Meta Brings Muse Personal Agent to US Users Across Apps
Meta launched Muse in the United States as a hosted personal agent that can act across connected apps, with approval gates and a dedicated secure virtual machine.
Meta has launched Muse, a personal AI agent rolling out in the United States across iOS, Android, and muse.ai. It is designed to take action on a user’s behalf rather than only answer questions, using Meta’s Muse Spark model.
Muse runs on Muse Secure VM, a dedicated virtual machine that houses the agent and a user’s data. Meta says it can work across connected everyday apps and services, while users choose which connections to enable and how much access to grant.
The agent can handle tasks such as sending email or booking travel, but Meta says it checks with the user before sensitive actions such as sending an email or making a purchase. It also provides an audit trail of actions taken and planned. Users can change permissions, disconnect services, and opt out of having their interactions used to train Meta’s AI models.
Meta says Muse does not have visibility into passwords or payment methods. Credentials are stored securely for use by the agent. The company also says conversations and VM data are not shared with its advertising systems.
A future Muse Confidential VM is planned for later in 2026. Meta says it will encrypt the entire VM, including data and conversations, with a key held only by the user, so that Meta cannot access it.
The rollout moves Muse from a conventional chat assistant toward a hosted action layer for personal tasks. Its usefulness will depend on whether it can maintain context across connected services while keeping users informed about actions that affect communications, purchases, or private data.
The current rollout is limited to the United States and is hosted on Meta’s infrastructure. Meta says the service is free for most needs, with subscription plans for users who want more.
Why it matters: personal agents gain much richer context when they can act across services, but the same access turns ordinary mistakes into privacy, communication, and financial risks. Muse’s permission and approval design may matter as much as Muse Spark’s model capability.
Uncle Cat take
Muse’s differentiator is delegated action across connected apps, while its unresolved liability is that a hosted agent remains between users and their private data.