Companies
Meta Launches Muse, an AI Agent With Access to Your Inbox
Meta's Muse agent is live in the US, sending emails, booking travel and paying with your card from an isolated VM. Internal testers reported unauthorized password resets and leaked photos first.

Meta has shipped the most capable consumer AI agent on the market, and it did so while its own employees were still filing security bug reports against it. Muse launched in the United States on September 8. It connects to your email, calendar and payment accounts, and it will send messages, book flights, negotiate bills and check out with your card. Whether that trade is worth making depends less on what Muse can do than on what happened when Meta's staff tried it first.
What the product is
Muse is a personal agent that runs on Meta's Muse Spark model, available on the web at muse.ai, on iOS and Android, inside WhatsApp, and soon on Meta's smart glasses. Meta lists the jobs it expects people to hand over: sending emails, booking travel, lowering bills, filling out forms, turning a recipe into a shopping list, sending party invitations and making purchases. Payments run through Link by Stripe, with Shop Pay and 1Password integrations promised next. It is US-only for now.
There are three tiers: a free plan, Power at $20 a month and Maximum at $100 a month. A payment card is required even for the free plan. Meta says most people will stay on the free tier, and press reports quote a free allowance of up to 100 million tokens a week, though that figure comes from coverage rather than Meta's product page.
The architecture Meta wants you to notice
Two design choices set Muse apart from browser-based agents. Each user's agent runs inside its own cloud virtual machine, which Meta calls the Muse Secure VM. A separate process called Sentinel sits between that VM and the internet and has to approve every outbound action the agent tries to take. Later this year Meta plans a Muse Confidential VM, where the whole machine is encrypted with a key only the user holds, so that Meta itself cannot read what is inside.
On paper, this is the right shape. Isolation limits the blast radius of a bad decision, and a second agent auditing the first is how most serious enterprise agent deployments are now built.
The part that is not on the product page
Muse was tested internally under the codename Hatch, and The Information's reporting from employee testers reads like a checklist of what an agent must not do. It reset passwords without being asked, including one for a health-tracking app. It sent emails nobody approved. It moved travel points to the wrong account. It pointed users to scam websites. One tester asked it to identify the toys in photos from a child's birthday party, and the agent worked around its guardrails to reach the person's private iCloud library. Another set it to watch for tickets that sell out fast, and reported that it stopped refreshing after about 15 minutes and switched monitoring off "for no apparent reason."
Meta added confirmation prompts and a credential vault in response. It has not commented publicly on the specific reports. The launch also came less than two weeks after Meta signed an $18 billion multistate settlement over harms to children on its platforms, which is not the backdrop a company would choose for asking users to hand over their inbox.
What this changes for businesses
Even if you never install Muse, agents like it will soon be your customers. They will read your booking page, compare your prices and file your refund requests, and they will do it through Muse, Google's Gemini Spark or Anthropic's Claude Cowork rather than a human clicking around. Sites with convoluted checkout flows and forms that only a person can decode will lose that traffic first.
For teams building their own agents, treat Meta's two-layer model as the minimum bar: an isolated execution environment plus a separate approver for anything that leaves it. Then run Meta's incident list against your own pilot before a customer does. An agent that can move money or change passwords without a confirmation step is not a productivity tool yet. It is a liability with a chat interface.
Sources: TechCrunch, Reuters, The Information (Hatch internal testing report), Implicator

Written by
Muhammet Fatih Batman
Founder & Editor
Founder of YZ Uzman, with 20+ years of experience in web design and software development.