Meta's Muse is here, and this is what it can do

Meta's personal agent reads your email, shops for you and haggles your bills down, and it asks before it sends or spends. Here is what it does, what it costs, what its first three weeks turned up, and what to connect first.

News

Meta launched Muse on 8 September 2026: an app you message like a person, which then goes and does the job, opening a browser, filling in forms and negotiating. It is in the US and Canada so far, free for most of what people need, and three weeks in Sensor Tower estimates 5 million downloads.

What Muse is

  • A personal agent. Meta's own line is that it "doesn't just answer questions, it actually does the work". You talk to it in the Muse app or in WhatsApp, and it keeps working after you close the app.
  • Its own model and its own computer. It runs on Muse Spark, which Meta calls its most capable model to date, inside a dedicated cloud machine Meta calls the Muse Secure VM. A separate Sentinel agent on the same machine has to approve anything that reaches the internet.
  • It remembers. It keeps what matters to you and acts on things you mentioned once, such as a friend's dietary needs. You can tell it to forget any of it.

Where to get it and what it costs

  • Where: the US and Canada, on iPhone, Android, the muse.ai website, a Mac app, and inside WhatsApp. It is still rolling out, so your store may show fewer of those. Meta's help page says it is not yet available everywhere, has published no waiting list, and has no Windows app yet.
  • If you live elsewhere: there is nothing to sign up for yet, and Meta has not said whether the WhatsApp route works outside those two countries. The prompt below works for any agent app you can use today.
  • Free up to 100 million Muse tokens a week, the figure Mark Zuckerberg gave in his launch post on 8 September. Meta's help page states only that there is a weekly limit. When you hit it, you wait for the reset or upgrade.
  • Power, $20 a month: 500 million Muse tokens a week. Muse tokens are Meta's measure of how much work the agent does, so the allowance is a weekly ceiling on work.
  • Maximum, $100 a month: 3 billion tokens a week. Buy either plan in the app or at muse.ai, and you must be 18 or the age of majority where you live. Prices in US dollars, from Meta's subscriptions page, read on 1 October 2026.
  • Check the maker before you pay. A developer found a copycat called "Muse AI" in the App Store on 27 September, charging $20 a month, and one reviewer had paid thinking it was Meta's. Start from muse.ai, which is Meta's own site, and check the maker's name before you pay.

What it can do

Everyday jobs

  • Meta's own examples: sell a car for more, lower a bill, adjust a training plan as your week changes, turn a recipe reel you saved on Instagram into a grocery list, and suggest a menu for a dinner party.
  • Long jobs run on their own. Give it a goal and it builds a plan and keeps working after you close the app.
  • Connectors do the reaching. Email, calendar, files and more, each with its own level of access. For email, Meta says you choose whether it only reads your mail or can also send.

Shopping and paying

  • Where it can shop: dozens of partners and the whole Shopify catalogue at launch, and at Connect on 24 September Meta added Walmart, Best Buy, Sephora, Ulta, Gap, Wayfair and others, with Shop Pay and PayPal to pay, Instacart for groceries and Expedia coming for travel.
  • How it pays: Meta says it always asks before completing a purchase, and Link by Stripe gives it a one-time card number so your real card stays hidden. You are responsible for every purchase it makes.
  • Who says no: Amazon blocked it on 20 September and the insurance site Insurify followed on 23 September, saying Muse showed bare prices without the small print. No other shop has joined them, the Boston Globe reported on 30 September.
  • Who gains: Mark Zuckerberg said on 23 September that Meta expects to take a small fee from transactions, so Meta earns when you buy through Muse.

On your Mac

  • What the app reaches: the Mac app asks for Full Disk Access, which covers every file on your computer, and Automation, which lets it act in apps. It can read Messages, Notes, Reminders, Mail and Calendar.
  • Your choice per app: during setup each app can be Off, Read only, or Read and interact, which lets it send a message or delete a note.

For a small business, and what is coming

  • Muse for Small Business launched on 29 September in the US and Canada, connecting Shopify, QuickBooks, Stripe, Canva, Slack, Notion, Zoom, Facebook Pages and Instagram business accounts. Meta says nothing publishes, sends or spends without your approval.
  • Announced at Connect: Muse on Meta's AI glasses in the coming months, where you say its name and it acts on what you are looking at; a voice mode for long conversations; an email address of Muse's own; and a pocket device called Muse Charm, with more due later this year.
  • Later this year: a Confidential VM where everything, your data and conversations included, is encrypted with a key only you hold, so, Meta says, not even Meta can read it.

How it keeps you in control

  • It asks first. It checks with you before sensitive actions such as sending an email or buying, and each connector has its own setting: Always ask, Ask for some actions, or Always allow.
  • It cannot see your passwords. Anything you share goes into secure storage that Muse uses without reading, and it cannot see passwords you type into its browser yourself.
  • Everything is logged. The Activity log under your assistant icon is a record of every action it has taken, in order.
  • Memory you can edit. Tell it to forget something, edit the memory file directly under your assistant icon, then Identity, then Memory, or wipe everything with Reset Muse under Data controls, which cannot be undone.
  • Training is on by default. The "Help improve our AI models" switch under Data controls is on when you start. When it is off, Meta says your interactions with Muse will not be used.
  • Meta does not review custom connectors or how they use your information, so a connector Muse builds for a service that is not on its list is on you to judge.

What the first three weeks turned up

  • 5 million downloads. Sensor Tower's estimate on 30 September, with 12 days at number one in the US, reported by 9to5Mac. Sensor Tower also says Muse got up to half of the ads Meta ran for its own products that fortnight, so Meta's promotion drove part of it.
  • A Mac flaw, fixed in a day. On 21 September the security researcher Patrick Wardle showed that malware already on a Mac could hijack Muse's voice input. Meta shipped a fix the next day. Keep the Mac app updated.
  • The iMessage dispute. An Inc. columnist reported on 19 September that Muse brought up his private iMessages with, he says, Full Disk Access off. By 30 September Meta disputed it: Muse "can't read your Messages unless" both Full Disk Access and the Messages connector are on. Neither side has published a log.
  • An address given to a buyer. The Verge reported on 29 September that a YouTuber who let Muse answer his Marketplace messages says it gave a buyer his address: "Just found out it told people my address and agreed a lowball price". Memeburn explained why: he had picked the always option, so that reply was approved like any other.
  • Its own files walked out. One developer asked Muse to archive what it could see into their Google Drive and received 6.8 GB of its working environment, memory files and logs included, none of it other users' data. Muse hands over whatever it can reach when asked, which is the case for keeping that list short.
  • Written rules helped one seller. After the Marketplace case one reviewer deleted Muse, while a reseller showed ten items sold for $530 under rules he had written for it. The prompt below writes the never-share part of a rule like that.
  • It can be turned on other people. Hunterbrook reported on 28 September that its reporters got Muse to list real Facebook and Instagram accounts of people in vulnerable groups, many of them private, by rewording requests it had first refused. Meta asked for detail, then went quiet. Refusals can be talked around, so keep Always ask on anything that matters.

What to connect first

Muse is only as exposed as the accounts you hand it.

  • Email and calendar: connect a personal account read-only first, since Muse can search your mail without sending from it. A work account stays off unless your employer allows it, and Meta says connecting a calendar shares attendees' names and event details too.
  • Login codes: your inbox holds them, and Business Insider reported on 24 September another agent app reading one and using it without asking. Keep Always ask on your email, and turn down any approval that involves a code you did not request.
  • Your Mac: skip the app unless a job needs your files. If you install it, leave Full Disk Access off and set Messages to Off. One AI engineer put it this way: "Full Disk Access is the key to the building. Your Messages connector is the key to one room."
  • Shopping: pay with the one-time card, check the order on the shop's own page before you approve, and read anything with small print on the provider's own site.
  • Facebook, Instagram and Threads: if Muse sits in the same Accounts Center as these profiles, its privacy policy says Meta may combine your information across them. Meta also says Muse chats are kept away from its ad systems.
  • Marketplace and page messages: keep Always ask, pick the one-time option every time, and tell it what it may never share: your address, your phone number, when you are home.
  • Health, money and custom connectors: leave them off until Muse has done a few small jobs well. Custom ones are easy to make: one Substack writer asked for an iCloud email connector on 21 September and Muse built one.

The prompt: plan which apps Muse can reach

Paste this into any AI chat before you connect anything to Muse or any other agent app. It gives every app a verdict, the setting to pick, and a written never-share rule for anything that answers strangers.

Have ready two or three small jobs you want done, and Muse's list of connections, copied from Settings, then Connectors. If you know what a connection can do, such as read only, add that too.

PromptPlan which apps my AI agent can reach
You are helping me decide what to connect to my AI agent app before I connect anything. An agent can read my accounts and act in them for me, so a connection I do not need adds risk and gives me nothing, and a mistake here can mean an email sent in my name, a purchase I did not want, or other people's private details handed to a company. Work through my apps one at a time, weigh each one against the jobs I actually want done, and give me a clear verdict for each. Never invent a feature, setting name or menu path for my app. If you do not know how my app handles something, say so and tell me what to check.

ABOUT ME (I fill this in once)
- The agent app I am setting up: [e.g. "Meta Muse", "ChatGPT agent", "Claude with connectors"]
- Where I use it: [e.g. "iPhone only", "iPhone and my Mac", "a web browser on my work laptop"]
- The jobs I want it to do in the next two weeks, as specifically as I can: [e.g. "find the school dates in my email and add them to my calendar", "compare prices on a new vacuum and show me three options", "draft replies to customer emails for me to send myself"]
- The connections it offers or asks for, pasted from its settings screen or listed: [e.g. "Gmail, Google Calendar, Outlook, Instagram, Apple Health, Link by Stripe, Messages on my Mac"]
- What the app says each connection can do, if I can find it: [paste from the app's help or settings screen, such as "read only" or "read and send", or write "not found"]
- Which of those accounts are work accounts, shared accounts, or accounts that hold other people's private details: [e.g. "Outlook is my work email", "the family calendar is shared with my partner", "my Gmail has client invoices", or "none"]
- Things I never want an AI to see: [e.g. "my health records", "anything to do with my bank", or "nothing specific"]
- Things I never want it to do or share: [e.g. "give anyone my home address or phone number", "message my ex", or "nothing specific"]
- How hands-on I want to be: [e.g. "ask me before everything for now", "fine for it to read, ask before it sends or buys"]

BEFORE YOU START
Read my answers, then ask me up to five questions, only where the answer would change a verdict. For example: a job too vague to know what access it needs ("which email account do the school emails arrive in?"); an account where you cannot tell if it is work or personal; a connection whose powers I did not describe. Offer options where you can, then wait for my answers. If everything is clear, say so and go on.

STEP 1: WORK OUT WHAT EACH JOB REALLY NEEDS
For each job, list the smallest access that gets it done: which app, whether it only needs to read or also needs to act, and for how long. If a job could be done by me pasting something into the chat instead of connecting a whole account, say so, because a one-off paste gives the app far less than a standing connection.

STEP 2: GIVE EVERY CONNECTION A VERDICT
Go through every connection on my list, one at a time, including the ones no job needs. Give each exactly one of these:
- CONNECT: a job needs it, it holds nothing I never want an AI to see, and it is my own personal account.
- CONNECT READ-ONLY: a job needs to look but never to act. Tell me to switch off sending, posting or changing, if the app allows it.
- WAIT: no job needs it yet. Leave it off until one does.
- KEEP OUT: it holds something I never want an AI to see, it is a work or school account, or it holds other people's private details.
Apply these rules:
- If it is a work or school account, the verdict is KEEP OUT, and tell me to check my employer's or school's rules on AI tools first, since many do not allow work accounts to be connected.
- If it holds other people's private details (clients, patients, pupils, family members' messages), the verdict is KEEP OUT unless I say they have agreed, and explain that their details reach the app company too.
- If it can spend money, connect it only if a job needs it, and tell me to require my approval before every purchase; prefer a one-time or virtual card number, if the app offers one, over a saved card.
- If it can send messages or emails in my name, it must ask me before every send.
- If it replies to strangers for me (a marketplace, a shop's inbox, comments on a public page), it must ask before every reply and never be set to act without asking, even after the first week. Write me a short rule I can give the agent listing what it may never share in those replies: my address, my phone number, when I am home, and everything on my never-do-or-share list.
- If it reads a whole device (full disk access, all files, all messages), treat it as the widest connection on the list: only connect it if a job needs files on that device, and switch off the apps inside it that the job does not use.
- If the app maker says it does not review a connection (custom connectors, or ones someone else built), the verdict is KEEP OUT unless a job cannot be done without it.
- If a connection brings in content from strangers (an inbox, web browsing, shared documents), say so, since text in it can try to steer the agent into doing something I did not ask for.
- If a connection sends updates to the agent on its own, without me asking, say so, since the app then sees changes even when I am not using it.
- If you do not know whether my app can make a connection read-only, write [CHECK IN APP: can this be read-only?] and do not guess.
For each connection write the verdict, one line on why, the exact setting to choose if I told you it exists or [CHECK IN APP] if not, and what could go wrong, in one plain sentence.

STEP 3: THE SETTINGS TO CHANGE BEFORE THE FIRST JOB
Give me a short checklist, in order, of the settings to look for in my app: how often it asks before acting (the strictest option for the first week), whether my chats are used to train the company's AI and how to switch that off, which approval button to press when it asks (the one-time option over the always option while I am learning, and for good on anything that replies to strangers), and where to see a log of what it did. Use only setting names I gave you or that you are sure exist in this app; otherwise describe what to look for and mark it [CHECK IN APP].

STEP 4: A TWO-WEEK CHECK
Tell me what to look at after the first job and again after two weeks: what it did compared with what I asked, anything it opened or read that the job never needed, and which WAIT connections a new job now justifies. Say what should make me disconnect something straight away.

WRITE IT IN THIS SHAPE
MY CONNECTION PLAN
Jobs and the access each needs
[one line per job]
Connections
[Connection] | [VERDICT]
Why: [one line]
Setting: [exact setting or CHECK IN APP]
What could go wrong: [one line]
Settings before the first job
[numbered checklist]
Rules to give the agent in writing
[the never-share rule, word for word, ready to paste, or "none needed"]
Two-week check
[short list]
Questions I still have

CHECK YOUR WORK BEFORE YOU SHOW ME
1. Every connection I listed has exactly one verdict, and none is missing.
2. Nothing I never want an AI to see is CONNECT or CONNECT READ-ONLY, and every connection that replies to strangers has a written never-share rule in the plan.
3. Every work or school account, and every account holding other people's private details, is KEEP OUT unless I said otherwise.
4. You have not named a setting, menu or feature for my app that I did not give you and you are not sure of; each unsure one is marked [CHECK IN APP].
5. Name the one verdict you are least sure of, and why.

Set it up before your first job

  1. Get the real app, and connect nothing yet. Install Muse from the App Store or Google Play with Meta listed as the maker, or sign in at muse.ai. Open Settings, then Connectors, and copy that list into the prompt above.
  2. Pick your first job from the plan. Choose the lowest-stakes one, where a mistake costs little, like finding dates in your email, because Meta's own advice is to start with low-risk tasks while you learn how Muse behaves.
  3. Connect only what the prompt approves. Link the apps marked CONNECT or CONNECT READ-ONLY, since every extra account is more for Muse to read.
  4. Make it ask first. Go to Settings, then Permissions, and set Connectors and Web access to Always ask for the first week, and for good on anything that answers strangers, such as Marketplace. When it asks, pick the one-time option, never the always one.
  5. Treat every approval as a check. A website, email or file can hide instructions meant to steer an agent, which Meta calls a prompt injection attack, and each approval is your chance to catch one. The same goes for Muse's own inbox once it arrives.
  6. Decide about training. Turn off "Help improve our AI models" under Settings, then Data controls, if you would rather your chats stayed out of Meta's training.
  7. On a Mac, switch off what the job does not use. In Muse, open Settings, then File System Access, and turn off those apps, or remove Muse's permissions under Privacy & Security in your Mac's System Settings.
  8. Watch the first job. If something looks wrong while Muse is in its browser, choose Take control of the browser to pause it or Stop the task to end it, because some actions, like a sent email, cannot be taken back.
  9. Check its work in the log, never by asking it. After the first job, open the Activity log under your assistant icon and disconnect anything the job never needed. If you ask Muse instead, you get a generated answer that can be wrong, and the log shows what actually happened.

The honest bit

  • I have not used Muse myself, since it is only in the US and Canada. This page is built from Meta's own pages and dated reports, all read on 1 October 2026, and where Meta and a user disagree, both sides are here.
  • The numbers age fast. The download and ad figures are Sensor Tower estimates, for the first 22 days and the fortnight to 27 September, and the plans and partner lists are what Meta had published by 30 September.
  • Deleted things can stay remembered. Meta says Muse may still remember what it learned from something you deleted, so Reset Muse is the surest wipe.

Make the first job a small one

Run the prompt tonight with two or three jobs you actually want done, connect only what it approves, and give Muse one of them. The log tells you the next morning whether it earned the second.