Vishal Shah had a deadline he did not want to miss again. Meta’s product executive had originally planned to launch the company’s personal AI agent in April, then pushed it back to harden the security architecture around it. On September 8, he shipped it anyway, into a market that has spent the past two weeks watching Meta settle a painful lawsuit over how it treats young users.
The product is called Muse, and Meta describes it as a personal AI agent that, once authorized, can reach into a user’s email, calendar, payments, health and shopping apps to act on their behalf. It can send emails, book flights, fill out forms and place paid orders. Long-running tasks keep progressing after the app is closed, and the agent pauses to ask permission before anything sensitive goes through.
Muse runs inside what Meta calls a Muse Secure VM, an isolated virtual machine in the company’s cloud, and is built on a new model named Muse Spark. It arrives through standalone iOS and Android apps, through the web at muse.ai and through WhatsApp, which Meta sees as its broadest distribution channel. Support for the company’s AI glasses, a product it has bet heavily on, will follow later.
The payment plumbing is designed to keep card numbers away from merchants. Muse pays through Stripe Link and generates a one-time card number for each transaction, so the retailer never sees the user’s real card details. Meta is pitching the isolation and the tokenization as the answer to the obvious objection: that handing an agent your inbox, calendar and bank cards is a leap of trust most people will not take lightly.
Pricing starts at free, with paid tiers attached. The Power plan costs $20 a month and the Maximum plan $100 a month, and both require a card on file. Meta did not say how much usage the free tier allows before a user is nudged toward a subscription, or how the agent decides which tasks are worth interrupting its owner about.
The launch lands less than two weeks after Meta agreed to an $18 billion settlement with a group of U.S. states over claims that it harmed teenage users. That timing gives the product an awkward backdrop. A company that is still rebuilding public trust around data is now asking customers to route some of their most sensitive accounts and their payment information through its own infrastructure, at the same moment its data practices are being scrutinized.
Meta’s broader bet is that the next computing platform is a personal agent that knows its owner well enough to act without constant instruction. Chief executive Mark Zuckerberg has talked for months about building toward a “personal superintelligence” that sits alongside every user. Muse is the first product that turns that ambition into a utility that touches real money and real calendars, and it is the clearest test yet of whether users want that kind of autonomy.
The competitive field is crowded, which is part of why Meta is moving now. OpenAI, Google and Amazon have each pushed their own assistant efforts this year, and Apple has signaled it will lean on agentic features across its software. Meta’s edge, if it has one, is distribution: billions of people already live inside its apps, and WhatsApp is a default communication tool across much of the world, which gives Muse a built-in audience no rival can match.
Shah’s decision to delay the April launch points to how seriously Meta took the safety questions. The company spent the intervening months on the secure VM design and the permission model, treating the architecture as the feature rather than an afterthought. That work is invisible to most users, but it is the part Meta needs to get right if the agent is to survive contact with skeptical regulators and privacy-conscious customers.
Meta’s investment in the underlying models has been heavy. The company has committed to large-scale AI infrastructure spending this year, and Muse Spark is the latest in a series of models released to compete with the frontier labs. The agent is the point where that spending meets a product a consumer can actually use, and where the economics of running advanced models at scale will be tested against a $20 monthly subscription. If agents become the default way people manage their digital lives, the company that controls the default agent controls a toll booth on commerce, scheduling and communication. That is the prize, and it is why Meta is willing to absorb the trust risk and the settlement headlines to get Muse into phones first.
The question analysts are asking is whether people will trust Meta enough to let an agent act on their behalf, or whether the permission prompts and one-time cards will be met with the same wariness that greets most new Meta products. Shah’s delayed launch suggests the company understood how much was riding on getting the story right. The market will now decide whether it did.


