The new US service can work across websites and keep going after a person closes the app. Meta says a separate safety agent checks important actions before they happen.
New to this? Read it in simple words
- Meta launched Muse, a personal AI agent for adults in the United States. It can use websites, send email, book travel and buy things.
- Meta says another agent, called Sentinel, checks important actions before they happen. It can allow a step, block it or ask the person.
- An agent that can spend money needs clear permission. It also needs a safe way to stop.
- The safety design sounds careful, but it still needs outside testing.
- AI agent
- An AI that takes steps on its own to finish a task, such as booking or coding.
Muse moves from advice to action
A person can talk to Muse in its own app, on the web, or through WhatsApp. The agent can open a browser, fill in forms, and continue a task after the user closes the app.
Meta gives examples such as booking travel, lowering a bill, selling a car, and planning a dinner. Muse can ask for approval before it sends a message or buys something. It can also remember details that a person shared earlier.
The service is for people aged 18 or older in the United States. Meta offers a free level and paid plans. TechCrunch reports prices of $20 and $100 per month, with different limits and features.
Meta says Muse works in an isolated virtual machine and asks for approval before actions such as sending email or making a purchase.
A separate system checks risky steps
Muse works inside a special virtual computer called Muse Secure VM. This area keeps the agent and a person’s data separate from other users. Credentials are stored outside the agent, according to Meta.
Meta says another agent, called Sentinel, reviews actions that use the internet or another service. Sentinel can approve a normal step, block it, or ask the person. This separation may stop one mistake from becoming a real action.
The design sounds careful, but it needs outside testing. A harmful page can try to change an agent’s instructions. A wrong booking or payment can also cause damage even when the computer itself is secure.
Trust depends on visible control
Meta says users decide which accounts Muse can reach. It also says people can review an action history and disconnect a service. The company says Muse data is not shared with its advertising systems.
A useful approval screen should explain the exact action, price, receiver, and data being shared. A simple yes button is not enough. People also need a fast stop button and a clear way to correct mistakes.
Muse is an important test of personal agents. Its value will not come from how many websites it can open. It will come from whether normal people understand, control, and trust each important action.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · September 8, 2026Introducing Muse: The World’s First Personal AI Agent Built for Everyone Meta
- 2Primary source · September 8, 2026Security and safety for AI agents: Our approach with Muse Meta AI Research
- 3
We used Meta for the product design, launch limits, and privacy claims. We used TechCrunch for prices and outside questions about trust. We describe safety features as Meta claims because the new system has not yet faced broad independent testing.