Meta Muse AI Agent in 2026: Pricing, Mac App, Security, and How It Works

By

· Published

· Updated

·

,
Meta Muse AI agent in 2026 with desktop computer use, connected apps, permissions, and secure agent workflows

Meta Muse is no longer just another chatbot. Meta launched Muse on September 8, 2026 as a personal AI agent that can work toward goals, use connected services, browse the web, fill forms, make purchases and keep working after you close the app. On September 17, Meta expanded Muse to the Mac, where it can work across local files, Messages, Calendar, Notes and Mail with user-approved access.

That makes Muse one of the clearest examples yet of the shift from AI assistants that answer questions to agents that can actually take actions across a person’s digital life. The most important questions are therefore not only what Muse can do, but what it costs, how much access it gets, where it is available and how Meta is trying to contain the risks of giving an AI agent that level of reach.

Source check: September 24, 2026.

What changed with Meta Muse?

Meta describes Muse as a personal AI agent powered by its Muse Spark model. Instead of requiring a user to direct every step, Muse can take a goal, break it into tasks and keep working until it needs more information or approval.

At launch, Meta said Muse could:

  • browse the web and work across multiple steps;
  • read from connected apps according to the permissions a user grants;
  • send email, fill out forms, book travel and negotiate on a user’s behalf;
  • keep working after the app is closed;
  • remember relevant preferences and details;
  • ask for approval before sensitive actions such as sending email or making a purchase;
  • show an audit trail of what it has done and what it plans to do.

Meta’s September 17 Mac release is a meaningful expansion because Muse can now act inside native desktop contexts instead of relying only on its cloud environment, browser and mobile surfaces. TechCrunch reports that the Mac app can interact with files, Messages, Calendar, Notes and Mail, with access granted on an opt-in basis.

If you want the broader technical context for this category, see our AI Agents in 2026 guide and our guide to AI computer use.

Meta Muse pricing in 2026

Meta’s official Muse product page says the service has a free tier with a usage limit. If the free allowance is exhausted, users can either wait for the limit to refresh or upgrade to a paid subscription.

For Meta’s separate cross-app subscription bundles—including Core, Premium, and creator/business tiers—see our Meta One pricing guide.

Meta’s public launch announcement confirms that paid subscriptions are available but does not publish the dollar amounts. Launch coverage from TechCrunch and Reuters reports two paid plans:

Plan Price What is publicly confirmed
Free $0 Usage-limited access. Meta does not publish the free cap on its public product page.
Power $20/month Higher Muse usage than the free tier, according to launch reporting.
Maximum $100/month Highest launch-tier usage level, according to launch reporting.

One important caveat: Meta uses its own usage accounting for Muse, and its public product page does not currently explain a simple tasks-per-month equivalent. That means the headline monthly price alone does not tell you how many long-running browser or desktop jobs a subscription will support in practice.

TechCrunch also reported that Muse shows a usage meter and requires a payment card to get started. Because Meta can change limits and regional entitlements independently of the monthly plan price, we recommend checking the in-product subscription screen before relying on a specific allowance.

Where is Muse available?

Meta launched Muse in the United States on iOS, Android and the web at muse.ai, with access through WhatsApp as well. At Meta Connect on September 23, Meta moved that roadmap forward by announcing that Muse is coming to its AI glasses, including the new Ray-Ban Meta Audio lineup. Meta describes this as hands-free access to the same personal agent, but the announcement should not be read as proof that every glasses owner already has the full Muse experience today.

The Mac app is now an additional surface. As of September 19, 2026, the launch remains U.S.-focused rather than a full global rollout. Meta has not published a firm worldwide availability date.

How the Mac app changes the product

The original Muse launch already gave the agent a browser and connected-service access inside Meta’s cloud environment. The Mac app changes the practical scope because the agent can work with information and apps on the user’s computer.

That creates a different class of workflow. A cloud browser agent may be able to research a trip and fill an online form; a desktop agent can potentially combine that web task with local files, calendar context, notes and messages. The upside is less manual context-switching. The downside is a larger permission surface.

That tradeoff is why local-agent permissions matter. A useful mental model is to treat every connected app or folder as a capability grant rather than as a convenience toggle. Give the agent only the access required for the current job, and remove access that is no longer needed.

How Muse handles security and permissions

Meta’s security architecture is one of the most important parts of Muse because a useful personal agent needs access to sensitive services and data.

Muse Secure VM

Each Muse runs inside what Meta calls a Muse Secure VM: a dedicated cloud virtual machine that contains the agent and the data associated with connected services. Meta says one user’s agent cannot reach another user’s environment.

Sentinel approval layer

A separate Sentinel agent is isolated from Muse at the system level. Meta says outbound internet actions must pass through this protective layer, which can block actions or ask the user for approval.

Credentials are separated from the model

Meta says Muse does not directly see passwords or payment methods. Credentials are stored separately so the agent can use them without reading the underlying secret.

Sensitive actions require confirmation

Meta says Muse checks with the user before actions such as sending an email or making a purchase. Users can also inspect an audit trail and change or revoke service permissions.

Training and advertising controls

Meta says users can opt out of having their Muse interactions used to train Meta AI models. The company also says Muse conversations and data inside the VM are not shared with Meta’s advertising systems.

Later in 2026, Meta says it plans to introduce a Muse Confidential VM in which the entire virtual machine is encrypted with a key held by the user, so even Meta cannot access the contents. That is a future capability, not the current baseline, so it should not be treated as already available.

For a broader checklist on permission design, prompt injection, runtime isolation and approval boundaries, see AI Agent Security in 2026.

Purchases and payments

Muse can use Link by Stripe for purchases. Meta says Link’s wallet for agents generates a one-time-use card so the user’s actual card number is not exposed to the agent or merchant flow. Meta originally announced Shop Pay and 1Password support as planned. On September 21, 2026, Meta and Shopify confirmed an agentic-commerce partnership intended to bring Shop Pay checkout into Muse across Shopify-powered stores; 1Password support remains planned.

This is a notable design choice because payments are one of the highest-risk actions an autonomous agent can take. Muse’s current model combines stored credentials, approval gates and transaction protections rather than giving the model unrestricted access to payment information.

Amazon blocks Muse from shopping on Amazon.com

On September 20, 2026, Amazon blocked Muse from shopping on Amazon.com on behalf of users. Amazon told GeekWire that it had not authorized Meta’s agent to access the store, said Muse did not identify itself while browsing, and raised concerns about account-data and credential handling. Users attempting the workflow were shown a notice that continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.

Meta disputes the implication that Muse can see users’ passwords or payment credentials. Meta’s published architecture says credentials are stored separately from the model, and its launch materials say purchases require user approval. The immediate practical takeaway is narrower: Muse’s advertised shopping capability does not currently work across every major retailer, and Amazon is now a confirmed platform-level exception.

This matters beyond one retailer because general-purpose browser agents depend not only on model capability but also on whether destination websites permit automated access. Users should therefore treat cross-site shopping support as dynamic availability rather than assume that a browser-capable agent can transact everywhere. The block does not mean Muse’s broader shopping or payment features have been disabled across the web.

Shopify confirms Shop Pay agentic checkout for Muse

On September 21, 2026, Meta and Shopify confirmed a partnership to make shopping and checkout easier inside Muse using Shop Pay. Shopify CEO Tobi Lütke said the integration is intended to enable agentic checkout across Shopify stores, while Meta CEO Mark Zuckerberg framed it as part of a broader push to make Muse a practical shopping interface.

The important change is that Shop Pay is no longer just a launch-roadmap item. It now has a named commerce partner behind it. The contrast with Amazon is also instructive: Amazon currently blocks Muse from shopping on its marketplace, while Shopify is actively integrating the agent. For users, that means retailer support will depend on platform policy as much as model capability. For merchants, agent-ready product data and checkout may become a separate discovery and conversion channel.

PayPal and Instacart expand Muse commerce reach

On September 22, 2026, PayPal announced a partnership with Meta to let PayPal customers shop and check out with Muse across PayPal merchants worldwide. That does not mean Muse itself has launched worldwide: Muse remains U.S.-focused today, while PayPal’s announcement describes the merchant network the integration is intended to reach. PayPal’s official announcement is available on its X account.

Instacart separately announced that Muse will become another connector into its grocery-shopping infrastructure. Instacart says users will be able to turn natural-language grocery requests into carts grounded in store inventory and its catalog, but the company describes Muse support as coming soon rather than already live. The first-party announcement is available from Instacart.

Together with Shop Pay and Link by Stripe, these deals show that Muse’s shopping usefulness increasingly depends on direct platform and payment partnerships rather than unrestricted browser automation. The contrast with Amazon’s block is important: some platforms are building explicit connectors and checkout rails for agents, while others are refusing access. For users, supported merchants and services should therefore be treated as a changing compatibility layer, not a universal capability of the model itself.

September 23 Meta Connect update: AI glasses, Muse Charm, and Meta VR Glasses

Meta also announced a separate Meta VR Glasses product for Spring 2027 at $1,299.99. Unlike the Ray-Ban/Meta AI-glasses rollout, Meta’s VR announcement says a Meta AI agent is integrated directly into the device operating system and can respond to voice, eye and hand input to open apps, adjust the workspace, play media and search. Meta has not said that this OS-level agent is identical to Muse, so AI-XBlog treats it as a related Meta agent surface rather than folding it into Muse availability.

Meta Connect 2026 expanded Muse from a phone, web and Mac agent into a broader hardware strategy. Meta announced that Muse is coming to its AI glasses so users can talk to the same personal agent hands-free while it helps with goals, routines and other tasks. The company also introduced Ray-Ban Meta Audio, an audio-only AI-glasses line that starts at $349 in the United States, is available for preorder now and is scheduled to ship October 13.

Meta also unveiled Muse Charm, a pocket-size device built specifically for talking to Muse through a real-time voice model. Meta’s Connect recap says more details are coming later in 2026; Reuters reported that Meta expects the device to be ready for the holiday season in December, but the company did not announce a price. That makes the product strategically important but still too early to evaluate on value.

The practical change is that Muse is no longer only a software agent. Meta also used Connect 2026 to expand the agent itself, not just the hardware around it. The company says Muse Realtime Voice can keep working in the background while a user is still talking, and a new Muse Realtime Avatar model can turn that voice experience into an expressive interactive avatar. Meta also announced that Muse will get its own email address, while the Mac version can now, with permission, drive any app on the Mac and continue queued work after the user walks away.

Meta also broadened Muse’s connector layer. Its official Connect recap lists the full Shopify catalog plus Walmart, Best Buy, American Eagle Outfitters, DICK’S Sporting Goods, Fanatics, Gap, Michael Kors, Sephora, Ulta and Wayfair for shopping; Shop Pay and PayPal for payments; Expedia as coming soon; Instacart for grocery workflows; and Notion, Granola, GitHub and Box for work. On AI glasses, Meta says Muse is coming in the coming months, can be activated by saying the agent’s name, and can act on what the wearer is looking at. These are announced capabilities with different rollout states, so AI-XBlog does not treat every connector, glasses feature or email workflow as universally live today.

Meta is trying to make one persistent personal agent available across phone, web, Mac, WhatsApp, glasses and dedicated hardware. For users, that increases continuity but also makes permission design more important: a persistent agent that follows a person across devices can become more useful, but mistakes or over-broad access can also travel across more contexts.

Muse vs a chatbot: what is actually different?

Capability Typical chatbot Meta Muse
Answer questions Yes Yes
Browse and complete multi-step tasks Sometimes Core product behavior
Keep working after the app closes Usually no Yes
Use connected apps Varies Yes, with user-granted permissions
Take sensitive actions Limited Yes, with approval gates
Work across native Mac context Usually limited Now supports files and selected native apps
Persistent memory Varies Yes, with user controls to forget information

Practical implications

Muse matters less because it adds another AI chat interface and more because Meta is trying to make agentic behavior a mainstream consumer product. Three changes are especially important.

First, computer access is becoming a product feature rather than a developer experiment. The Mac app moves agent permissions, local files and native-app actions into a consumer workflow.

Second, security architecture is becoming part of the product comparison. For agents with email, financial or account access, the relevant questions are no longer only model quality and price. Isolation, credential handling, approval gates, auditability and revocation matter just as much.

Third, agent pricing is moving away from simple message limits. Long-running tasks can consume substantially more compute than a short chat response, so plan value depends on what kinds of jobs users delegate and how Meta measures usage.

Who should consider Muse?

Muse is most relevant to users who want an agent to handle multi-step personal tasks instead of simply generating text. That includes research, scheduling, travel planning, forms, shopping and coordination across multiple services.

Users who only need occasional writing, brainstorming or Q&A may not gain much from granting broad app permissions to a persistent agent. The most sensible approach is to start with low-risk, reversible tasks and expand access only when the time savings justify the additional permission surface.

Known launch caveats and reported reliability issues

Muse’s security architecture does not mean the product is failure-proof. Reuters reported that internal Meta testing surfaced mixed results before launch. According to internal posts reviewed by Reuters, one test exposed personal iCloud photos after the agent was prompted to identify toys in birthday pictures; employees also reported repeated login problems, monitoring jobs that stopped refreshing, silent errors and other reliability failures. Meta did not comment to Reuters on the specific incidents. Meta AI product vice president Vishal Shah told Reuters that the company had delayed Muse’s release from April to do additional security work and acknowledged that mistakes can still happen.

Those reports are not evidence that every Muse session is unsafe, but they are relevant to how the product should be used today. Keep permissions narrow, retain approval gates for external side effects, and avoid delegating high-stakes tasks where a silent failure could create financial, privacy or account-security harm.

September 2026 Messages privacy incident: what actually happened

On September 19, 2026, technology columnist Jason Aten reported that Muse referenced the contents of a private Messages conversation after he believed he had not granted Muse access to Messages. When he asked Muse how it knew about the conversation, the agent said it was only seeing notification previews from his Mac. Aten then reported finding evidence that Muse had synchronized data from the local Messages database instead.

Meta disputed the idea that Muse can silently bypass its permission model. David Singleton of Meta Superintelligence Labs said Muse only synchronizes Messages after the relevant Mac access is enabled, and that Muse’s explanation about notification previews was incorrect. Meta apologized for the inaccurate explanation and said it is working to make Muse describe its own data access more accurately and consistently. Meta’s published product documentation continues to say that users choose which apps Muse connects to, can change or revoke access, and that Full Disk Access on Mac is optional.

The practical issue is therefore broader than a single permission toggle. There is currently a gap between what the agent can access, what a user believes they authorized, and how reliably the agent can explain its own access path. For a personal agent that can work across messages, mail, files and calendars, that transparency gap is itself a security and trust concern even if the underlying OS permission was technically granted.

For now, Mac users should review Muse’s app-level permissions and macOS Privacy & Security settings, avoid granting broader disk or app access than a task requires, and verify permissions in system settings rather than relying on Muse’s natural-language explanation of what it can see. This incident does not establish that Muse is broadly reading Messages without permission; it does show why capability grants, audit trails and accurate permission reporting matter for desktop AI agents.

September 2026 Muse Mac zero-day and hotfix: what users need to know

On September 21, 2026, macOS security researcher Patrick Wardle published a proof of concept called not-a-mused for a local zero-day in the Muse Mac app. Wardle found that an undocumented setting, endo_voyager_dictation_endpoint, can be changed by an unprivileged local process so Muse sends dictated prompts to an attacker-controlled endpoint instead of the expected service.

According to Wardle’s proof of concept, that redirect can expose dictated audio or prompts, enable prompt injection, expose Muse authentication material and let an attacker abuse access the user has already granted to Muse. The important limitation is that this is not a remote zero-click compromise of a clean Mac: an attacker or malicious process must already be able to run code as the local user. The added risk is access amplification. A process that starts with relatively limited local access may be able to turn Muse’s broader permissions across files, apps and connected services into a much larger attack surface.

Meta issued a hotfix on September 22, 2026, within hours of the public disclosure. Meta Superintelligence Labs’ David Singleton described the bug as a local privilege-escalation issue rather than a remote exploit, noting that malicious code already had to be running under the user’s account to abuse it. The hotfix addresses this specific dictation-endpoint flaw, but risk-sensitive Mac users should still keep Muse permissions as narrow as practical and treat agent permissions as a meaningful security boundary. This disclosure also reinforces a broader lesson for desktop AI agents: cloud isolation can be strong while the local client remains a separate point of attack.

Meta tested human contractors for some Muse phone calls — then rolled the test back

On September 22, 2026, Reuters reported that Meta had been internally testing a “human concierge” system for Muse in which contract workers handled some phone calls that the AI agent was asked to place. The test followed the rollout of Muse’s phone-calling capability and was intended to improve completion rates for calls where businesses did not successfully interact with an AI caller.

The key privacy point is that this was an internal employee test, not a disclosed public consumer feature. According to Reuters, Meta employees raised concerns that people could unintentionally expose sensitive information to contractors. A Meta Superintelligence Labs vice president acknowledged that starting the test without proper disclosure was “a miss” and said the company had rolled the feature back for now. Meta said any future testing would need stronger disclosure, privacy and safety safeguards.

Practical implication: Muse users should distinguish between the public AI calling feature and this rolled-back internal human-assistance experiment. The report does not establish that ordinary public Muse calls are currently being routed to human contractors. It does, however, highlight why agent products that make calls, bookings or payments need explicit human-in-the-loop disclosure, clear data-handling boundaries and consent controls whenever a person can enter the workflow.

What to watch next

The next milestones are more important than benchmark scores: international availability, final Mac permission behavior across more apps, the launch of Muse Confidential VM, support for AI glasses, 1Password integration, the actual rollout and merchant coverage of Shop Pay agentic checkout, and clearer public documentation of usage limits.

We will keep this page updated as Meta changes Muse pricing, availability, supported platforms and security controls.

Sources

AI-XBlog Weekly Brief

Keep up with AI that actually works

Join the AI-XBlog Weekly Brief for major AI updates, practical workflows, useful tools, and editor’s picks. No daily noise.

Double opt-in. Unsubscribe anytime. See our Privacy Policy.

Reader discussion

Join the discussion

Have you tried this tool or workflow? Share your experience, corrections, or questions. Useful reader feedback may help us improve this article.

All comments are reviewed before publication. Your email address will not be published. Promotional links and low-value spam are removed.

Add a comment

Comments are moderated to keep the discussion useful and trustworthy.

About the author

AI-XBlog Editorial Team researches and maintains practical coverage of AI tools, automation, agents and applied artificial intelligence. We prioritize primary sources, clear evidence and useful real-world guidance.

Editorial Policy · Review Methodology · Corrections Policy