Meta launched Muse, a consumer agent with access to email, payments and health apps
It books travel, fills forms, lowers bills and buys things through Link by Stripe. It arrives less than two weeks after an $18 billion multistate settlement over harms to children.
Meta has launched Muse, a personal AI agent for US consumers that connects to email, calendars, payment systems, health apps, smart home controls and shopping platforms. It can send emails, book travel, negotiate bills down, fill in forms, build plans, turn recipe videos into grocery lists and make purchases through Link by Stripe.
It is available on the web at muse.ai, on iOS, Android and WhatsApp, with Meta's AI glasses to follow. The service is free initially, with paid tiers at $20 and $100 a month.
The architecture Meta is leading with
Meta has built what it calls Muse Secure VM — a dedicated virtual machine with separate browser isolation. The company says Muse cannot reach passwords or payment methods, and does not share user conversations with its advertising systems.
That is more than most competitors have published, and it deserves credit on that basis alone. OpenAI has not published an equivalent isolation model for ChatGPT Work, which Simon Willison noted on 30 August closes all three sides of the prompt injection "lethal trifecta": access to private data, ingestion of untrusted content, and a path to act externally.
Muse has the same three properties. An agent that reads a user's email and can act on the outside world will encounter text written by people who want it to do something, and the isolation boundary is what stands between that and a consequential action. Meta has described the boundary; it has not published what actions require confirmation, or how the agent distinguishes a user's instruction from an instruction embedded in content it is reading.
The trust problem is the story
The question is not whether Muse works. It is whether American consumers will connect their email, calendar, payments and health data to Meta.
The timing is difficult. The launch comes less than two weeks after Meta settled multistate litigation over social media harms to children for $18 billion, and the company's privacy record includes an FTC settlement in 2011 and a $5 billion penalty in 2019 for violating it.
On 8 September, WIRED and the Tech Transparency Project reported that Meta had carried hundreds of ads over nine months containing AI-generated child sexual abuse imagery, some of it manipulating photographs of real children. That is the same week as the Muse launch, and it concerns the company's ability to police what its automated systems do at scale.
Meta is also, separately, paying users to observe how they interact with its latest model.
What the pricing implies
Free, then $20, then $100 a month is the standard consumer AI ladder, and the $100 tier is the interesting one. It implies workloads heavy enough to justify the price, which means long-running agentic tasks.
Those are expensive. Vals AI estimated this month that long agentic tasks can carry roughly 10,000 times the energy footprint of a simple query, with some web app builds matching 2.5 hours of household electricity use. A consumer agent running continuously across a user's accounts is a different cost structure from a chat product, which is why Meta has established a dedicated compute organisation and entered a $100 billion multi-year agreement with AMD for up to six gigawatts of infrastructure.
The advertising question is the one Meta's assurance does not fully close. Muse conversations are not shared with advertising systems today. Meta's entire business is advertising, the agent is free at the entry tier, and the company has not said what the commitment is worth in a year.
Runs the newsroom. Rename this profile in the studio to your own byline.
Related
Every weekday, the AI stories that moved money or shipped code.
No cross-posting, unsubscribe anytime. See all newsletters