | Confirmed in the announcement and technical post | Ask for the audit, not the adjective |
| Sentinel approves every network exit; the agent never sees real credentials | Confirmed as documented design; independent audit still pending | Pilot it against injection before money moves |
| Checks with the person before sending email or paying | Confirmed as launch product behaviour | Map which of your actions need the same gate |
| Free for most needs; Power $20, Maximum $100 | Confirmed across launch reporting | Model the meter before the team touches it |
| A first step towards personal superintelligence | Positioning, not a shipped capability | Buy the controls, never the prophecy |
| The first personal agent built for everyone | Marketing claim; capable rivals already exist | Judge the gate, not the crown |
- Muse runs each user in a dedicated Secure VMConfirmed in the announcement and technical postAsk for the audit, not the adjective
- Sentinel approves every network exit; the agent never sees real credentialsConfirmed as documented design; independent audit still pendingPilot it against injection before money moves
- Checks with the person before sending email or payingConfirmed as launch product behaviourMap which of your actions need the same gate
- Free for most needs; Power $20, Maximum $100Confirmed across launch reportingModel the meter before the team touches it
- A first step towards personal superintelligencePositioning, not a shipped capabilityBuy the controls, never the prophecy
- The first personal agent built for everyoneMarketing claim; capable rivals already existJudge the gate, not the crown
A word on the brand standing behind the gate, because the gatekeeper's history is part of the risk register. Meta's privacy record includes a 2011 FTC settlement over deceptive privacy claims, a record $5 billion penalty in 2019, and an $18 billion multistate settlement in August 2026 over social media harms, all rehearsed in TechCrunch's launch coverage.
None of that proves the Secure VM leaks; architecture is architecture. But it explains why a regulated buyer demands external audit and key custody rather than promises, and why the Confidential VM matters more than any slogan. For harder lessons on what happens when agent claims meet incident reality, keep folkfox's interactive story on rumour and disclosure open in the next tab: attribution discipline is a buying skill now.
Follow the money layer#
Money is where agent theatre becomes agent liability, so follow the payment path coin by coin. When meta muse pays, it checks out with Link, the wallet infrastructure built by Stripe, and it is reportedly the first agent covered by Link purchase protections: cover for damaged or lost items, price drops, no-fee returns and a return promise on eligible buys. The mechanism is neat: the wallet mints a single-use card number per purchase, so the merchant never sees the real card and the agent never holds it either.
Shop Pay is named as coming soon, which plugs the biggest independent checkout rail into the same flow, and 1Password support is promised for the logins the agent borrows. An ai shopping agent that cannot leak what it never held is a genuine step forward for ambient commerce.
That step still lands inside your ledger, not Meta's, and ledgers have thickets of their own. A single-use card per purchase means a statement full of unfamiliar references unless your reconciliation is ready for them. Refunds travel Link's rails, not your card's, so the return path needs testing with real money and real patience. And the merchant's side of the mirror is already cloudy: recent folkfox reporting found most merchants cannot even tell when an agent made the sale, which turns attribution, support and chargeback evidence into guesswork. Read the attribution gap piece before your first test purchase, because the receipt you cannot explain is the refund you cannot defend.
Three payment controls belong in every pilot policy, written before the first purchase. First, a per-transaction ceiling above which no grant may be perpetual, only one-time, so a forgotten permission cannot become a standing order. Second, a named human who reviews the week's agent purchases against the ledger, the way expenses are reviewed, because agents develop expensive tastes in exactly the categories nobody watches. Third, a shortlist of forbidden checkouts: anything regulated, anything irreversible, anything where the merchant cannot identify the buyer.
The quiet quarry here is not fraud but drift, small approved sums wandering somewhere unexamined. For the brand layer around all of this, how the business talks about agent buying without spooking customers, folkfox brand strategy keeps the voice human while the checkout goes quiet.

The thirty-day pilot#
So what does Monday look like for an ai agent for business that has read this far and still wants the prize? A thirty-day meta muse pilot with a small blast radius, a written forbidden list, and three numbers that must come out clean. The pilot connects one low-risk service, provokes the approval gate on purpose, attacks its own credentials, reconciles real money, and rehearses the revoke. Nothing in that sentence needs Meta's permission, and everything in it works on whichever agent you trial next, because gates are portable even when vendors are not.
The measurement spine follows the NIST habit of governing before trusting: map each control to a function, assign an owner, and review the log like it matters, because it does. The NIST AI Risk Management Framework gives a regulated team the vocabulary, govern, map, measure and manage, and a thirty-day pilot is simply those four verbs with dates attached. Week one governs: policy written, owners named, forbidden list signed. Week two maps: every connected service and granted scope drawn on one page. Week three measures: approval hits, slips, refunds and revoke drills counted. Week four manages: keep, tighten or kill each grant on evidence. Calm, sequential, auditable, the opposite of a thicket.
Approval coverage
Share of money and message actions that needed human sign-off. Target, not measurement.
Unapproved exits
Actions reaching the outside world without Sentinel approval. Must stay at zero.
Refunds cleared
Test purchases fully refunded and reconciled inside the pilot window.
Expect two surprises, and budget for both. First, approval fatigue: the gate that charms on day one nags by day ten, and tired humans start granting perpetual scope to stop the buzzing. Rotate the reviewer, keep one-time grants the default, and treat every perpetual grant as a tiny resignation.
Second, the preference memory will delight and unsettle in equal measure: an agent that remembers dietary restrictions unasked is lovely until it remembers something a customer told it in confidence.
Schedule a forget drill in week two, not week four, and write the data retention rule before the agent learns anything worth forgetting.
Outfox the fatigue and the fondness alike, and the pilot teaches. Conclude the month with a decision memo, not a vibe. Either the gates held and the numbers reconcile, in which case widen one service at a time, or they did not, in which case say so plainly and keep the memo: the next agent trial starts from evidence rather than enthusiasm. If the memo needs a second pair of eyes, folkfox pricing is published and plain, the news stream carries the ongoing agent coverage, and contact folkfox when the pilot needs designing rather than describing. The den is open, the kettle is on, and the gate, as ever, comes first.
Frequently asked questions#
What is Meta Muse?
Meta Muse is a personal ai agent announced by Meta on 8 September 2026. It connects to email, calendars, shopping and other services, then acts on a person's behalf: booking, buying, filling forms and pursuing longer goals. It runs in a dedicated secure cloud computer, asks approval before sensitive steps, and is currently limited to adults in the United States.
Where is Meta Muse available, and on which devices?
At launch Meta Muse is available in the United States only, for people aged 18 and over, through a dedicated iOS app, an Android app, the web at muse.ai, and chats inside WhatsApp. Meta says meta muse is coming to its AI glasses soon. Nothing about other countries or dates has been confirmed, so buyers elsewhere should treat this as a preview, not a roadmap.
How do approvals work in Meta Muse?
Meta Muse proposes an action and a separate component called the Sentinel checks it against policy. If policy cannot decide, everything stops and the person gets an approval dialog sent straight to their screen, outside the chat. Grants are strict and scoped to one connector, one destination and one use, from one-time up to perpetual, and every decision lands in an audit trail.
Does Meta Muse train on my data or share it with advertisers?
Meta states that conversations and vault data are not shared with its advertising systems, and people can opt out of their interactions being used to train Meta models. People can also tell the agent to forget specific things it has learned. Note the honest footnote: Meta bars itself by policy from looking inside the vault, but admits it remains technically possible until the promised Confidential VM arrives.
What does Meta Muse cost?
Meta Muse is free for most of what people need, with a usage meter that warns before paid use begins and a reported allowance of up to 100 million tokens a week. Two subscriptions sit above it: Power at $20 a month and Maximum at $100 a month, both for heavier use. A payment card is required to get started.
What should a regulated business test before letting an agent near money or customer data?
Test five things in a sandbox before anything live: which actions trigger approval and which slip through, whether credentials stay invisible to the agent, whether every action lands in an exportable audit trail, how purchases and refunds reconcile in your own books, and how you revoke access and delete learned preferences. Measure all of it for 30 days before a customer, calendar or checkout is exposed.
Read more on this topic#
Most of It Went Through the Mesh. They Counted What Stayed.
Agent purchases are arriving faster than merchant reporting can see them. The meter problem, one layer down the funnel.
Read the pieceContent marketingAgentic browsing just won its first appeal
A US appeals court held the user does the accessing. Your access rules need the same clarity as your approval rules.
Read the pieceAI consultancyOne staffer, 1.5 million tokens, and a meter nobody was watching
One staffer burned 1.5 million tokens in a day. Caps, routing and per-outcome rates, before finance asks.
Read the pieceWant the gate fitted before the agent arrives?
folkfox designs approval, payment and audit controls for agentic systems in regulated and awkward categories, then proves they hold.
Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.