Meta’s new personal AI agent can send emails, book travel, and make purchases. Its safeguards may be as important as its capabilities.
Meta introduced Muse in September 2026 as a personal AI agent that can work across apps and websites. According to Meta, Muse can send emails, book travel, fill out forms, negotiate on a user’s behalf, and complete purchases after receiving approval.
Muse initially rolled out in the United States on iOS, Android, and muse.ai. Meta now describes the agent as available in the United States and Canada, with access through the Muse app, WhatsApp, the web, and Mac. Support for Meta’s AI glasses is planned for the coming months.
At Meta Connect, the company also previewed Muse Charm, a pocket-sized device designed for talking and interacting with Muse.
According to Meta, Muse runs on its Muse Spark model inside Muse Secure VM, a dedicated cloud environment with its own browser. The product also includes connected-app permissions, secure credential storage, activity history, and Sentinel, a separate system that Meta says reviews Muse’s actions before they reach the internet.
Muse is a useful test of where personal AI agents are headed. Its capabilities matter, but so do Meta's choices about access, supervision, and accountability when an AI system can operate across the services people use every day.
What Can Muse Do Across Apps and Websites?
Meta positions Muse as a personal AI agent for individual tasks and longer-term goals. A user could ask it to plan a trip, research a purchase, negotiate a bill, or organize a project. Rather than treating each request as a one-off exchange, Muse can continue working on a task and return when it needs clarification or permission.
The product is also intended to retain context from earlier interactions, including a person’s preferences, ongoing goals, or details such as dietary restrictions. Meta’s examples include turning a saved recipe into a grocery list, helping plan a dinner party, or adjusting a training plan when someone’s schedule changes.
That design asks more of the product than a standard AI assistant. Muse needs to identify the steps involved in a task, access the information or service required at each step, and pause when the next action has a meaningful consequence.
For a purchase, that may mean comparing products, checking delivery options, applying a user preference, and asking for approval before checkout. For an email, it may mean retrieving relevant details, preparing a draft, and confirming that the user wants it sent. Meta builds those approval points into the product rather than relying on the model to decide when user confirmation is necessary.
Muse Secure VM, Sentinel, and App Permissions
Muse currently runs inside Muse Secure VM, a dedicated cloud-based virtual machine with its own browser. According to Meta, the environment houses the agent and a user’s data, while securely storing credentials for services the user chooses to connect. This lets Muse work across apps without operating directly inside the user’s device.
Muse works alongside Sentinel, a separate agent that runs on the same machine but is isolated from Muse at the system level. According to Meta, nothing Muse does reaches the internet unless Sentinel approves it, and Sentinel asks the user for permission when needed.
Meta says Muse can’t see a user’s passwords or payment details. Instead, connected credentials are stored separately, allowing the agent to use a service without accessing the underlying login or payment information. For checkout, Muse can use Link by Stripe to create a one-time-use card rather than expose a user’s actual card number. Meta has also announced planned support for Shop Pay and 1Password.
Users can determine which services Muse may access and what it can do within each one. For example, someone could allow Muse to read email without letting it send messages. They can also disconnect a service, revise access settings, review an activity record, or ask Muse to forget retained information.
Meta also says users can opt out of having their Muse interactions used to train Meta’s AI models. The company says it doesn’t share Muse conversations or data stored in a user’s VM with its advertising systems.
These safeguards don’t eliminate every risk, however. Meta acknowledges that Muse can make mistakes and that prompt injection remains an open problem. The current VM architecture also doesn’t prevent Meta from accessing stored information when needed to support, secure, or operate the service. Meta says a planned Confidential VM is intended to provide that stronger separation.
Where Permissions and Approval Fit In
Muse began as a consumer product, and Meta has since expanded it with connectors and skills for small businesses. Its design reflects a broader challenge for any agentic system: the agent needs enough access to complete useful work without receiving unrestricted authority.
That distinction becomes clearer when an agent’s abilities are separated by the type of action involved. It might retrieve an order record without changing it, prepare a response without sending it, or recommend a resolution without issuing a refund. Each step calls for a different level of access and human review.
For example, a customer-support agent could retrieve an order record, identify the relevant return policy, and prepare a response for an employee to review. A sales agent could draft follow-up notes from approved CRM and product information. An operations agent could assemble a work order while leaving a supervisor responsible for scheduling changes or equipment requests.
Production workflows usually need:
Read access to approved systems and documents
Task-specific access to tools and data
Approval steps for actions involving customers, money, operations, or sensitive information
Activity records showing what the agent retrieved, recommended, and attempted
A clear handoff when the agent lacks information, encounters a tool failure, or reaches a decision it is not authorized to make
Activity records are particularly important once an agent can work across business tools or customer data. Teams need to investigate inaccurate outputs, understand the information and actions that led to a result, and update the workflow when policies, systems, or edge cases change.
Muse and Muse Glimmer are related releases, but they serve different purposes.
Muse is a managed personal AI agent powered by Meta’s proprietary Muse Spark model. It is designed to complete tasks across connected apps and websites, using Meta’s hosted environment, browser, permission controls, credential handling, approval prompts, and activity history.
Muse Glimmer is an open-weight model for developers building their own tool-using agents. Teams can run it locally, fine-tune it for a specific use case, and connect it to internal systems and data sources.
Muse is aimed at individuals who want a ready-to-use agent that operates in Meta’s hosted environment. Muse Glimmer is aimed at developers and organizations that want to run and adapt a model within their own systems. With Glimmer, the team deploying it is responsible for the surrounding controls: deciding where it runs, which data and tools it can access, what actions require approval, and how activity is monitored and logged.
From Demos to Workflows
Muse provides a useful reference point for teams considering agents in customer support, sales, operations, engineering, or internal knowledge management. The product is designed around consumer tasks, but the implementation questions are familiar across industries.
Before connecting an agent to enterprise systems, teams should define:
The workflow the agent will support
The systems, tools, and information it needs
The minimum level of access required
The actions that require employee, customer, or administrator approval
The information that must be logged for review and troubleshooting
The fallback process for incomplete data, conflicting instructions, or failed tool calls
The workflow should shape the architecture. A knowledge assistant may only need read access to approved documentation. A customer-service agent may need to retrieve account information and propose a resolution, while an employee retains the authority to issue a refund. An agent that changes inventory, creates a purchase order, or modifies a production schedule needs stronger controls, clearer review points, and more detailed activity logging.
Teams also need to test agents against the environment where they will actually operate. That includes incomplete records, ambiguous requests, permission errors, tool failures, and attempts to direct the agent outside its approved role. A polished demonstration does not show whether an agent will behave reliably across the edge cases that emerge in a production workflow.
Building Agentic Systems for Production
Meta’s Muse combines a model, a secure execution environment, connected applications, permission settings, credential controls, approval prompts, and activity history. Each part supports a different aspect of the work Muse is designed to perform.
For organizations building AI agents, the starting point isn’t broad access to every available system, but instead a clear understanding of the task, the tools required, the decisions an agent can make, and the situations where people need to remain involved.
FullStack helps organizations build AI and agentic systems around real workflows. Our teams support product strategy, software development, enterprise integrations, data controls, evaluation, and production deployment.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Meta Muse is a personal AI agent designed to work across connected apps and websites. According to Meta, it can help with tasks such as sending emails, researching purchases, booking travel, filling out forms, negotiating bills, and completing purchases after receiving approval.
How does Meta Muse use permissions and approvals?
Muse lets users choose which services it can access and what it can do in each one. A user could allow the agent to read email without allowing it to send messages, for example, while actions involving purchases, sensitive information, or other meaningful consequences can require approval.
What is Muse Secure VM?
Muse Secure VM is Meta’s cloud-based virtual machine for running the Muse agent and its browser. Meta says the environment stores connected-service credentials separately from the agent, allowing Muse to use approved services without directly accessing a user’s passwords or payment information.
What is Sentinel in Meta Muse?
Sentinel is a separate control system that reviews Muse’s actions before they reach the internet. According to Meta, Sentinel acts as the permission authority for connected services and network activity, deciding whether to allow an action, deny it, or request the user’s approval.
What is the difference between Meta Muse and Muse Glimmer?
Meta Muse is a managed personal AI agent for individuals, operating in Meta’s hosted environment with built-in permissions, credential controls, approval prompts, and activity history. Muse Glimmer is an open-weight model for developers and organizations building their own tool-using AI agents, meaning the deploying team is responsible for access controls, approvals, monitoring, and logging.
How can you cut your AI coding costs without switching models?
This guide gives you the math, the meaningful benchmarks, and a six-step plan to cut spend without giving up capability.
Enjoyed the article? Get new content delivered to your inbox.
Subscribe below and stay updated with the latest developer guides and industry insights.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Iframe is blocked. Accept cookies to load it.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We use cookies to provide our services, to allow us to better understand our audience, and to provide and serve personalized ads or content. By using our website, you consent to the terms of our Privacy Policy and our Cookie Policy, and the use of cookies, pixels, and other technology as described more fully therein