Verified · Sep 9, 2026
Independently verifiedMeta launches Muse — a personal agent that opens browsers, fills out forms, and checks out with Stripe, wrapped in security claims that haven't been tested yet
4 sourcesMeta introduced Muse, its personal AI agent, on Tuesday, September 8 (official announcement, 2026-09-08T19:00:51+00:00). Per Meta: Muse runs on 'Muse Secure VM, a dedicated, virtual machine (VM) that houses both the agent and a person's data'; talking to it 'works just like messaging another person, in the Muse app or directly in WhatsApp'; it is 'powered by Muse Spark, Meta's most capable model to date'; 'It can open a browser, fill out forms, and negotiate on their behalf'; it 'keeps working after people close the app' and returns for approval 'like before it sends an email or makes a purchase'; checkout runs on Link built by Stripe — 'the first AI agent covered by Link's purchase protections', with a wallet that 'generates a one-time-use card so your real card details stay hidden'; Shop Pay and 1Password support are 'coming soon'; rollout is 'in the US on iOS, Android, and muse.ai, and coming soon to AI glasses'; it is 'free for most of what people need, with subscription plans for people who want to do more.' Per TechCrunch: two paid plans, 'Power at $20/month and Maximum at $100/month', a payment card required to start, and a usage meter — figures that do not appear in the announcement, and The Verge reports Meta 'did not specify the nature and costs of these paid plans' nor free-tier limits. On security, the announcement itself states: 'A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level'; 'Muse has no visibility into people's passwords or payment methods'; 'Muse doesn't share a person's conversations or the data in their VM with Meta's ad systems'; Muse 'shows people a complete audit trail of everything it has done and plans to do' — all Meta's own descriptions, which TechCrunch notes 'will require deeper investigation by security experts'; and Meta separately promises a Confidential VM later this year 'encrypted with a key only they hold, so not even Meta can access it.'
Why now
The product launched yesterday (September 8), US users can try it free right now, and the walkthrough window is open — whoever demos it first takes the search and recommendation traffic. The trust debate is already on record: TechCrunch frames the launch as arriving 'less than two weeks after' Meta's $18 billion multistate settlement, and The Verge disputes the 'world's first' tagline outright. Meta also left a dated promise to hold: the Confidential VM — 'encrypted with a key only they hold' — is promised for 'later this year'. Whoever separates today's VM from that future one first owns the year-end comparison.
Why it is worth publishing
A rare three-for-one: the official announcement is one click away, two major outlets are fully readable, and the product is demoable in minutes. Every capability line on this card traces to Meta's own text; every isolation claim carries its 'Meta says' layer; and the pricing conflict (TechCrunch-exclusive $20/$100 vs no prices in the announcement or The Verge) is a ready-made media-literacy segment. For the audience it is utility content: whether a card is required, what free tier buys, and who can see your passwords.
Evidence basis
All three sources read in full on 2026-09-09: Meta's announcement (article:published_time 2026-09-08T19:00:51+00:00), TechCrunch (posted 12:00 PM PDT September 8, 2026, Sarah Perez), The Verge (article:published_time 2026-09-08T19:00:00+00:00, Robert Hart). The muse.ai campaign page and the security.muse.ai technical post were unreachable to AITopic (connection reset / timeout); the security facts on this card stand on the announcement's own security section, read in full.
“Meta's new agent can lower your bills and fill out your forms — and Meta says it can't even see your passwords.”
Angle
Run it as a two-track piece: the product track follows the official announcement — what it does, where it's live, where the free tier ends. The trust track keeps vendor claims labeled — the security section (Sentinel gate, no password visibility, no ads-system sharing, the audit trail) is all Meta's own announcement text, unverified by any independent source on this card; prices carry 'per TechCrunch'; 'world's first' stays pinned to Meta's marketing headline. Close on the checkable promise: the Confidential VM arriving 'later this year.'
Format
Long-form explainer
Demo idea
Walk it end to end on camera: sign-up (capture the payment-card step, per TechCrunch), connect one low-stakes service, hand it one small task (turn a saved recipe reel into a grocery list), show the usage meter — then close on a 'Meta says / unverified' card for the security claims.
Platform notes
Every security property is Meta's own announcement line — say 'Meta says' and note no independent security review exists yet (TechCrunch: the claims 'will require deeper investigation by security experts'). Every price gets 'per TechCrunch'; the announcement lists none. 'World's first' is Meta's marketing title and The Verge disputes it — don't restate it as fact. Never type real credentials on camera. The Confidential VM is a 'later this year' promise; today's VM is not encrypted with a user-held key — keep the two apart.
Usable claims
- Meta introduced Muse, a personal AI agent, on September 8, 2026. Per Meta's announcement: Muse 'runs on Muse Secure VM, a dedicated, virtual machine (VM) that houses both the agent and a person's data'; talking to it 'works just like messaging another person, in the Muse app or directly in WhatsApp'; it is 'powered by Muse Spark, Meta's most capable model to date'; and it is 'rolling out in the US on iOS, Android, and muse.ai, and coming soon to AI glasses.' Meta says it is 'free for most of what people need, with subscription plans for people who want to do more.'
- Per Meta's announcement, Muse 'keeps working after people close the app, and comes back when something changes or when it needs approval, like before it sends an email or makes a purchase'; 'It can open a browser, fill out forms, and negotiate on their behalf'; and 'Muse can checkout with Link built by Stripe, and it is the first AI agent covered by Link's purchase protections' — Link's wallet for agents 'generates a one-time-use card so your real card details stay hidden.' Shop Pay and 1Password support are 'coming soon,' as both the announcement and The Verge's report state.
- Per Meta's announcement: 'People choose which apps Muse connects to and exactly how much access it gets' — for email, 'whether it reads their mail or can also send on their behalf' — and people 'can change access or disconnect a service whenever they want.' Per TechCrunch: users connect apps 'one at a time', from built-in connectors covering things like email, calendars, payments, health and fitness, the smart home, dining, shopping, music and events; 'If a service the user wants isn't available but offers a public API, Muse can set up a connection using credentials the user provides. When no API is available, Muse can access the service via the browser instead.'
- Per Meta's announcement: 'A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level. Nothing Muse does reaches the internet unless the Sentinel approves it, and it asks the person for permission when needed.' 'Muse has no visibility into people's passwords or payment methods'; 'Muse doesn't share a person's conversations or the data in their VM with Meta's ad systems'; people 'can also opt out of their interactions being used to train Meta's AI models' — The Verge notes it is not known whether the opt-out is on or off by default — and 'can always tell it to "forget" specific things it's learned'; Muse 'shows people a complete audit trail of everything it has done and plans to do.' Meta also promises: 'Later this year, Meta will introduce Muse Confidential VM, where the whole VM, including a person's data and conversations with Muse, is encrypted with a key only they hold, so not even Meta can access it.' TechCrunch notes the claims 'will require deeper investigation by security experts.'
- Per TechCrunch: 'Two paid plans will be available at launch: Power at $20/month and Maximum at $100/month', Muse 'requires a payment card to get started', and the app includes a usage meter that warns users when free usage runs out. These figures do not appear in Meta's announcement — which says only that Muse is 'free for most of what people need, with subscription plans for people who want to do more' — and The Verge reports Meta 'did not specify the nature and costs of these paid plans' nor free-tier limits.
Evidence pipeline
From the news
Breakdown
Meta launched Muse, a personal agent that opens browsers, fills out forms, and checks out with Stripe's Link — on a dedicated VM. This breakdown keeps the evidence in its layers: the announcement's own text (capabilities, rollout, the free-tier framing, and the 'later this year' Confidential VM promise), the announcement's security section — official words, vendor-asserted substance (the Sentinel approval gate, no password visibility, no ads-system sharing, the audit trail — TechCrunch notes they 'will require deeper investigation by security experts') — and TechCrunch-exclusive details (the Power $20/Maximum $100 plans, the payment-card requirement, the usage meter — absent from the announcement and from The Verge).
Sources
Risks
- Say 'Meta says' for every security property, keep the enforcement history as attributed context rather than a verdict, and if you demo, connect one low-stakes service and never enter real credentials on camera.
- Attribute every price to TechCrunch ('per TechCrunch'), tell viewers the announcement itself lists no prices, and check the live pricing page before you publish.
- Quote the line as Meta's announcement title, and if you contrast Muse with rivals, name them the way The Verge does (ChatGPT Work, Claude Cowork, Copilot Tasks, Gemini Spark).
Demo ideas
- 'Meta says / unverified' split card: official lines on the left (Secure VM, one-time-use card number, Link purchase protections), vendor-asserted lines no independent source has verified on the right (no password visibility, Sentinel approval gate, no ads-system sharing, the audit trail)
- Promise-tracking card: Meta's Confidential VM line — 'encrypted with a key only they hold, so not even Meta can access it' — stamped 'promised later this year', with an empty checkbox column for when it actually lands