Most of the software people use every day still asks for them to do two jobs at the same time. One is to figure out what needs to happen. The other is to make it happen by clicking through the apps, forms, inboxes, and checkout pages it takes to make it happen.
Chatbots closed that gap by making the first step a little easier.
They left the second sitting on the user's desk.
That split is what much of the current AI race is curiously focusing on.
Meta, the company known as the social media giant, has been taking the AI race to a different level. And now it has put a consumer product onto it.
On 8 September, it announced "Muse", a personal agent that can be messaged through a dedicated app, through the web at muse.ai, or through WhatsApp.
The selling point is not a better answer. It is a system that keeps on working after the conversation ends, across email, calendars, shopping, travel, and other connected services.
The firm put it in the same language: an agent that "gets things done across every part of life".
The launch video and the site explain the same idea more softly, as something people talk to the same way they would message a person. The user can give the agent a name, an avatar, and choose how chatty it is.
The user interface is based around one long-running chat rather than a string of isolated prompts, with side chats for tasks that need their own context. There's a Goals tab for longer projects, and a tab for Ideas, prompted from what the system has already heard.
Under the hood the work doesn't run on the phone.
Each user gets a dedicated cloud virtual machine that Meta calls a "Muse Secure VM". That VM contains the agent, a browser you can watch, files, and credentials for connected services.
A separate process on that same machine, called "Sentinel", is the only thing allowed out to the internet or third-party apps.
Muse can suggest an action. Sentinel either matches that to a permission the user already granted, or stops and asks. Jobs such as sending mail or making a purchase are supposed to get an approval card which is not at least filtered through the model, which is Meta's solution to prompt-injection attacks that hide a prompt inside a webpage or email.
The model powering the agent is Muse Spark, which Meta says is built for tool use, long context, and work that extends across many steps.
Official examples include booking travel, completing forms, negotiating a bill, turning a saved Instagram recipe into a shopping list, remembering dietary restrictions before sending out dinner invitations, and continuing a task after closing the app. Payments can go through Link, developed by Stripe, which issues a one-use card number so the agent does not see the real number, and Meta says eligible purchases are covered by Link's protections against damage, price drops, and returns. Support for Shop Pay and 1Password are listed as coming soon.
Control is the other side of the design.
Users decide which services to connect and what amount of access each is given, and they can revoke that access. Memory files are intended to be readable and editable. Conversations are not shared with Meta's ad targeting systems, according to the firm, and users can choose not to have their conversations used for training models.
Later this year Meta says it will give a Confidential VM, encrypted with a key held by the user, so even Meta could not read what happens in it.
The version published today is not that. Wired notes that Secure VM is isolated from other users but still runs on Meta's infrastructure, which means it is not a sealed box.
Availability is more limited than the language about "everyone" might imply.
At launch Muse is available in the US to adults on iOS, Android, the web at muse.ai, and WhatsApp, with Meta's AI glasses listed as a future platform. There is a free tier and two paid tiers which reportedly cost $20 and $100 a month for more intensive usage. Alexandr Wang has said most people should be able to stay on the free tier, with the paid ones primarily covering compute for power users.
Some reports say a billing card is required even to start on the free plan.
There is no advertising in the product at launch, though the firm has said it is exploring commerce as a longer-term opportunity.
The open question is not whether an agent can click a web page.
It is whether people will hand over their inbox, calendar, and a pathway to their money. This is because the app demands more personal access than Meta's previous consumer projects, and that the launch came just weeks after a major settlement over social media harms.
Privacy-concerned people who are already think that Meta is gathering more information than pretty much any single entity on the internet, should probably worry how the he product can struggle in some cases exposing sensitive data it should not have.
Meta's own safety checklist is unusually blunt on that point.
It says the agent will still make mistakes, and may sometimes be attacked through the data it reads, which is why the harness is isolated, credentials are kept hidden from the model, and Sentinel cannot be overruled by Muse itself.
That is a smaller claim than the launch video. It also matches how this category of product works in 2026. The useful part of Muse is not a new chat window.
It is the attempt to place a long-running worker, a visible browser, and a permission layer all together in the same place, and then ask ordinary users to supervise it the way they might supervise a person with the keys but not the final say.






















































































































































































































































































































































































