共有:

Personal AI Agent

Meta's companion AI
steps into the spotlight.

On September 8, 2026, Meta AI launched Muse, a personal AI agent that can operate a browser and handle bookings and emails on your behalf once you tell it a goal. It's the first time Meta's Muse model family, previously reached mostly through APIs and research, gets a consumer-facing front end.

AI Navigate Editorial2026.09.096 min read

BEFORE Muse models API access only 2026.09.08 public launch AFTER M ai.meta.com/muse
01
The Launch

Why Meta moved now

While ChatGPT, Claude and Gemini compete over the conversation window, Meta caught up with an AI that acts

Until now, the Muse models were something you could only reach through a developer-facing API. Meta launched Muse, a consumer-facing personal AI agent, at ai.meta.com/muse, shipping an iPhone and Android app alongside a web version at muse.ai at the same time. It's aimed at U.S. users aged 18 and over, and Meta's official announcement says support for AI glasses is coming.

What Muse can do goes well beyond answering questions: tell it a goal, and it builds a plan, opens a browser, fills out forms, and negotiates on your behalf. Meta's announcement cites sending emails, booking travel, negotiating a lower bill, and selling a car as concrete examples, with purchases going through Stripe's Link for checkout. Where ChatGPT and Claude were built to answer, Muse is built to act — which is what makes this more than an ordinary product launch.

Until nowFrom Sept 8, 2026
Muse models reached mainly via APIPublic launch at ai.meta.com/muse
Aimed at developers and researchersAimed at U.S. consumers 18 and over
Mostly conversational responsesAutomates browsing, bookings, negotiation
No payment integrationHandles purchases via Stripe's Link

What comes after the chatbot is
an experience where asking makes it happen. Muse is the testing ground.


02
How It Works

Keeping an AI that acts
on its own safe

The key is a two-layer design: "Secure VM" and "Sentinel"

State a goal Secure VM Dedicated isolated env. Sentinel Send email Book travel Payment
FIG. From stating a goal, through execution inside a Secure VM, to permission checks by Sentinel

An agent that can autonomously send emails and complete payments naturally raises the worry that it might do something unwanted. Meta's answer is the Secure VM, an isolated virtual machine assigned to each individual user. Each person's Muse runs only inside this dedicated environment, and the credentials and data for any connected service are stored there too.

On top of that, a separate process called Sentinel inspects every outbound network request and every action taken through connected apps, and acts as the sole permission authority that asks a human to approve sensitive actions, according to Meta AI Research's technical blog. Not giving the agent itself final authority over network egress is a design choice that could become an industry pattern for guarding against prompt injection and runaway actions.

01

State a goal

Describe the outcome you want — "lower my bill" — rather than the steps to get there.

02

Secure VM plans and executes

Inside the isolated environment, it browses, fills out forms, and negotiates automatically.

03

Sentinel checks permission

Only sensitive actions require human approval; all outbound traffic is inspected.

03
Pricing

How much you get for free

Three pricing tiers — and Meta itself says the free one should be plenty

Free
Meant to cover basic everyday use
$20/mo
For more frequent users
$100/mo
Top tier for heavy usage

Alexandr Wang, Meta's chief AI officer, told Axios that "for the vast majority of users, they should be able to do what they need to within the free tier." Muse is built on Meta's latest-generation model, "Muse Spark," and the generous free access suggests Meta's priority is getting the underlying model and the agent experience itself adopted widely first.

04
Who Benefits

Who it helps, and how

Don't stop at "one more conversational assistant" — think through where each role actually gains

Business leaders

Muse handling bill negotiation and admin chores is a live test case for which parts of your own customer support or back-office work could be delegated to an agent. Its Stripe-based checkout flow is also a useful reference for designing payment-involving services of your own.

Product managers

The Secure VM / Sentinel split — separating what an agent can do from who authorizes it — is a reference model for adding agentic features to your own product safely. The free / $20 / $100 tiering is also a concrete example of usage-based pricing to study.

Marketers

It means there's one more conversational channel alongside ChatGPT and Claude. Since Muse can shop, book, and even draft invitations on a person's behalf, the point of contact with consumers is expanding beyond search and social — you now have to design for comparison happening through an agent, too.


05
Risk & Limits

This isn't a story of pure optimism

Meta itself seems aware this is a bet made against the wind. CNBC's coverage frames the launch as arriving while the company is in the middle of a broader public reckoning over privacy and safety. The more authority an agent is handed, the wider the blast radius of a wrong action, a misread intent, or a flaw in a connected third-party service.

Resistance to letting AI handle purchases is real and well documented: in a survey of U.S., U.K. and Canadian consumers by Forrester, 75% of online shoppers said they feel uneasy about letting an AI agent complete a purchase and payment on its own. Given that Muse is explicitly designed to handle payments through Stripe, that discomfort isn't a footnote — it's a core constraint. Safeguards like Secure VM and Sentinel reduce the odds of things going wrong; they don't, by themselves, manufacture trust.

06
What's Next

One more conversational window has opened

The real shape of this news is simple: it's one more conversational assistant alongside ChatGPT and Claude. If you're already comparing daily-use AI options, there's now another one on the table. For now, though, it's limited to the U.S., ages 18 and up, and iOS/Android/web — Meta hasn't said when it will reach other regions or younger users.

Three concrete next steps for now: (1) start with low-risk tasks on the free tier — drafting emails, organizing information — and keep a human in the loop for anything involving payment or contracts; (2) watch the Secure VM / Sentinel "separate what an agent can do from who authorizes it" pattern as a reference point for your own agent design; (3) keep tracking regional rollout news and follow-up research like Forrester's to gauge how quickly trust actually builds. Muse is, for now, an experiment worth trying — whether it becomes a reason to switch depends on what the next few months show.