2026-09-09 11:42 UTC
DANGMUAAI & Developer Tools, Decoded
BackAgents

Meta's Muse Agent Wants Your Inbox, Calendar, and Card

Meta's new personal agent runs $20 and $100 tiers, needs a card at signup, and asks for your email, calendar and payments. What the security pitch covers.

DangMua EditorialSep 09, 20264 min read

Meta launched Muse on Tuesday, a personal AI agent with $20 and $100 monthly tiers that asks for a payment card up front.

The free tier is real — Meta says most people will stay on it — but the card is required because paid plans kick in as usage rises. Power runs $20/month, Maximum $100/month, and the app carries a usage meter showing what percentage of usage is left.

What it wants access to

Muse connects to the services people run their week through: email, calendars, payments, plus health and fitness, smart home, dining, shopping, music and events apps. Given a goal, Meta says the agent works on its own — opening a browser, filling forms, booking travel, lowering bills, turning recipe reels into grocery lists, negotiating on a user's behalf. It keeps working after the app is closed and returns for approval on purchases.

Connections are added one at a time. Muse ships with built-in connectors, and for anything missing it will build a connection against a public API using credentials the user supplies — or drive the site through a browser when there is no API at all. That fallback is worth reading twice: browser-driven access means the agent types into your account the way you would.

It runs in the US on iOS, Android, muse.ai and inside WhatsApp chats, with AI glasses "coming soon." The model underneath is Meta's own, called Muse Spark.

The security architecture Meta is selling

Meta's pitch is that the agent is boxed. Muse runs in a dedicated cloud VM with its own browser — Secure VM — that Meta says has no visibility into passwords or payment methods and keeps each user separate from other users' agents. A second agent, Sentinel, runs on the same machine but is kept apart at the system level, and Meta says nothing leaves the VM without matching an existing permission or raising a human-in-the-loop dialog.

David Singleton, Meta Superintelligence Labs' VP of engineering for consumer products, says those approval prompts reach the user directly rather than being filtered through the model — the standard defense against prompt injection. He also concedes the limit: Secure VM "is not a truly locked box," and while policy bars Meta from reading user Muse data, it remains technically possible.

Checkout goes through Stripe's Link, which issues a single-use card number so the agent never handles real card details; Meta says Muse is the first agent covered by Link's purchase protections and their no-fee return guarantee. 1Password and Shop Pay support are listed as coming. Muse is now in Meta's public bug bounty with payouts up to $300,000, including up to $130,000 for a prompt injection affecting a single user. A "Confidential VM" running in a trusted execution environment, with user-held keys and published binaries plus a transparency log, is promised later this year, built with Signal creator Moxie Marlinspike.

The trust ledger

The launch landed less than two weeks after Meta agreed to an $18 billion multistate settlement over social media's consumer harms. The company's own AI record includes a Discover feature that displayed other users' prompts and conversations, and a support chatbot that helped attackers take over more than 20,000 Instagram accounts. Meta says Muse conversations are not shared with its ads systems, and users can opt out of model training and tell Muse to forget specific things — though The Verge notes it is not known whether the training opt-out is on or off by default.

Should you connect it?

The bounty numbers and the single-use card are engineering commitments, not marketing lines, and the Secure VM split is a stronger default than the blanket-license terms early Instinct testers found in their agreement. But every claim above is Meta's, published in a same-day technical post, and none of it has cleared outside review.

Two things to watch before wiring in your inbox: whether independent security researchers confirm the Secure VM boundary once bounty submissions start landing, and whether Confidential VM actually ships this year with the audits and transparency log attached. Until then, connect the accounts you would not mind an agent misusing — and keep the calendar and payments out of it.

More from DangMua