Mark Zuckerberg did not bury the lede at this year’s Connect keynote. “The centerpiece of our vision for what we’re building is Muse,” he told the crowd in Menlo Park on September 23, and then spent the next hour explaining why he wants an AI agent, not a headset, to define Meta’s next decade. “In the coming years, I expect that Muse is going to grow into the personal superintelligence that billions of people around the world are going to use to accomplish their goals and improve their lives.”
That is a large claim for a product that has been publicly available for barely two weeks. Muse launched in the United States on September 8 through dedicated iOS and Android apps, the web and WhatsApp, with a Mac version following on September 19. What makes it different from the chatbots that came before it is scope: Muse does not just answer questions, it acts, reaching into a user’s email, calendar, payment methods, health data, shopping accounts and smart home devices to finish multi-step tasks with what Meta describes as minimal supervision.
The short version
- Muse launched September 8 in the US on iOS, Android, web and WhatsApp, with a Mac app following September 19
- It connects to six categories of a user’s digital life: email, calendar, payments, health, shopping and smart home
- At Connect on September 23, Meta announced Muse Charm, a keychain-sized voice device shipping in time for the holidays
- New shopping partnerships with Shopify, PayPal and Instacart let Muse compare prices and complete purchases on a user’s behalf
- Pricing runs a free tier plus $20 and $100 monthly plans, with Meta planning to eventually profit from a small fee on transactions
- Data sits in a Secure VM today; a Confidential VM, which Meta says even it cannot inspect, is coming later
- The launch follows an $18 billion multistate privacy settlement and a history that includes a $5 billion FTC penalty, which is why trust, not capability, is the question analysts keep asking
An agent built to act, not just chat
The distinction Meta keeps drawing is between an assistant that answers and an agent that finishes. Ask Muse to sell a used car and, according to Meta’s own demos, it can draft the listing, post it, field buyer messages and negotiate within limits a user sets in advance. Ask it to plan a trip and it can compare flights, book a hotel and add the itinerary to a shared calendar without the user opening a single travel site. That kind of chained, multi-app task is exactly what Meta means when it talks about Muse “accomplishing goals” rather than answering prompts.
The infrastructure behind that ambition is split into two systems. Muse itself runs inside a dedicated cloud virtual machine that Meta calls the Secure VM, isolated from the rest of Meta’s infrastructure. A separate system, Sentinel, sits between Muse and the outside world, approving or blocking any action that touches a connected service before it goes out. Zuckerberg described the split plainly at Connect: “We built the Muse Secure VM to keep your information on your own secure virtual machine, and soon we are also going to release the Muse Confidential VM so that even Meta won’t be able to see that information.” The word “soon” is doing real work there, since the Confidential VM, the version Meta says it genuinely cannot inspect, has not shipped yet. The Secure VM that exists today keeps data isolated from other Meta systems, but a secure environment and one Meta itself cannot read are two different promises.
The holiday hardware push
Connect also introduced the first piece of dedicated Muse hardware: Muse Charm, a small, keychain-sized puck built for talking to the agent without opening a phone. Meta says it will ship “in time for the holidays” this December, and Muse is separately being built into the company’s AI glasses line, extending the agent from a screen you tap to a device you wear.
The shopping integrations follow the same logic of removing friction between wanting something and having it delivered. New partnerships with Shopify and PayPal, alongside work already underway with Instacart and other retailers, let Muse check prices across merchants, apply a saved payment method and complete a purchase inside the conversation. Zuckerberg was direct about the business model this enables: “We believe that Muse will make you money and we are standing behind this by making Muse free for a huge number of tokens with the expectation that, over time, we will profit by taking a small fee from transactions.” Free usage funds adoption now; a cut of every transaction Muse completes is the plan for later.
Meta is not the first to hand an agent the keys
The pattern of letting an AI system reach directly into services that used to require a human hand on the mouse is spreading well beyond Meta. Weeks earlier, Google opened its own smart home platform to outside AI agents, breaking Gemini’s exclusive hold on the devices in a user’s house. Enterprise software is moving the same direction from the other end: companies like Ema have raised large rounds specifically because enterprise software is being rebuilt around agents that query and act on company data directly, rather than waiting for an employee to open a dashboard. Muse fits the same shape at consumer scale, just applied to a personal inbox instead of a corporate database.
What sets Muse apart is the breadth of what it touches in one product. A smart speaker skill or an enterprise agent typically has a narrow, defined job. Muse is pitched as a general-purpose executor across health records, financial accounts and personal messages simultaneously, which multiplies both its usefulness and the number of places something can go wrong.
Why the reaction has been about trust, not capability
Reviewers who tested Muse in its first two weeks have mostly come away impressed with what it can technically do. The harder question, raised consistently by analysts, journalists and privacy researchers, is whether people will hand that capability to Meta specifically. The company announced Muse’s broad rollout shortly after agreeing to an $18 billion multistate settlement over social media harms, and its regulatory history includes a $5 billion FTC penalty tied to prior privacy violations. Bank of America analysts summarized the tension directly in a note to clients, writing that “privacy and trust remain key considerations for broader adoption.”
The Secure VM and Sentinel architecture is Meta’s answer to that skepticism, but the mechanics only go so far. A system where Meta says it cannot see your data is a different guarantee than one where Meta cryptographically cannot see it and can prove that to an outside auditor, and today’s Secure VM is the former, not the latter. Meta has also been explicit that AI safety and behavioral commitments are now written into formal policy elsewhere in the industry; Microsoft recently added shutdown-compliance rules directly into its own AI code of conduct, a sign that the industry is starting to treat agent behavior as something that needs to be codified rather than assumed.
| Plan | Price | What it includes |
|---|---|---|
| Free | $0 | A capped allowance of Muse tokens, enough for everyday tasks like email drafts and calendar scheduling. |
| Muse | $20/month | Higher usage limits and priority access to new connected-app integrations. |
| Muse Pro | $100/month | Highest usage ceiling, aimed at users running Muse continuously across shopping, travel and household tasks. |
Pricing as announced at Meta Connect 2026. Meta says per-transaction fees, not subscriptions, are the long-term business model.
Signals to watch
- Whether the Confidential VM actually ships, and whether Meta submits it to independent verification rather than asking users to take its word for it
- Adoption numbers past the novelty phase. Letting an agent touch email and payments is a bigger ask than trying a new chatbot once
- How Sentinel handles edge cases where a task technically matches a user’s permission but produces an outcome they wouldn’t have approved
- Whether competitors follow Meta’s breadth-first approach or continue shipping narrower, single-purpose agents instead
Muse is a genuine bet that people will trade a meaningful amount of access for a meaningful amount of convenience, and Meta is backing that bet with real engineering, a holiday hardware launch and a pricing model built for habitual use. Whether it works depends less on what Muse can technically do, which is already considerable, than on whether the company asking for the keys has done enough to earn being handed them.

