The Field GuideAI Explained
Meta Muse: the pros, cons and real risks of a personal AI agent
Meta's Muse reached the top of the US App Store within ten days. What it does for a small business, what went wrong in its first month, and how safe it is to let it act without supervision.
By Adi Huric, founder of Most AI LabsOctober 4, 202611 min read
On this page
Meta launched Muse on 8 September 2026 as a personal AI agent: software that does not just answer questions but sends the email, books the trip and negotiates the sale. Ten days later it was the top free app on the US App Store. On 29 September Meta added Muse for Small Business, connected to tools like Shopify, QuickBooks and Stripe.
It is the most popular AI agent so far, and it arrived with some of the most detailed safety engineering any company has published. It also produced two of the first widely reported agent incidents. Both things matter if you are deciding whether to let it run part of your business.
What Muse is
According to Meta, Muse runs on its own dedicated computer in the cloud, which Meta calls Muse Secure VM, with its own browser. You talk to it like a person, in the Muse app or in WhatsApp. It is powered by Meta's Muse Spark model, and Meta says it can "open a browser, fill out forms, and negotiate on their behalf," keep working after you close the app, and come back "when it needs approval, like before it sends an email or makes a purchase."
Muse for Small Business connects to Asana, Box, Canva, Dropbox, Figma, Granola, HighLevel, Intuit QuickBooks, Klaviyo, Lovable, Notion, Shopify, Slack, Stripe and Zoom, plus your Facebook Pages, Instagram professional account and Meta ad accounts. Meta's pitch is that it starts out "already understanding your business": what you sell, how your brand sounds and what customers keep asking.
Who can use it in Canada, and what it costs
Meta's launch post on 8 September said Muse was rolling out in the US. By 29 September, Meta described it as "available in the US and Canada." It runs on iOS, Android, the web at muse.ai and WhatsApp, with AI glasses announced for the coming months.
Muse is free for most use, with two paid plans for heavier use: Power at US$20 a month and Maximum at US$100 a month. Mark Zuckerberg said the plan is to keep Muse free "for a huge number of tokens, with the expectation that over time we will profit by taking a small fee from transactions." That is worth remembering for an agent whose job includes buying things for you.
Why it took off
The demand is real, and so is the promotion behind it. Muse reached the top of the US App Store on 18 September and the top of Google Play on 19 September. Estimates of its early downloads range from about 2.3 million (Appfigures) to 3.4 million (Sensor Tower) and 4.3 million (Apptopia). TechCrunch also reported, citing Sensor Tower, that Meta began running house ads for Muse the day after launch, and within ten days Muse received the majority of Meta's own promotion across its apps, ahead of Facebook, Instagram and WhatsApp.
The case for Muse
It is built for people who are short on hours
Meta's small-business example is a grocery owner in Iowa working 65 hours a week. That is the right customer. Asking an agent to read your sales, your ad results and your inbox, then hand you a plan and first drafts, is genuinely useful for an owner who does every job in the business.
The safety design is unusually specific
Meta Superintelligence Labs published a detailed account of how Muse is contained. The parts that matter most for a business owner:
- A separate gatekeeper. A second agent called Sentinel is "the sole permission authority" for actions in connected apps and for anything leaving the machine. Muse proposes; only Sentinel can allow it, deny it or ask you.
- Approvals that cannot be faked in chat. Approval requests appear in a separate dialog in the app, not inside your conversation with Muse, which makes it harder for a malicious message to fake your "yes."
- No passwords for the agent. Muse works with stand-in tokens; the real credentials are inserted at the network boundary, so it cannot leak what it never sees.
- Email that cannot hijack your other accounts. The email connector filters out one-time codes, password-reset links and login links.
- Safer payments. Purchases on sites with saved cards need approval with the exact details every time, and new sites use Stripe Link's single-use card numbers.
- Read and write kept apart. Where a service allows it, you can give Muse read access without letting it send or change anything.
- Money on the line. Meta opened a public bug bounty of up to US$300,000 for valid reports, including up to US$130,000 for prompt-injection attacks.
Your data and Meta's ads
Meta says Muse does not share your conversations or the data in your Muse computer with its ad systems, and that a future "Muse Confidential VM" will encrypt it with a key only you hold. You can also opt out of your interactions being used to train Meta's models.
The case against Muse
The first incidents were exactly the ones that matter
The Marketplace sale. Tech YouTuber Matt Robb reported that Muse, handling a Facebook Marketplace listing, agreed to a lower price and gave a buyer his home address. The buyer turned up at his building and waited. When Robb confronted it, Muse replied: "You're right, and I'm sorry." TechCrunch later noted that Robb acknowledged granting a permission that made this possible.
That detail does not make it less important. It makes it more useful. Nothing was hacked. A broad permission, given once, let the agent speak for its owner in a way he never intended.
The private messages dispute. Inc. writer Jason Aten said Muse referred to private messages from his editor and podcast co-host although Full Disk Access was switched off on his Mac. Meta's communications chief Andy Stone said reading Messages requires both Full Disk Access and the Messages connector, and Meta's David Singleton said those protections "can't be circumvented even if the Muse application had a bug." As of TechCrunch's report, the two accounts had not been reconciled.
Amazon blocked it
On 20 September, Amazon began blocking Muse from shopping on Amazon.com. People using Muse there saw a notice: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." According to GeekWire, which first reported the block, Amazon had asked Meta to leave Amazon out of Muse and Meta had not.
Amazon gave three reasons: Meta never told it Muse would shop on its store, the agent does not identify itself as an AI while browsing, and it "appears to capture and store customer credentials," which Amazon says could reach account pages and order history. An Amazon spokesperson said agents that buy on customers' behalf "should operate openly and respect service provider decisions about whether or not to participate." Meta's position, from its launch materials, is that Muse "has no visibility into people's passwords or payment methods."
There is a business side too. Amazon earned more than US$68 billion from advertising last year, which depends on shoppers browsing its pages, and it has moved against shopping agents from Perplexity, Google and OpenAI as well. Tech Times pointed out that Amazon's own "Buy for Me" agent shops other retailers' websites that did not opt in. As of GeekWire's report the two companies were in direct talks, and we found no report of the block being lifted as of 4 October.
The practical point for a business: an agent can only shop, book or buy where the website lets it. Some of the biggest sites are choosing not to.
Meta's own words about mistakes
Meta's engineers are candid. Describing their own early use, they wrote that handing an agent their inboxes, calendars and a computer "to let it run unattended" is something that "didn't always work out as planned," and that "Muse can and will still make mistakes."
Standing permissions remove the main safeguard
Muse's protection rests on asking you at the right moments. But its approvals can be one-time, per session, per task, time-limited or perpetual, and Meta says read-only, previously allowed or low-risk actions proceed without interruption. Every "always allow" you grant to save time is a decision you will no longer see.
The track record
TechCrunch's launch review pointed to Meta's history: a 2011 FTC settlement over deceiving users on privacy, a US$5 billion FTC penalty in 2019, and the Cambridge Analytica scandal. The new architecture may be sound. Trust in the company running it is a separate question each business has to answer for itself.
Model training is an opt-out, not an opt-in
Meta offers an opt-out from training rather than an opt-in. For a business connecting customer records and finances, that setting deserves a decision on day one, not a default.
How safe is Muse as an agent nobody supervises?
This is the question most owners are really asking. Our answer, task by task, is below. It is our assessment from the published design and the reported incidents, not a measured probability.
Reading and summarising: inbox triage, sales and ad reports, spotting odd expenses
Useful: High · Risk if left unsupervised: Low
Nothing leaves your accounts. The remaining exposure is your data itself, so check the model-training setting.
Drafting for your approval: posts, campaigns, email replies, plans
Useful: High · Risk if left unsupervised: Low
Meta says nothing publishes, sends or spends without your approval. Safe for as long as you keep that approval step.
Scheduling and bookings
Useful: Medium · Risk if left unsupervised: Medium
Mistakes are usually reversible, but they reach other people and cost goodwill.
Replying to customers or buyers on your behalf
Useful: Medium · Risk if left unsupervised: High
The Marketplace case: a standing permission let Muse agree a lower price and share a home address the owner never meant to share.
Spending: purchases, ad budgets, subscriptions
Useful: Medium · Risk if left unsupervised: High
Meta requires approval at checkout and issues single-use cards, which helps. A wrong purchase is still real money, and some stores, Amazon included, block Muse outright.
Write access to finance and customer records: QuickBooks, Stripe, Shopify
Useful: Medium · Risk if left unsupervised: High
Errors land in your books and your customers' data. Start these connectors read-only.
Desktop access on a Mac, including Messages
Useful: Low · Risk if left unsupervised: High
A journalist's claim that Muse read his messages is disputed by Meta and unresolved. Do not grant Full Disk Access.
The pattern is clear. Muse is safe to leave alone where it reads and drafts, and risky wherever it speaks for you, shares personal information or moves money. The danger rarely comes from Muse breaking its rules. It comes from an owner granting broad, permanent permissions to save a few taps, which turns a supervised assistant into an unsupervised one.
An agent is only as controlled as the permissions you leave switched on.
How to set it up safely in a small business
- Connect read-only first. Give email, QuickBooks and Shopify read access for the first weeks. Add write access one connector at a time, only after Muse has earned it.
- Refuse "always allow" for anything that talks to customers, shares personal details or spends money. Choose one-time or task-scoped approval instead.
- Keep personal information out of reach. Your home address, staff details and client records should not sit where the agent can quote them to a stranger.
- Turn off model training if you connect business or customer data. Under Canadian privacy law your business stays accountable for the personal information it handles. Our guide to AI and data privacy for Canadian businesses covers what to check.
- Do not grant Full Disk Access on a Mac until the Messages dispute is resolved.
- Read the audit trail weekly. Muse records what it did and plans to do. Someone in the business should own that review. We explain how to set those levels in human-in-the-loop decision levels.
Muse and OpenAI's dots
Muse arrived three weeks before OpenAI launched dots, its own always-on agents, and the two share the same core idea: an agent with its own cloud computer that keeps working while you are away, kept in check by approvals and separate safety systems. Muse is free and mass-market; dots sit inside paid ChatGPT plans. We weighed dots in OpenAI Dots: the pros and cons of always-on AI agents.
Agents like these will also increasingly visit your website on a customer's behalf, looking for prices, availability and a way to book. A site they can act on is part of being found, which we covered in the agentic web.
Our view
Muse is the first agent that ordinary small businesses are actually using, and Meta has published more of its safety engineering than most. Its first month also showed the real failure mode of personal agents: not a hacker, but a permission given too broadly. Used with narrow access, per-action approval for anything that speaks or spends, and someone reading the audit trail, it can take real work off an owner's plate. Left uncontrolled, it can speak for your business in ways you never agreed to.
If you want help deciding where an agent fits in your operations, and where it should not, that is the work we do in AI implementation.
Sources
We used Meta's own announcements and engineering post for every product fact, and named news coverage for adoption figures, criticism and reported incidents.
- Meta: Introducing Muse, the world's first personal AI agent built for everyone (8 September 2026)
- Meta: The future is for everyone, Muse for Small Business (29 September 2026)
- Meta Superintelligence Labs: Security and safety for AI agents, our approach with Muse
- Meta: The biggest news from Connect 2026
- TechCrunch: Meta debuts its Muse AI agent. Will consumers trust it?
- TechCrunch: Everything new coming to Meta's AI agent Muse
- TechCrunch: Meta is putting its muscle behind Muse as the AI app takes off
- TechCrunch: Meta disputes claim that Muse read a user's private messages without permission
- GeekWire: Amazon blocks Meta's Muse AI assistant in new standoff over agentic shopping (21 September 2026)
- Tech Times: Amazon blocks Meta Muse using standards it ignores for its own shopping agent
- The Cool Down, via Yahoo Tech: Man says Meta's Muse AI gave Facebook Marketplace users his home address
Last reviewed: 4 October 2026. Muse is changing quickly, and the Messages dispute was unresolved at the time of writing, so check availability, pricing and settings in your own account.
Where this leads
Next step
See where your own visibility stands.
The 7-day audit turns this research into a picture of your business. Yours to keep, whether you hire us or not.
Read next
The Agentic Web
The agentic web is here. Your next customer might send a bot first.
In mid-2026 Google, ChatGPT, and Claude all shipped AI agents that browse websites, compare options, and even book appointments for a person. Your site now has two audiences: humans, and the agents people send ahead of them. Here is what changed, and the honest, no-hype way to get ready.
8 min
AI Implementation
What an AI agent actually costs, and what it does
Real cost ranges, real examples, no buzzwords. What AI agents do in a working business, and how to know if one will earn its keep in yours.
8 min
Build decisions
Build vs buy for AI implementation
How to choose between a packaged AI product, a custom workflow and a mixed architecture based on differentiation, data, risk and exit cost.
10 min