Will it run?
Agents

Meta launches Muse, a personal AI agent built for the masses

By Ilse Brandt Clawpit staff

Meta unveiled Muse yesterday — a personal AI agent designed to handle everyday tasks: online shopping, sending emails, planning trips — and keep working in the background after you close the app. It runs on Meta's in-house Muse Spark model and rolls out first in the U.S. on iOS, Android, and at muse.ai; a version for the company's AI glasses is coming "soon." Basic use is free. Meta hinted at paid subscriptions for users who want to "do more," but didn't share pricing or free-tier limits.

The claim that Muse is "the first personal AI agent built for everyone" lands in a crowded room. OpenAI's ChatGPT Work, Anthropic's Claude Cowork, Microsoft's Copilot Tasks, SpaceXAI's Grok Bot, the open-source Moltbot, and Google's Gemini Spark all offer similar autonomous capabilities — most targeting enterprises or technical users. Meta's bet is friction: "no learning curve," chat or WhatsApp interaction, and a memory that retains details you mention once so the agent can make proactive suggestions.

For an agent like this to be useful, it needs access to personal data, passwords, and payment methods — a classic attack vector. Meta says Muse runs on a cloud virtual machine isolated per user, with no exposure of credentials or payment info. A second agent, Sentinel, monitors that VM and blocks network access without explicit permission. Users can ask the agent to "forget" specific details and opt out of having their interactions used for model training (it's unclear whether the default is opt-in or opt-out). An encrypted "secret" VM that even Meta cannot access is planned for later this year.

On payments, Muse already supports Stripe Link; 1Password and Shop Pay integration are on the way. The architecture resembles digital wallets more than traditional browser permissions — secure checkout without exposing card details to the agent itself. Meta hasn't published benchmarks for Muse Spark against competitors, and hasn't disclosed model architecture, size, or training data.