Connect with us

NEWS

Meta Opens Muse, a Personal Agent on a Cloud PC

Meta’s Muse personal AI agent runs on a cloud VM with Sentinel, paid $20 and $100 plans, and sites that already ban bots.

Published

on

Meta opened Muse on September 8, a personal AI agent that lives on its own cloud computer and acts across the web. It is out in the United States on iOS, Android, and the web, with a free tier and paid plans at $20 and $100 a month.

Muse shows up as a chat thread, and under that thread sits a virtual machine Meta hosts, plus a second agent that decides whether anything may reach the internet. Users can name the agent, give it an avatar, and set how it talks. Glasses support is promised later.

The Cloud Computer Behind Muse

The product Meta is selling is not another answer box. Each person gets a dedicated Muse Secure VM, a contained cloud computer with its own browser that the user can watch. Credentials for connected services sit on that machine. Other people’s agents are not supposed to reach it.

Talking to it is meant to feel like texting a person, in the Muse app or in WhatsApp. Tell it a job and it is supposed to open pages, fill forms, and keep going after the app is closed, pinging the user when a plan changes or when a purchase or an email needs a yes. Meta’s own examples include booking travel, sending mail, haggling a bill, and turning a saved Instagram recipe reel into a grocery list.

The model underneath is the Muse Spark 1.3 agent model, which Meta Superintelligence Labs listed on September 2 for long, messy jobs that juggle tools and need a check-in before a consequential step. Chief AI officer Alexandr Wang, who joined from Scale AI to run that lab, called Muse an early step toward personal superintelligence, an agent that helps people finish work they would not have started alone.

MUSE AT LAUNCH

  • Where: United States on iOS, Android, and muse.ai, with chat in WhatsApp and AI glasses listed as coming soon.
  • Model: Muse Spark 1.3, built for long agent threads and shipped six days before the consumer app.
  • Computer: Muse Secure VM, a per-person cloud machine with a visible browser.
  • Chat: A thread you can name and dress with an avatar, closer to a contact than a search box.

The official account posted the launch film the same afternoon, and the replies were already mixing the product up with the rock band that has used the name for decades.

Sentinel Holds the Only Door to the Web

A personal agent that can send mail and spend money fails in a boring way if the model is the only lock. Meta put a second process on the same machine, called Sentinel, and says nothing Muse does reaches the internet unless that process allows it. When the action is sensitive, Sentinel is supposed to stop and ask the person.

The design is a reaction to a year of agents that were told to wait and then did the damage anyway. It also sits next to an earlier Muse Spark security incident in the same family, which is why the company is now describing the VM, the gate, and the audit trail as the product, not as a footnote.

CONTROLS ON THE MUSE MACHINE

  • The VM: Each person gets a contained cloud computer that other agents are not supposed to reach.
  • Sentinel: A separate agent on that machine must approve anything headed to the internet.
  • Credentials: Passwords and payment methods go into storage Muse cannot see, including secrets typed in the browser.
  • Approvals: Sending an email or making a purchase waits on the person, with a full audit trail of what ran and what is next.
  • App access: People pick the apps and, for mail, whether Muse may only read or may also send.

Executives said they know the other failure mode too. If every small step needs a tap, people start tapping yes without reading, and the gate becomes theater. Muse is built to demand a yes for the sharp moves and to reuse permission already granted for lower-risk work, scoped to a task, a service, a payment, or a window of time. That is a policy choice, not a proof it will hold when the inbox is huge and the thread is long.

Read Access Versus Write Access

The useful version of Muse is the one that can send, book, and pay. That is also the version that can delete, spam, or drain a card. Meta says people can split read from write and can cut a service off at any time. They can tell Muse to forget a fact it stored. They can opt out of having those interactions used to train Meta’s models, which means the default is that the company may use them. Conversations and VM data are not shared with Meta’s ad systems, Wang said, and there is no advertising inside Muse itself.

The open question is how many people will leave write access on after the first week. An agent that can only draft is a chatbot with extra steps. An agent that can send is a staffer, and staffers get fired for one bad afternoon.

The Year-End Confidential VM

On the machine shipping now, the VM is private to the person in Meta’s telling, and it still runs on Meta’s cloud. Later this year the company says it will add Muse Confidential VM, with the whole machine, data and chats included, encrypted under a key only the user holds, so Meta itself cannot read it. Until that ships, “private” means isolated from other users and from the ad pipe, not sealed from the company that hosts the box.

How Much Does Muse Cost?

Wang split the SKU the way the compute bill splits. He said most people should never leave the free tier, and that the two paid plans exist so heavy users cover the machines they burn.

MUSE PLANS IN THE US

Plan Monthly price What Wang said it is for
Free $0 Most people, for the work they actually need
Paid $20 Heavier use that starts to cost real compute
Paid $100 Power users; the fee helps cover those runs

There are no ads in the product. Wang said Meta is looking at commerce as a second way to get paid, which is a quieter shift than the VM. If Muse books the hotel and buys the pan, the company can take a cut without putting a banner over the chat. The free tier is the distribution play. The $100 plan is the admission that a long-running browser in the cloud is not a cheap chatbot query.

Paying With a One-Time Card

When Muse checks out, it can use Link, built by Stripe. Meta says it is the first AI agent under Link’s purchase protections, which on eligible buys cover damaged or lost items, price drops, no-fee returns, and a guarantee. Link’s wallet for agents mints a one-time card so the real number never sits in the page. Shop Pay is listed as next, and so is 1Password, so the agent can use a login the person already stored without seeing the password.

That stack is how Meta wants Muse to look like a person at the register and like a locked box at home. A throwaway card cuts the blast radius if a site is dirty or a prompt goes sideways. It does not decide whether the restaurant, the airline, or the bank will treat the session as a human in a browser or as a bot to kill.

Resy’s Ban Is the Other Gate

Sentinel is Meta’s door. Plenty of services have already built the opposite door. Resy, the booking app, publishes a zero-tolerance policy for bot use: flagged accounts are shut, future reservations are canceled, and there is no path back. American Express accounts tied to that behavior can go too. The page is written for scalper bots, and it does not make an exception for a polite agent with a user’s name on it.

Any agent that hunts for a four-top on a Saturday will trip the same sensors, whether it lives on a Mac mini or in a Meta VM. Muse can ask before it books. The restaurant software still sees an automated client refreshing inventory. Other tools that sit on inboxes and calendars have already shown how thin a typed “wait” really is.

In February, Summer Yue, director of alignment at Meta Superintelligence Labs, connected an OpenClaw agent to her mail, told it to suggest deletes and not to act, and then watched the safety line fall out when the real inbox was too large and the context got compacted. She said she could not stop it from her phone.

Nothing humbles you like telling your OpenClaw “confirm before acting” and watching it speedrun deleting your inbox. I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb.

Summer Yue, Director of Alignment, Meta Superintelligence Labs, on X, February 23, 2026

She later put the loss at over 200 messages. The agent, when asked, said it remembered the rule and had broken it. Sentinel is Meta’s answer to that class of failure: take the stop switch out of the chat and put it in a separate process. The Yue incident still stands as the reason write access to mail is the feature people want and the one they should be slow to grant.

What Zuckerberg Promised in August

On August 10, 29 days before Muse opened, Zuckerberg published a 6,500-word essay, The Future Is for Everyone, restating the bet he first sketched on July 30, 2025. Meta, he wrote, would put an agent that works around the clock on health, money, home, and relationships, with privacy “similar to how encryption works on WhatsApp,” and would keep a basic version free so the tools were not only for labs and governments.

Everyone will have an exceptionally capable personal agent that understands you, your goals, and everything you care about. Your agent will work 24/7 on your behalf to improve your relationships, health, career, finances, home management, hobbies, and more.

Mark Zuckerberg, The Future Is for Everyone, August 10, 2026

Muse is that essay turned into an app, with the encryption comparison still sitting in the later-this-year column. The free tier matches the “billions of people” line. The $20 and $100 plans are a simpler price list than the “dynamic auction” for compute the essay described. WhatsApp as a chat surface is the one piece that is already live, and it is the reason Muse can show up where Meta already has a thread, not only in a new app store icon.

THE MUSE LADDER

  1. July 30, 2025: Zuckerberg posts Personal Superintelligence for Everyone, the first public letter on the goal.
  2. April 8, 2026: Meta Superintelligence Labs releases Muse Spark, the first model in the family.
  3. August 10, 2026: He publishes The Future Is for Everyone, promising a 24/7 personal agent with WhatsApp-like privacy.
  4. September 2, 2026: Muse Spark 1.3 ships; Meta engineers said it used about 20% fewer tool calls and 25% fewer tokens than 1.2.
  5. September 8, 2026: Muse the agent opens in the US on phones and the web.

Five months after Spark, the lab has a consumer surface that can spend money. The manifesto’s sealed mode is still a date on a slide.

ChatGPT Work, Already on the Desktop

Meta is late to agents that click, and it is early to putting one on a per-user cloud PC with a named gate and a throwaway card. On July 9, OpenAI began rolling out ChatGPT Work on desktop and on the web, an agent that can sit on a job for hours, use connected apps, and, on a Mac or Windows machine, run Computer Use against local files and the browser. Chat, Work, and Codex are on every desktop plan, including Free. Web and mobile Work started with Pro, Enterprise, and Edu, then moved to Plus and Business.

OpenAI said more than 5 million people use Codex every week, and that more than 1 million of them now use it for work that is not software. That is the installed habit Muse has to beat, without a desktop binary and without leaving the United States on day one. Muse’s counter is the social graph already in Instagram and WhatsApp, a VM that keeps running when the phone is in a pocket, and a price of zero until the compute gets expensive.

The constraint is still not which lab has the prettier chat. It is whether a person will let a Meta-hosted browser send as them, and whether Resy, a bank, or an airline will let that session finish. Sentinel can block a bad click. It cannot force the other end of the socket to play along. The Confidential VM, when it ships, can hide the disk from Meta. It cannot hide the booking from the site that already said bots get deleted.

Harry is the editor and lead writer of WEBWIZARD 360, which he owns and runs independently for readers around the world. Ten years in journalism, the early ones reporting and the later ones editing, shaped a simple rule about technology coverage: a vendor's claim stays a claim until it has been tested or documented. Benchmarks are run on the device itself, changelogs and filings are read in full, and a launch announcement is checked against what actually ships. He carries the same caution into the other nine sections, so business stories start with the accounts, science stories with the paper, and sports, entertainment, lifestyle, travel, auto, gaming and general news with whatever official record exists. Numbers are verified before publication, without exception. If an article turns out to be wrong, it is corrected on the page with a note that says what changed, in line with the corrections policy the site publishes. Reader mail reaches him at support@webwizard360.com, and he replies to it himself.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending