Meta announced Muse on Tuesday, a personal AI agent that carries out everyday tasks from natural-language instructions, according to the company, Wired and SiliconANGLE.

The agent is live in the US through a dedicated app for iOS and Android, the muse.ai website, and directly inside WhatsApp. Meta says access through its AI glasses is coming soon.

What Muse can do

According to Meta, users just tell Muse what needs to get done and it takes action: it can send emails, book travel, fill out forms, open a browser and negotiate on a person's behalf — for instance, to sell a car or lower a bill. For longer jobs, the agent keeps working after the app is closed and comes back when it needs approval, such as before sending an email or making a purchase.

Purchases run through payment infrastructure built with Stripe, called Link, which issues a single-use card number for each transaction so Muse never exposes a user's real financial details. Meta says Muse is the first AI agent covered by Link's purchase protections, which include free returns and coverage for damaged or lost items and price drops.

An isolated virtual machine for every user

Muse runs on an architecture called Secure VM, which isolates each user's data and activity inside its own virtual machine, according to Meta, Wired and SiliconANGLE. The company built a layer called Sentinel to monitor everything that leaves that virtual machine: if an action matches a policy already authorized, it proceeds on its own; if not, the system asks the user directly for approval, without routing through the AI model itself — a safeguard against prompt-injection attacks, Meta Superintelligence Labs engineering vice president David Singleton told Wired.

Meta says Muse also remembers details a user mentioned only once, so it can make suggestions without being asked again — for instance, turning a recipe reel saved on Instagram into a grocery list, or recalling a friend's dietary restrictions before sending a dinner invite.

Meta plans to release a version called Muse Confidential VM later this year, in which the entire virtual machine — including data and conversations — is encrypted with a key only the user holds, so that even the company could not access the content, according to Meta, Wired and SiliconANGLE. Wired reports that Meta intends to give security firms access to the Confidential VM source code for independent audits and to publish a transparency log so users can verify the integrity of their own connection to Muse.

Wired reports that Muse's security architecture was already vetted by Meta's human and automated red teams and a private bug bounty program before launch, and that the company expanded its public bug bounty program to cover the agent.

Competition and context

Muse comes out of Meta Superintelligence Labs, the AI unit chief executive Mark Zuckerberg set up roughly a year ago to help the company catch up with OpenAI and Anthropic, according to Wired and SiliconANGLE. The launch positions Muse against other message-based AI agents built to automate digital tasks, such as OpenClaw, which both Wired and SiliconANGLE cite as comparable products.

Meta says Muse is free for most of what people need, with subscription plans for those who want to automate a larger volume of tasks.

The release adds Meta to a field already crowded with frontier labs racing to put an AI agent directly inside a messaging app people already use, rather than asking them to learn a new interface — the bet Meta is making to get Muse adopted quickly.

Meta says Muse is designed around the way people already communicate, so talking to it works just like messaging another person, whether inside the dedicated app or through WhatsApp — no separate command syntax or settings menu to learn before the agent starts taking action.