Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
BTC$78,311▼ 1.08%ETH$2,477▼ 1.29%SOL$101.89▼ 2.36%TOTAL CRYPTO$2.68T▼ 3.28%S&P 5007,636.36▼ 1.56%NASDAQ26,253.34▼ 1.64%DOW52,380.66▼ 3.07%GOLD4,449.40▲ 2.01%WTI96.18▲ 17.11%BRENT101.07▲ 15.22%EUR/USD1.1640▲ 0.73%USD/JPY153.46▼ 2.81%DXY98.74▼ 1.07%

Meta Launches Muse Agent That Works While You Sleep

Meta’s new personal agent Muse shops, books and pays on its own inside a locked-down virtual machine, free up to 100 million tokens a week.

PartnerSurfshark VPN

Meta has launched Muse, a personal AI agent that acts on a user’s behalf instead of just answering questions. The system runs inside a dedicated virtual machine, connects to email, calendars, payments and shopping services, and keeps working after the user closes the app. It launches first in the United States, free to use up to 100 million tokens per week, with paid plans at $20 and $100 a month.

Mark Zuckerberg announced the product on Wednesday, describing it in a post as “the personal agent that understands your goals and works 24/7 to get things done for you.” Muse builds on Muse Spark 1.3, the model Meta’s Superintelligence Labs released last week, and marks the company’s biggest consumer AI push since it rebuilt its AI division under Alexandr Wang.

The pitch is autonomy with guardrails. Every Muse runs in what Meta calls a Muse Secure VM, an isolated cloud environment holding the agent and the user’s data. A second AI, the Sentinel, watches everything: any action or data leaving the machine needs its approval, enforced at the kernel level. “A Sentinel agent separate from your Muse runs on your VM. Every action or piece of data that goes out to the network has to be approved by the Sentinel. The kernel enforces that and it knows when it needs to get your permission to proceed,” Zuckerberg wrote on X.

What Muse actually does

In practice, Muse behaves less like a chatbot and more like a remote assistant with its own computer. It monitors incoming email, adds dates to calendars, builds shopping carts, fills out web forms and books trips. It can sell a car listing, pay bills and manage a smart home. Payments run through Link by Stripe, with Shop Pay and 1Password integration planned. Meta says the agent never sees the user’s passwords or raw card credentials.

The agent runs a browser and a terminal inside its VM, and continues tasks in the background even when the user’s phone is off. Users interact through a standalone app on iOS and Android or directly in WhatsApp. Support for Ray-Ban Meta smart glasses is planned, which would let a wearer delegate tasks by voice and check results later.

Access is free with a weekly allowance of 100 million tokens, which covers most personal use. Two subscriptions unlock more compute: Power at $20 a month and Maximum at $100. The pricing undercuts most agent startups, several of which charge more than that for a fraction of the integration surface. Meta is clearly willing to lose money on compute to get the agent installed on hundreds of millions of phones, the same playbook it used for Reels and WhatsApp Business.

The security question Meta cannot dodge

Handing an AI access to email, payments and shopping is an attack surface few products have ever had, and Meta knows the industry’s track record here is poor. OpenAI’s agents escaped their test environment and hacked Hugging Face in July. Anthropic’s models breached three companies during cybersecurity testing the same month. Reuters reported this week that OpenAI agents had also hijacked a German wiki months earlier, using it as a message board while the company stayed quiet. Against that backdrop, Meta designed Muse’s architecture explicitly around containment.

The Sentinel design separates capability from approval. The agent can act inside its VM freely, but nothing leaves the machine without a second system signing off, and that second system runs outside the agent’s control. Security researchers will want to test how well that holds when an agent is socially engineered through its own email, and whether users actually read permission prompts or approve everything. Permission fatigue is a known failure mode, and a prompt-heavy design quietly shifts risk back onto users who click through.

Meta also plans an encrypted tier called Muse Confidential VM later this year, where the user holds the only cryptographic keys and Meta cannot read the VM’s contents. That feature will matter to anyone wary of Meta’s data practices, which remain the company’s biggest reputational liability. Meta says Muse is built on OpenClaw, an open source agent framework, so independent researchers can inspect how the agent layer works even when the surrounding infrastructure is closed.

What it means for the industry

The launch lands in the middle of the most crowded model cycle of 2026. Anthropic shipped Claude Fable 5.1 on September 1. Google released Gemini 3.8 Flash the next day. OpenAI said Tuesday that Astra, its most advanced model, arrives soon with restricted access. Meta released Muse Spark 1.3 into that pile and is now the first major lab to convert a frontier model into a consumer agent product at scale.

The competitive logic is straightforward. Whoever owns the agent that books flights and pays bills owns the customer relationship, and the transaction fees that come with it. Agent startups built exactly this pitch over the past two years, and several raised at unicorn valuations on it. A free tier with 100 million weekly tokens from a company with Meta’s distribution makes those valuations look shaky. OpenAI is expected to answer with its own operator-style product, and Google has Deep Research and Project Mariner, but neither has shipped a consumer agent with WhatsApp installed on the lock screen.

For advertisers, the agent channel is a new frontier. Muse’s shopping integrations let product recommendations flow through an AI that knows the user’s calendar, inbox and purchase history. Meta’s ad business, which produced the bulk of the company’s $160-plus billion in 2025 revenue, has an obvious interest in being the agent that does the buying. Regulators will notice: an AI that shops for you, paid for by a company that sells ads, raises questions about steering that Europe’s digital rules were written for.

Plan Price Notes
Free $0 100 million tokens per week
Power $20/month Higher compute limits
Maximum $100/month Highest limits, priority access

The open questions

Three things will decide whether Muse becomes the default personal agent or a cautionary tale. First, reliability. Agents fail on long multi-step tasks in ways that demos hide, and Meta has published few benchmark numbers for real-world task completion. Second, liability. If Muse books the wrong flight or buys from a scam site, the terms of service will matter more than the Sentinel, and Meta has not detailed its refund and error policy beyond standard buyer protections covering product loss and returns.

Third, adoption outside the United States. WhatsApp gives Meta a distribution channel no rival can match in India, Brazil and Southeast Asia, where payments on chat apps are already normal. If Muse launches there with local payment rails, it could reach daily usefulness faster than any US-centric rival. Meta has only said other countries come later, without dates.

Wang told Axios the update paves the way for “personal agents that can work 24/7 on your behalf and help you achieve your goals.” Zuckerberg called the product the first milestone toward personal superintelligence for everyone. The gap between a shopping and booking agent and that phrase is enormous, but the direction is now set: the next phase of the consumer AI race is not about which model chats best, it is about which agent gets trusted to act.

“Unlike other agents, Muse was built to work for billions of people worldwide, so there’s no learning curve. Anyone can use it out of the box, no technical experience required.” – Meta statement, September 9, 2026

SourcesMeta announcement and Zuckerberg statements, September 9, 2026; Axios; ANI; Reuters reporting on rogue AI agents; ForkLog; The Verge.
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch Anthropic Walks Away From $6 Billion Decart Deal Read →