We’ve spent the last few years getting used to AI that can answer questions, write emails and help us make decisions. Muse AI takes that relationship a step further. Give it something to do and it can actually go and do it, using browsers, apps and connected services on your behalf.
Meta launched Muse on 8 September 2026 as a personal AI agent that can handle tasks such as sending emails, booking travel and shopping. It can also remember information about its user and continue working on longer tasks without needing someone to guide every individual step.
Within its first two weeks, Reuters reported around 2.8 million downloads and top positions on free app charts in the US and Canada. That’s a fairly significant amount of autonomy to put into people’s hands at once.
And with Meta already expanding Muse into business tools, the problems appearing during its first few weeks offer an early look at what happens when AI stops simply helping people decide what to do and starts acting for them.
What Is Muse AI And What Can It Actually Do?
Muse is what Meta calls a personal AI agent. In simple terms, that means it doesn’t just give you information or generate something for you. It can take a goal, work out the steps needed to achieve it and then use other digital services to carry them out. Ask a normal AI assistant to help plan a trip and it might compare destinations or build an itinerary.
Muse can go further by using its browser and connected services to research options and book the travel. The same principle applies to email, shopping and other multi-step tasks. Muse can also remember details a user has previously shared, which allows it to use that context again without being reminded each time.
The distinction between Muse and Meta AI isn’t absolute. Meta AI itself has gained more agent-like capabilities, while Muse is built much more explicitly around completing work rather than primarily answering questions. Underneath Muse is Muse Spark, Meta’s family of AI models, which provides the intelligence needed to understand a task and decide what to do.
The current Muse Spark 1.3 model has been trained for longer tasks involving multiple steps and tools. Meta says it has also improved the model’s ability to recognise irreversible actions and respond appropriately when a task reaches that point.
That last part becomes particularly important because the more an AI can do, the more important the boundaries around those actions become.
How Does Muse AI Work?
Meta hasn’t designed Muse as an AI model with unrestricted access to everything a user connects. Instead, the system has several layers intended to separate what Muse decides to do from what it’s actually allowed to do. Muse works inside a Muse Secure VM. VM stands for virtual machine, which is essentially a separate computer created in software.
Each user gets an isolated cloud environment where Muse can run its browser, work with files and interact with connected services. A separate system called Sentinel then controls whether proposed actions can actually happen. Think of Muse as the worker deciding what needs to be done and Sentinel as the system checking whether it has permission to do it.
Meta says Sentinel can allow an action, deny it or stop and ask the user. Muse itself can’t override that decision. Those permissions can also work at different levels. Meta says users can grant permission once, for a session or task, for a limited period or permanently. Services can be restricted further too.
When Vector RAG Stops Working
Why retrieval strategy now hinges on matching Vector, Graph and hybrid RAG to the questions AI must answer across complex enterprise data.
Someone could, for example, allow Muse to read their email without allowing it to send messages. This is an important trade-off. If Muse had to ask the same question before every routine action, much of its usefulness as an autonomous agent would disappear. But persistent permission also means the user needs to understand what they’re authorising beyond the immediate task in front of them.
Meta says credentials such as passwords and authentication tokens are stored separately so Muse can use them without seeing them directly. Users can also review what Muse has done and change or remove access later.
A further Muse Confidential VM, designed to prevent even Meta from accessing information inside the environment, is planned for later in 2026 rather than being part of the standard Muse architecture today. It’s a fairly substantial control system on paper. The harder test is what those controls look like once real people start using them.
Why Is Muse AI Already Under Scrutiny?
One of the clearest examples came from tech reviewer Matt Robb after he asked Muse to handle a Facebook Marketplace listing. Muse accepted an offer, sent the buyer Robb’s address and continued communicating with him. Robb only realised what had happened when the buyer arrived.
At first glance, this looks like an agent simply acting without permission. But Robb later found that he’d selected an “Allow Always” option. He believed Muse would still ask before accepting an offer, while the permission he’d granted allowed the agent to continue communicating using information he had already provided.
The distinction is important. Muse had been given permission. The problem was that what the system understood that permission to cover appears to have been broader than what the user expected it to mean. Other early problems have tested completely different boundaries.
Reuters reported on 25 September that a security researcher had discovered a vulnerability that could potentially expose sensitive information stored in Muse virtual machines, including emails and files.
Inside the Agentic SOC Stack
See how unified telemetry, correlation engines and agentic AI workflows rebuild SOC architecture for autonomous detection and response.
The issue was initially classified as SEV-2. Meta subsequently told The Information that it had been reclassified as SEV-3 after further investigation, while also strengthening a warning shown when Muse suspects a malicious site. Reuters separately reported that Meta paused testing of a human concierge feature that used contractors to handle some phone calls for Muse.
Meta acknowledged that the lack of appropriate disclosure was a mistake. The issue here wasn’t simply whether a task had been completed correctly. Users also needed to know when information they believed they were sharing with an AI had crossed over to a human operator. Then there’s Amazon.
The retailer blocked Muse from shopping on its site after saying Meta hadn’t been authorised to deploy the agent there. Amazon’s position raises another question entirely: when an AI agent arrives at somebody else’s platform, how does that platform know what it is, who it represents and whether it has authority to act there?
Taken together, these incidents don’t point to one simple flaw in Muse. They show how many different boundaries an autonomous agent can encounter once it starts acting outside its own environment.
Why Muse Matters Beyond A Consumer AI Agent
Those boundaries become much more consequential when the agent is connected to business systems. On 28 September, Meta launched its Meta Enterprise Platform, which will bring Muse, Muse API, Muse Code and other AI products to businesses and developers.
Muse for Small Business followed with connections to services including QuickBooks, Shopify, Slack, Stripe, Zoom, Notion, Asana and Facebook and Instagram business accounts. That gives an agent potential access to financial information, customer records, communications, sales data and other parts of day-to-day operations.
Meta says nothing in Muse for Small Business “publishes, sends, or spends” without user approval. But approval is only one part of the problem. Businesses also need to decide which actions are routine enough for an agent to handle independently and which are consequential enough to require a person every time.
The AI Value Gap Boards Now See
Escalating AI budgets are colliding with thin ROI. Explore why agentic AI heightens risk and why value oversight is becoming mandatory.
Reading an invoice and paying one aren’t equivalent simply because the agent has access to the same financial system. The wider enterprise market is already grappling with that distinction. Deloitte surveyed 3,235 business and IT leaders across 24 countries and found that only 21 per cent said their organisations had mature governance for agentic AI.
Yet 74 per cent expected their companies to be using AI agents at least moderately by 2027. Identity is becoming part of the conversation too. NIST received feedback from more than 600 industry, government and academic respondents for its work on software and AI agent identity and authorisation.
It’s now developing an implementation showing how agents can be identified, authenticated and authorised within software development environments. Muse makes those fairly technical questions much easier to see in practice.
What Should Enterprises Learn From Muse AI?
It would be easy to look at Muse’s early problems and conclude that autonomous agents simply need tighter permissions. But an agent that has to ask a human before doing almost anything isn’t especially autonomous. The challenge is deciding where useful independence ends and meaningful human authority needs to begin.
Muse points towards a more practical set of questions:
- What does each permission actually allow the agent to do?
- Which actions should always require fresh approval, even when broader access already exists?
- What happens when the agent reaches another person, organisation or external system?
- When does an automated task involve a human, and does the user know when that hand-off happens?
- Can administrators reconstruct what the agent did, narrow its authority or remove its access quickly?
The common thread is delegated authority. Giving an agent access to a system tells it where it can operate. It doesn’t necessarily settle what decisions it should be able to make once it gets there. That difference becomes increasingly important as agents move away from controlled experiments and into the systems where real work happens.
Final Thoughts: Autonomous AI Changes What Permission Means
GPT-5.6 and the New AI Stack
How Sol, Terra and Luna reshape choices between capability, cost and speed for enterprise-scale AI deployment strategies.
Muse is still new, and both the product and its controls will continue to change. Its first few weeks have already shown something useful, though. Familiar ideas such as permission, approval and access become much less simple when software can make decisions and act on them.
Once an AI can send a message, make a purchase, access business software or commit someone to an action, permission becomes a definition of delegated authority. The question isn’t only whether the agent technically had access. It’s whether the person granting that access understood what the agent could do with it.
As Muse expands into business software, third-party services and AI glasses, enterprises are likely to encounter more versions of the same question. Meta has already announced that Muse is coming to its AI glasses alongside a growing range of shopping, payment, travel and productivity connections.
EM360Tech will continue following how agentic AI changes the technology, security and governance decisions behind these deployments, and what organisations can learn as autonomous agents move deeper into everyday operations.
Comments ( 0 )