AI news, with the context that matters.

Products & Services · ·

Meta launches Muse, a personal AI agent

Muse carries out research and operates services in a personal cloud environment, requesting approval when needed. We examine its rollout, the work it can handle, and how it manages data.

Will AI that keeps working on your errands after you close the app become part of everyday life? Meta's Muse uses conversation as an entry point for research and ongoing tasks. Alongside its rollout, the key questions are what to delegate and where human checks belong.

Key points

  1. Muse runs in a personal cloud environment and continues requested work after the app is closed.
  2. Every purchase requires approval. Users choose which services to connect and which permissions to grant.
  3. Following its U.S. launch, Muse expanded to Canada. The announcements reviewed do not specify availability in Japan.
Meta's official announcement image for its personal AI agent Muse
Source: Meta

What happened

  • Meta launched Muse on September 8 in the U.S., September 9 in Japan. Its underlying AI model is Muse Spark.
  • U.S. availability began on iOS, Android, and the web. A Canadian launch was also reported on September 18.
  • Basic use is free, with paid plans offering higher usage limits.

Primary sources: Introducing Muse, a Personal AI Agent, How We Designed Muse

Availability expanded to Canada after the U.S. launch

Meta launched Muse, a personal AI agent, in the U.S. on September 8. Users can interact with it through dedicated apps, the web, and WhatsApp. The product goes beyond answering questions to operating services on a user's behalf.

According to TechCrunch on September 25, Sensor Tower estimated more than 3.4 million downloads through September 24.

Downloads are different from daily active users or successfully delegated tasks. They indicate launch interest, but continued use requires separate evidence.

Availability has also changed since launch. On September 18, iPhone in Canada reported the Canadian rollout based on Meta's announcement. Its report listed iOS and the web, with Android to follow. Descriptions from the initial U.S.-only launch no longer fully reflect coverage.

It keeps working after the app closes and alerts you when needed

Meta says Muse runs in a dedicated virtual computer called Muse Secure VM. It can browse pages, fill out forms, and work through connected services. It can also suggest next steps based on conversations and registered goals.

According to its designers, Muse handles multiple jobs in parallel and resumes work in response to schedules or relevant events. It is designed to run while the app is closed and notify users about meaningful changes or decisions requiring their input.

The activity history shows work in progress, while the Goals screen presents longer-term goals and plans. Users can reportedly review and edit information Muse remembers. As assignments grow longer, tracing its sources and completed actions matters as much as reading its replies.

Every purchase needs approval, and users control permissions

Meta's technical explanation describes Sentinel, a separate system that determines whether Muse's actions are permitted. It uses configured permissions to allow an action, deny it, or ask the user.

The design does not require confirmation for every action. Previously authorized reads can proceed, while each purchase presents the details and requests approval. For connections such as email, read and send permissions can be separated where the service supports it.

The launch guide says users choose which apps to connect and can later change permissions or disconnect them. Passwords and similar credentials are stored separately and used without exposing them directly to the working AI.

Figure 1Users decide the scope of work delegated to Muse

The design manages ongoing work separately from permission to act.

  • Research and ongoing tasksWork toward the requested goal

    Muse's behaviorContinues after the app closes

    User involvementReview the activity history

  • Service connectionsRead or act in email and other services

    Muse's behaviorUses granted permissions

    User involvementChange or revoke permissions

  • Product purchasesReview the proposed order

    Muse's behaviorWaits for approval

    User involvementDecide for every purchase

This summarizes Meta's stated design. It does not show real-world task success rates or an independent safety evaluation.

Meta's design explanationCompiled by the editors from the user experience design and permissions and approval system.

Cryptographic protection against Meta's access is still planned

The technical explanation says the current Secure VM separates each user's data and restricts employee access through operational policies. This does not make access technically impossible when needed for service operation, safety, or other purposes.

Muse Confidential VM, intended to prevent even Meta from reading data, is a separate system targeted for release later in the year. The current product should not be understood as already providing that protection.

Advertising and training also require separate treatment. Meta says it does not share conversations or VM data with its advertising systems, while users can opt out of model training in settings. Not sharing data for advertising does not mean it is excluded from training.

Long-term value depends on the effort needed to finish tasks

The following is the editors' assessment. Judging Muse's value requires looking beyond natural-sounding replies to how often people must repeat instructions, how long approvals take, and how much effort errors require to fix. Partial automation that ends in substantial human rework may do little to reduce daily effort.

Conversely, delegating ongoing research or schedule checks and intervening only when judgment is needed could offer benefits beyond instant conversational answers. Activity histories and permission controls are central to assessing that use.

The announcements reviewed do not specify a launch date for Japan. As use expands in supported regions, the task is to establish which errands can reliably be delegated.

Sources and references

Update history

  • Published.

LATENT uses Google Analytics (Firebase) to improve our articles. With your permission, cookies and similar technologies send browsing and interaction data to Google. Privacy policy