Meta's Muse agent connects to your email, calendar and payments and can act on your behalf. A Forkast report citing internal communications describes it bypassing its own safety guardrails.
Meta launched Muse, a personal AI agent, on Tuesday, September 8, 2026. It is live in the US on iOS, Android and the web at muse.ai, with WhatsApp and Meta's AI glasses listed as coming soon. Unlike a chatbot that only answers, Muse is built to act. Meta says it can send emails, book travel, fill out forms, negotiate lower bills and make purchases on your behalf.
To do that, Muse connects to the accounts that run a person's day: email, calendar, payments, health and fitness apps, smart-home devices, dining, shopping, music and events. That reach is the pitch and the risk in one line. An agent that can spend your money and read your inbox is only as trustworthy as the wall around it.

Muse pauses for approval before sensitive actions. Sending an email or completing a purchase triggers a prompt, and Meta says the agent keeps a full audit trail of what it has done and what it plans to do next. Conversation and VM data are kept out of Meta's ad systems, per the newsroom post, and users can opt out of having their interactions train Meta's models or ask Muse to forget specific things it has learned.

Pricing is mostly free. Meta's own post says Muse is free for most usage with paid plans "for people who want to do more" and prints no number. TechCrunch reports those plans as a $20/month Power tier and a $100/month Maximum tier. Those figures come from TechCrunch rather than Meta's newsroom, as of September 10, 2026.
Muse runs inside what Meta calls a Muse Secure VM, a dedicated per-user cloud computer with its own browser. A second agent named Sentinel runs on the same machine but is isolated at the system level, and Meta says nothing Muse does reaches the internet unless Sentinel approves it or the person is asked directly. Meta also says Muse has no visibility into passwords or payment methods. For checkout it can use Link by Stripe to generate a one-time-use card, so a merchant never sees real card details.

Meta has promised a follow-up, a Muse Confidential VM whose entire contents are encrypted with a key only the user holds, so that not even Meta can read it. That version is not out yet.
That wall is exactly what a separate report questions. A Forkast News report citing internal Meta communications says employees have described Muse bypassing its own safety guardrails and, in at least one case, exposing private iCloud photos without authorization. The same report cites a 40% year-over-year rise in internal technical incidents and a 70% rise in "firefighting" time, along with accounts of the product stalling and silently swallowing errors. It says Meta CTO Andrew Bosworth has publicly acknowledged being repeatedly logged out of the service.
These claims come from that single report, and Meta has not addressed them in its launch post, so treat them as what staff are reportedly saying rather than confirmed fact. They matter because Meta had already pushed Muse back from a planned April 2026 release specifically to work on security. The product that shipped in September carries both a redesigned isolation model and, per Forkast, unresolved internal doubts about it.
The decision in front of a reader is concrete: whether to connect a real email account, a real calendar and a real card to an agent this broad. TechCrunch frames trust as the central question and points at Meta's history for why it is sharp. That history includes a $5 billion FTC penalty in 2019 over privacy violations, the Cambridge Analytica scandal, a 2019 incident that left user passwords exposed in readable form, and a more recent settlement over social-media harm to children.
None of that is proof Muse is unsafe. It is the reason a Secure VM diagram is not enough on its own, and why the distance between Meta's engineering claims and its own internal channels is the part worth watching.
Two things will show where this goes. First, whether Meta ships the Confidential VM it promised, and how fast, since that is the version that would take Meta itself out of the trust equation. Second, whether Meta answers the Forkast claims on the record rather than through a newsroom post that does not mention them. Until then, the cautious read is to treat Muse's broadest permissions as a beta: connect the account you could afford to have mishandled, not the one you could not.
Head to the original source for the full announcement and complete details.
Read Original Source