Meta’s bet with Muse is that a personal agent should feel like texting a person, then go do the work. You tell it to book travel, send an email, or chase a longer goal, and it keeps going after you close the app. It checks back when something changes, or when it needs a yes before it spends money or sends a message. The model behind that is Muse Spark, which Meta calls its most capable model so far, built for this kind of agent work. Muse is free up to a weekly usage cap. Power is $20 a month for 500 million Muse tokens a week. Maximum is $100 a month for 3 billion. Paid plans buy more usage, not a different product.
A computer of its own
The computer it runs on is the part worth paying attention to. Each person gets a Muse Secure VM, a dedicated virtual machine in the cloud that holds the agent, a browser, and the credentials for services they connect. A separate Sentinel process has to approve anything that leaves that machine for the internet. Meta says Muse cannot see passwords or payment details. Credentials go into storage the agent can use without reading. Sensitive steps, including email and purchases, wait for the user, and the app keeps an audit trail of what it did and what it plans to do.
People pick which apps connect, and whether email access is read-only or includes sending. Conversations and VM data are not fed into Meta’s ad systems, and users can opt out of having their interactions used to train Meta’s models. Later this year Meta plans Muse Confidential VM, encrypted with a key only the user holds, so Meta itself cannot read the contents. That version is not what shipped.
Checkout, and the sites that said no
Checkout is already a product, not a demo. Muse pays through Stripe Link, which issues a one-time card so the real card number stays hidden. Meta says it is the first agent covered by Link’s purchase protections, including coverage for damaged or lost items, price drops, and eligible returns. Shop Pay and 1Password support are still coming. If a service has an API, Muse connects with credentials the user provides. If it does not, Meta says the agent uses a browser the way a person would. That second path is where the fights start.
Amazon cut Muse off from Amazon.com. The company said Meta never agreed the agent would shop there, that Muse does not identify itself while it browses, and that it can reach account pages and order history when a customer asks it to. Amazon’s notice to users cites its Conditions of Use. Meta’s answer is the VM, Sentinel, and the approval step before a purchase. Amazon’s objection is that an unidentified third party was moving through customer accounts. GeekWire reported the block.
Memory of people who never signed up
The memory design creates a second problem that has nothing to do with checkout. Wired reported that Muse’s own instructions tell it to keep a page for every person in a user’s life: family, partners, friends, colleagues, collaborators, and people the user follows. Those pages start thin and fill in over time, with sections for facts, history, the relationship, and open threads. The instruction says invented details are worse than an empty page, which means the pages are built from whatever evidence Muse already has. The people on those pages did not connect an account or accept a prompt. Meta’s controls, wiping a memory or disconnecting a service, sit with the Muse user, not with the friend who got a dossier. Wired’s report is the source for that behavior.
The security boundary was still moving at launch
The security story at launch was tighter than the marketing. 404 Media reported that in the weeks before release, Meta found vulnerabilities in the VM boundary, at least one of which could have let a normal Muse user reach internal Meta databases. The issues went to Mark Zuckerberg, and staff worked overtime to close them before the app went out. Meta’s own bug bounty treats a VM escape that reaches production services outside Muse as the highest severity. Fixing that class of bug before launch is what a serious team does. It is also evidence that the isolation story was not finished when the product was already on the calendar. 404 Media’s account is based on internal documentation and a Meta source.
What shipped after the app
Since the September 8 launch, Meta has been widening the surface. On September 23 it said Muse is coming to its AI glasses, including hands-free tasks like booking, price checks, and buying something you are looking at. On September 29 it opened Muse for Small Business, with connectors for tools such as Shopify, Slack, QuickBooks, Stripe, Notion, Canva, and Facebook and Instagram business accounts. On October 2 it published Muse Gadgets, open-source firmware so a hobbyist board can talk to the same cloud agent, plus a small USB-C Home Link for US subscribers. This week Meta, Sierra, Walmart, and Stripe started work on a Personal Agent Protocol, a standard for how an agent identifies itself and transacts with a business. That is the missing piece in the Amazon dispute, written down after the block rather than before it.
For anyone building agents, Muse is a useful spec even if you never install it. Isolate each user. Keep a watcher that can refuse an outbound action. Hide credentials from the model. Ask before money and messages leave the building. Then assume every site you browse without permission will treat you as an intruder, and that memory of other people is a product decision, not a side effect.


