Meta’s New AI Agent Can Spend Your Money and Read Your Email, but Only if You Trust It to Not Tell the Ad Team
Meta's Muse agent can manage finances and emails but demands extensive permissions and subscription fees

Meta has released its first artificial intelligence agent for all users. The tool, called Muse, is defined as a personal agent that can connect to applications and execute tasks on a user’s behalf. Users must grant permissions that no other Meta tool has previously requested.
Unlike Meta AI, which is limited to conversation within WhatsApp or Messenger, the agent can send emails, book travel, fill out forms, and manage bills. In the United States, users can ask it to complete purchases through a secure Stripe platform, and integrations with Shopify and 1Password are in process to expand payment options.
Muse requires explicit permission to connect to each individual app or service a user wants it to manage. The linking process is done one by one, so activation of email, calendar, health platforms, or smart home systems must occur separately. Users can choose what information they share and how frequently, and if a service lacks a native connection, Muse can configure access through a public API or its integrated web browser.

The agent is based on Muse Spark, the company’s most recent model. Meta stated the AI operates within a secure virtual machine called Muse Secure VM, which isolates user data from the rest of the company’s systems, including advertising infrastructure. The system uses an additional agent called Sentinel that runs in parallel inside the same machine, though separated at the system level, to manage passwords and payment methods securely.
The agent is not completely free. Muse uses a freemium model where most users can access it but will need to pay for more complex tasks. The company calculated most users will remain on the free plan, though it is offering Power and Maximum options at $20 and $100 per month, respectively.



Users can access a usage meter showing the percentage of their free quota remaining. When the quota is nearly exhausted, Muse will offer the option to purchase a paid add-on plan. The agent is not designed solely for answering questions.
One feature allows it to continue working in the background, even after the user closes the application. If it needs approval or discovers something important, it sends a notification for validation. Meta said Muse can learn from conversations to anticipate needs without explicit requests.
The broader competitive shift across Big Tech has moved from conversational chatbots toward action-execution systems capable of computer-use and autonomous API orchestration. Anthropic has Computer Use, Google has Project Jarvis and Astra, and Apple has App Intents. Meta’s shift from Meta AI, a chat-only tool, to Muse, an engine for booking travel, paying bills, filing forms, and executing transactions, places the company in that landscape.
Meta operates under historic FTC consent decrees and strict cross-service data segregation requirements under EU and global privacy scrutiny. The company’s engineering emphasis on architectural firewalls, including the Muse Secure VM and the isolated Sentinel credential manager, directly addresses those restrictions by separating user data from the core ad-targeting infrastructure.
Muse is available on the web, within WhatsApp, and through an app for iOS and Android. Meta confirmed it will also arrive on its smart glasses at a later date. Only the United States can access it currently.
Meta’s hardware ecosystem, including the Ray-Ban Meta smart glasses and upcoming AR platforms, relies on screenless, ambient computing. Those devices fundamentally require autonomous background execution, as users cannot easily interact with physical screens or keyboards. Muse’s background processing capabilities and its planned expansion from mobile and web to Meta smart glasses connect directly to that hardware strategy.









