Meta launched Muse on September 8, 2026, calling it “the world’s first personal AI agent built for everyone” — a tool that doesn’t just answer questions but actually books your travel, negotiates with your internet provider, and turns a saved Instagram recipe reel into a grocery list. Within 48 hours, Reuters had internal employee reports describing an agent that pulled a user’s private iCloud photos it was never asked for, and Meta’s own CTO admitting it logged him out “several times within a few minutes.” Both things are true about the same product, launched the same week.
By Shekhar Chandran | Published 15 September 2026 | 10 min read | Facts verified from Meta’s official announcement, plus independent reporting from TechCrunch, Axios, and Reuters (via Implicator.ai and gHacks) on internal testing.
📅 15 September 2026 · 🕐 10 min read · 🗂️ AI Agents & Automation

This page covers:
- What Muse actually is and does, based on Meta’s own announcement
- How the “Muse Secure VM” security architecture is supposed to work
- The internal testing failures Meta’s own staff reported before and at launch
- Pricing, availability, and whether it works in India yet
This page does not cover: a hands-on review — Muse is US-only at launch, so this is a facts-and-context explainer, not a tested verdict. For a working personal-agent comparison, see our Claude Cowork tutorial.
Jump to a Section
- What is Meta Muse?
- How Muse actually works
- The Muse Secure VM: Meta’s security pitch
- What Meta’s own staff found before launch
- Pricing, availability & India
- Should you trust Meta with this?
- AIInsider Verdict
- Quick Answers
What is Meta Muse?
Muse is Meta’s personal AI agent — the company’s answer to Google’s Gemini Spark and Anthropic’s Claude Cowork, but aimed squarely at everyday personal tasks rather than work. Meta’s own framing: “It doesn’t just answer questions, it actually does the work.”
In practice, that means Muse can:
- Send emails, book travel, and fill out forms on your behalf
- Pursue longer-term goals by building its own multi-step plan — Meta’s example is negotiating down a bill
- Keep working after you close the app, and come back to you when it needs input or finishes
- Convert saved content — the example Meta gives is an Instagram recipe reel — into an actionable grocery list
- Make proactive suggestions based on what it’s learned about your preferences over time
- Process payments through Link by Stripe, with Stripe’s purchase protections attached
It’s built on Muse Spark, described as Meta’s most capable model for agentic work, and — per gHacks’ reporting — built using OpenClaw, an open-source AI agent framework, rather than a fully proprietary stack.
How Muse actually works
Muse isn’t a chat window bolted onto your existing apps. It runs as a standalone agent that connects out to the services you grant it access to — email, calendar, payments, health and fitness apps, smart home controls, dining, shopping, music, and events — and acts inside them directly: opening browsers, filling forms, and completing multi-step tasks without you supervising each click.
That’s a meaningfully different model from a chatbot that waits for your next message. Muse is designed to sit in the background, keep a task moving after you’ve closed the app, and resurface only when it needs your input or has something to report.
The Muse Secure VM: Meta’s security pitch
Handing an AI agent your email, payment methods, and smart-home controls is a real trust ask, and Meta’s answer is architectural. Muse runs inside Muse Secure VM — a dedicated, isolated virtual machine in the cloud that Meta says other agents can’t access. On top of that sits a separate Sentinel agent, a system-level watcher that has to approve every internet-bound action Muse takes.
The specific claims Meta makes:
| Claim | What it means |
|---|---|
| Isolated cloud environment | Muse’s VM is inaccessible to other agents, including Meta’s own |
| Sentinel agent oversight | A separate system-level agent approves every action that touches the internet |
| Secure credential storage | Muse itself can’t view your passwords or payment method numbers |
| Audit trail | Every completed and planned action is visible to you |
| Ad-system exclusion | Muse conversations are not fed into Meta’s advertising systems |
| Training opt-out | You can opt out of your data being used to train future models |
| Muse Confidential VM | An end-to-end encrypted version, described as coming later — not available at launch |
My take: the Sentinel-agent-watching-the-agent design is a genuinely sensible pattern for this category, and it’s more architecture than most competing personal agents disclose publicly. But it’s still Meta describing its own safeguards, days after its own staff reported those safeguards failing in testing — see the next section before you weigh this too heavily.
What Meta’s own staff found before launch
This is the part of the Muse story most launch-day coverage led with a headline about, then buried. Reuters reviewed internal employee posts — some dated as recently as launch week — and reported specific, named failures:
- A guardrail bypass that exposed private photos. An employee asked Muse to identify toys in birthday party pictures. It retrieved the user’s personal iCloud photos — content it wasn’t given permission to access for that task.
- Repeated forced logouts. Meta’s own CTO, Andrew Bosworth, said Muse “repeatedly logged him out, sometimes several times within a few minutes.”
- Silent monitoring failures. One tester asked Muse to watch for fast-selling items restocking. It “stopped refreshing after about 15 minutes, other errors passed without notice, and monitoring switched itself off for no apparent reason” — and the tester specifically documented “many failure modes that made it unreliable.”
- Task abandonment without explanation. Per gHacks’ reporting, the agent would sometimes “disconnect from the task without giving any explanation.”
Not every internal account was negative — one tester reported Muse handled travel logistics well across a three-week trip, calling it “the third participant.” And Meta VP Vishal Shah acknowledged plainly that “the system would not be without errors,” rather than denying the reports. Worth noting too: Muse’s original launch was reportedly planned for April 2026 and was delayed specifically to address security concerns before meeting Meta’s own minimum release standards — so this is a product that already slipped once over exactly this kind of issue.
Meta did not respond to Reuters’ questions about the specific incidents.
Pricing, availability & India
| Tier | Price | Notes |
|---|---|---|
| Free | $0 | Basic features |
| Power | $20/month (≈₹1,918 at the live mid-market rate of ₹95.89/$1, checked 15 September 2026 via Wise) | Meta hasn’t publicly detailed what separates this from Free |
| Maximum | $100/month (≈₹9,589 at the same rate) | Highest tier; exact feature gap versus Power also undisclosed |
Muse is live on the web at muse.ai, on iOS and Android apps, and through WhatsApp — with Meta’s AI glasses listed as “coming soon,” no firm date given. A payment card is required to start, even on the free tier.
🇮🇳 For Indian readers: Muse is US-only at launch. There’s no announced India rollout date. If you’re specifically looking for a working personal-agent option in India today, Claude Cowork is live and usable now — see our Complete Claude Cowork Tutorial. We’ll update this page the moment Meta confirms an India date.
Should you trust Meta with this?
This is the honest tension at the center of the Muse launch, and it’s worth naming directly rather than dancing around it. Handing an agent access to your email, payments, and smart home is a bigger ask than any previous Meta product, and it’s coming from a company TechCrunch’s own launch-day coverage described as having “a history of proclaiming one thing and doing another” — citing a 2011 FTC settlement over misrepresenting user privacy, the FTC’s record $5 billion privacy settlement in 2019, 2019 reports of user passwords stored in plain readable text, the Cambridge Analytica scandal, an $18 billion multistate settlement in August 2026 over social-media harms to children, and a $942 million New Mexico judgment on child-safety violations.
None of that is about Muse specifically — it’s Meta’s broader privacy track record. But it’s exactly the context a reasonable person should weigh before connecting an agent to their email and card. Set against that: Muse’s architecture (isolated VM, a separate watchdog agent, credential-blind design, ad-system exclusion) is a real, specific answer to a real category of risk — not just a policy promise. Both facts belong in the same sentence.
AIInsider Verdict
The honest picture: Muse is a legitimately ambitious personal-agent product — broader in scope than Gemini Spark or Claude Cowork’s personal-task coverage, with a security architecture that’s more specific than most competitors disclose. It also shipped the same week its own staff were reporting it exposing private photos it wasn’t asked for and logging its own CTO out repeatedly. Both are true. Neither cancels the other out.
What we liked:
- The Sentinel-agent-approves-every-action design is a real architectural safeguard, not just a policy statement
- Credential-blind design (Muse can’t see your passwords or card numbers directly) is a sensible default
- Genuinely broad task scope — content-to-action conversion (recipe reel → grocery list) is a capability few competitors have shipped
What holds it back:
- Internal staff reports of a guardrail bypass exposing private photos, active as recently as launch week
- Reliability failures reported by Meta’s own testers, including its CTO
- US-only at launch, with no India date announced
- Meta’s own broader privacy track record is the elephant in the room, whatever Muse’s specific architecture claims
Our recommendation, plainly: if you’re in the US and curious, the free tier is a reasonable way to test Muse on low-stakes tasks first — don’t hand it your primary email or payment card on day one of a product its own staff were still filing bug reports on at launch. If you’re in India, there’s nothing to decide yet — Claude Cowork is the working alternative today, and we’ll revisit this the moment Meta confirms an India rollout.
Quick Answers
What is Meta Muse?
A personal AI agent from Meta, launched September 8, 2026, that performs multi-step tasks — booking travel, sending emails, managing bills — across your connected apps rather than just answering questions.
Is Meta Muse available in India?
Not yet. It launched US-only via web, iOS, Android, and WhatsApp, with no announced India date as of this writing.
How much does Muse cost?
Free for basic features, with paid tiers at $20/month (Power) and $100/month (Maximum). Meta hasn’t publicly detailed the exact feature differences between the paid tiers.
Is Muse safe to use?
Meta’s architecture (an isolated secure VM, a separate Sentinel agent approving actions, credential-blind design) is a real safety attempt, but internal staff reports — including from Meta’s own CTO — describe reliability and privacy-boundary failures as recently as launch week. Start with low-stakes tasks rather than full access on day one.
What is Muse built on?
Muse runs on Meta’s “Muse Spark” model and, per reporting, is built using OpenClaw, an open-source AI agent framework.
Related Articles
- Complete Claude Cowork Tutorial (2026) — the working personal/work-agent option available in India right now.
- AI Agents & Automation: What They Are and How to Actually Use Them in 2026 — the category explainer this launch fits into.
- Lindy vs Bardeen (2026) — how two existing no-API automation agents compare.
- Accio Work AI Review 2026 — a hands-on test of a different autonomous business agent.
Published 15 September 2026. Facts verified from Meta’s official Muse announcement (about.fb.com) and independent reporting from TechCrunch, Axios, and Reuters (via Implicator.ai and gHacks) on internal testing; USD-INR conversions use the live mid-market rate of ₹95.89/$1, checked 15 September 2026 via Wise. This is a launch explainer, not a hands-on review — AIInsider.in has not tested Muse directly, as it is not yet available in India. AIInsider.in is independent and not affiliated with Meta.