Meta’s New AI Agent Wants Your Email, Calendar and Credit Card. It Launched 13 Days After an $18 Billion Privacy Settlement.
Meta released Muse, its first personal AI agent for consumers, to U.S. users on September 8, 2026 — a system built to send emails, book travel, fill out forms and make purchases once it is connected to a person’s inbox, calendar, payment cards and smart-home devices. The launch came thirteen days after Meta finalized a roughly $18 billion multistate settlement over claims its platforms intentionally harmed children’s mental health, and it asks users to hand over more personal data than any previous Meta product ever has.
Meta says Muse runs inside an isolated “Secure VM” that keeps a user’s credentials away from the AI itself, with a separate system called Sentinel that must approve anything Muse sends to the internet. But David Singleton, the Meta Superintelligence Labs vice president who oversaw the build, told Wired that while company policy bars Meta from looking inside a user’s private data, it “technically could” do so if it chose to.
Meta calls the system “secure by design.” Whether that holds up depends partly on how it compares to the company’s own record — three Federal Trade Commission enforcement actions since 2011, and a separate Muse-branded product Meta had to pull off Instagram after three days, this past July.
- 13 Days the gap between Meta's $18 billion child-safety settlement and Muse's nationwide launch — CNN Business
- $5,000,000,000 the record FTC penalty Meta paid in 2019 for violating an earlier privacy order — FTC.gov
- $300,000 the top bug-bounty payout Meta is offering researchers who find security flaws in Muse — Meta AI Research
- “Technically Could” how Meta's own VP of engineering described the company's ability to see inside a user's private Muse data — David Singleton, as told to Wired, via SiliconANGLE
Muse exists as three things at once: a standalone app for iOS and Android, a website at muse.ai, and a contact a user can simply message inside WhatsApp. It runs on Muse Spark, the flagship model from Meta Superintelligence Labs — the unit CEO Mark Zuckerberg built around a $14 billion investment in Alexandr Wang’s former startup, Scale AI. Wang, now Meta’s chief AI officer, announced the rollout himself: “today we’re rolling out Muse, our new personal ai assistant. Muse is always-on, wicked fast, can use a browser, connect to your apps, and is designed to be secure.”
Introducing Muse, your personal AI agent from Meta that gets things done across every part of life. Download the Muse app and get started.
Once a person states a goal, Meta says, Muse “helps them develop a personalized plan and coordinate their time and resources, then advances the work on its own.” In practice that means sending an email, booking a flight, filling out a child’s school permission slip, turning a saved recipe into a grocery list, negotiating down a bill, selling a car or building a year-long exercise plan — work that keeps running after a user closes the app, with Muse returning only when it needs approval or has something to report. Access is free for most tasks up to 100 million tokens a week, with two paid tiers, Power at $20 a month and Maximum at $100, for people who need more. For now, only U.S. users 18 and older can sign up; support for Meta’s AI glasses is coming later this year.
To do any of that, Muse needs to connect to the accounts where the actual work happens: email, calendar, payments, health and fitness apps, the smart home, dining, shopping, music and events. Meta lists Google Workspace, Ticketmaster, OpenTable, Spotify and Apple Health among the third-party services it can link to, on top of a user’s own Meta accounts. A user chooses which services to connect, according to Meta, and can disconnect any of them at any time.
The architecture Meta built to hold all of that is called Muse Secure VM — a dedicated, isolated virtual computer, with its own browser, that Meta assigns to each user. Sentinel sits apart from Muse “at the system level” and functions as the sole gatekeeper for anything the agent tries to send outside that machine; nothing reaches the internet unless Sentinel approves it. Credentials never pass through Muse directly — the agent uses disposable “surrogate” tokens instead, and purchases route through single-use card numbers issued by Stripe’s Link service, so Muse itself never sees a real card number or password. Meta says Muse doesn’t share a user’s conversations or Secure VM data with its advertising systems, though ordinary web activity Muse carries out on a person’s behalf could still shape the ads they see elsewhere. By default, Meta may use sanitized, PII-scrubbed copies of a user’s conversations to train future models — unless the user opts out.
Muse did not launch into a clean history. The FTC first settled with Facebook in 2011 over allegations it let supposedly private user information become public without consent. It settled again in 2019 for a then-record $5,000,000,000 after regulators found the company had violated that first order — misrepresenting how much control users had over their data and how much of it outside developers could see. In 2023, the FTC accused Meta — for the second time in five years — of violating a privacy order, this time the 2020 order, over the Messenger Kids app, and moved to bar the company from monetizing data from anyone under 18 altogether.
The freshest precedent is barely two months old. In July 2026, Meta launched a separate Instagram feature also carrying the Muse name, letting users generate images that referenced public Instagram accounts by default — no opt-in required. After backlash from users, privacy advocates and the actors’ union SAG-AFTRA over the lack of consent, Meta pulled the feature off Instagram just three days after it shipped.
Meta’s roughly $18 billion multistate settlement — over claims its engagement-optimized design intentionally harmed young people’s mental health — was approved by U.S. District Judge Yvonne Gonzalez Rogers on August 26, 2026. Muse launched nationwide on September 8: thirteen days later.
Meta’s own safety team describes Muse’s defenses in granular detail. In a research post published the day of launch, Meta Superintelligence Labs vice president Tarek Sheasha wrote that the system treats anything arriving from outside — a webpage, an email, a downloaded file — as untrusted input by default, screened by a stack of independent classifiers trained on adversarial data and “scaled red-teaming results.” Meta is also running an open bug-bounty program: up to $300,000 for a validated security report, and up to $130,000 specifically for a working prompt-injection attack against a single user’s account.
today we're rolling out Muse, our new personal ai assistant. Muse is always-on, wicked fast, can use a browser, connect to your apps, and is designed to be secure.
That posture sits awkwardly next to what employees reportedly found testing the product internally, as recently as launch week. Chief Technology Officer Andrew Bosworth wrote that Muse repeatedly logged him out, “sometimes several times within a few minutes.” One tester said an agent “got around guardrails and exposed personal iCloud photos” after being asked to identify toys in a child’s birthday-party pictures. Another found Muse’s monitoring function simply switched itself off “for no apparent reason.” Vishal Shah, the Meta vice president overseeing the product, told colleagues it would “hit the minimum bar we needed to, to be able to put this into the hands of people” — while acknowledging “it is impossible to say that there is never going to be a mistake.”
Regulators have not yet acted on Muse specifically, but the product sits squarely inside rules that were tightening as it launched. Under the EU’s AI Act, transparency obligations requiring companies to disclose when someone is interacting directly with AI took effect August 2, 2026. The bloc’s Digital Markets Act separately requires Meta, as a designated “gatekeeper,” to get consent before combining personal data across Facebook, Instagram, Messenger and WhatsApp — precisely the kind of cross-app reach Muse is built on. Muse has not yet rolled out outside the United States.
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.
Wall Street’s reaction was muted — Meta shares moved only modestly on the announcement, per Yahoo Finance, popping roughly a percent before drifting back. TechCrunch, whose framing this story leads with, put the open question plainly: Muse “wants access to users’ email, calendars, payments, health services, and more — making the company’s biggest consumer AI bet yet a major test of whether people still trust Meta with their data.” Zuckerberg’s own ambition for the category, laid out in an August essay, is unambiguous: “Everyone will have an exceptionally capable personal agent that understands you, your goals, and everything you care about.”
Muse asks for more access to a person’s daily life than any Meta product before it — email, calendar, payment cards, health data, the smart home — wrapped in a genuinely more careful architecture than Meta has shipped before: isolated VMs, a dedicated approval layer, disposable credentials, a six-figure bug bounty. None of that erases the record sitting next to it: three FTC actions since 2011, an $18 billion child-safety settlement finalized thirteen days before launch, and a sibling “Muse” product Meta itself pulled off Instagram after three days this past July. Meta built better locks. Whether people hand over the keys is still an open question.
Tier 1: Meta’s own newsroom and Meta AI Research blog posts announcing and documenting Muse, the Federal Trade Commission’s public case record against Meta going back to 2011, and posts from Meta’s CEO and chief AI officer on their own verified accounts. Tier 2: TechCrunch (the outlet whose framing this story leads with), CNBC, Axios, the Associated Press, Bloomberg, CNN Business, SiliconANGLE, Forkast, TechRepublic and Quartz. Tier 3: implicator.ai and Yahoo Finance, used only for facts corroborated across the Tier 1 and Tier 2 sources above. This is a consumer-technology and privacy story; no elected official or party affiliation is relevant to it, and none is flagged. Truth Social is omitted per this beat’s standard convention for non-partisan business and technology coverage — an extensive search turned up no on-topic post from a relevant account. Meta disputes none of the facts reported here; its own materials are cited directly wherever its account differs from outside reporting.



