Muse wants your inbox, your browser, and your $100/month trust

Muse wants your inbox, your browser, and your $100/month trust

Meta's Muse is a persistent cloud operator with serious safety gates, but its $100 plan and default cloud and training boundary make the trust decision larger than the chatbot pitch.

"Your purpose is to make your user's life better." Muse's version of a better life comes with its own cloud computer, browser, inbox access, payment flow, and a monthly bill that can reach $100. 1
Meta launched Muse for U.S. users on September 8, 2026, through the web, iOS, Android, and WhatsApp. Meta describes it as a personal agent for everyday tasks and long-running goals. 1
The pitch is simple: tell Muse what you want, then leave it alone. The architecture is less like a chatbot and more like renting a remote employee a computer. That distinction is where the product gets interesting, expensive, and slightly uncomfortable.

The product is a remote operator, not a chatbot

Muse runs inside a dedicated Linux virtual machine with its own browser, file system, storage, CPU, and memory. Meta says the machine can compile code, create tools, run concurrent sub-agents, and schedule recurring work. 2
The browser matters more than the chat box. Muse can search websites, navigate pages, fill forms, send emails, book travel, and complete purchases. The product can also create documents, PDFs, web pages, trackers, study guides, and dashboards as interactive "Artifacts." 3
Muse keeps working after the user leaves the app. A user can give it a goal, let it track dates or tasks, and receive a message when Muse decides that something is worth surfacing. The product also supports side chats for separate projects, persistent memory, and an activity view that shows what the agent is doing. 3
Muse's official approval interface shows an agent preparing a purchase and waiting for permission.
The approval screen is Meta's product material, not an independent test. It shows the intended flow for a purchase: product details, a payment method, a total, and an Allow or Deny decision. 4
That persistence solves a real problem. A chatbot waits for the next prompt. Muse is designed to watch a goal, gather information, and return when the next step appears. The trade is equally clear: a product that keeps acting while the user is away needs more than a good answer. It needs a permission model that can survive bad instructions, malicious web pages, and its own mistakes.

The safety architecture is real

Meta built Muse around two separated security domains. The agent runs inside a restricted runtime cell. Credential storage, connector workers, safety classifiers, database state, and network controls sit outside that cell. Root inside the runtime cell is mapped to an unprivileged host user, and the cell has filtered system calls and limited kernel capabilities. 2
The split answers a practical question: what happens when a web page tells the agent to leak a password or change its task? The agent does not receive the real credentials. Meta says authd stores OAuth tokens outside the runtime cell, while connector workers use tightly scoped permissions. Muse receives surrogate tokens, and Sentinel inserts the real credential only after the request passes the relevant checks. 2
Sentinel is the gatekeeper for connector actions and network traffic. It can allow, deny, or ask the user about an action after checking the connector, destination, method, path, request context, and policy. When a user approval is needed, the approval arrives directly in the Muse client rather than as a conversational suggestion from Muse. 2
The arrangement is more serious than the usual "we added a confirmation button" story. Meta has put the confirmation authority outside the model's process, added network inspection, and limited the credentials that agent code can touch.
Meta's official architecture diagram separates the user's VM, runtime cell, credential storage, Sentinel, model inference, and external services.
Meta's diagram shows the vendor's intended architecture. The important boundary is visible: the runtime cell can request work, while host-side services decide whether credentials and network access are available. 2
Purchases get another restriction. Meta says Muse asks for human approval at checkout and uses a single-use card number tied to the merchant, amount, and a limited time window. Stripe Link handles the launch payment partnership, while Shop Pay is planned for later. 2
This architecture reduces the damage an agent can cause. It does not make the agent correct. Meta says prompt injection remains an open problem and that Muse will still make mistakes. The product's answer is to contain those mistakes and interrupt the expensive ones. 2

The trust boundary still ends at Meta's cloud

Muse's security story is about limiting what the agent can do inside Meta's infrastructure. It is not a local-first story.
Meta says the user's dedicated VM is the system of record for files, generated work, memory, credentials, and connected-service tokens. The VM is backed up continuously. Meta also says its personnel may access data when necessary to support, secure, or operate the service. 2
Meta says Muse conversations and VM data are kept out of Meta's ad systems. The company also says browsing performed by Muse can influence ads indirectly because a merchant may treat the visit as the user's activity. That is a narrower promise than "Meta never learns anything from the agent." 2
The training policy is just as important. Meta says conversations, tool calls, and sub-agent handoffs, which it calls trajectories, can help train new model checkpoints after personal identifiers are sanitized. Users can opt out with a setting in Muse. 2
Meta is also building a Confidential VM that is intended to prevent Meta from accessing the user's data cryptographically and verifiably. The company says that version is planned for later in 2026 and is already being tested with a small group. It is a future product boundary, not the boundary users get at launch. 2
That leaves Muse in an awkward middle ground. The model cannot see your real password. Meta's cloud still stores the surrounding world that makes the task possible, and Meta retains operational access under its stated policy. The lock is inside the house. Meta still owns the house.

The free tier comes with a card attached

Muse is free to use at launch, but Meta requires a payment card to get started. TechCrunch reports two paid plans: Power at $20 per month and Maximum at $100 per month. Meta uses a usage meter and warns users when the free allowance runs out, but the launch report does not give a public task quota that lets a buyer estimate a monthly workload. 1
The price is not really for chat. The price is for delegation: a computer that keeps running, opens websites, watches goals, stores context, and waits for approval when money or reputation is at stake. A $20 plan can be reasonable for someone who would otherwise spend hours on repetitive personal administration. A $100 plan asks the buyer to treat a general-purpose cloud operator as a household utility.
Muse fits a user who wants an always-on task runner and accepts Meta as the provider of the computer, storage, connectors, model, and safety gate. Muse fits poorly when the user's first requirement is local execution, provider-blind data handling, or a hard guarantee that personal trajectories stay outside model training.

Verdict

Muse is a serious attempt to turn a chatbot into a supervised remote operator. Its separate runtime, credential broker, network gate, and approval flow are real engineering choices, not a privacy badge pasted onto a chat window. The catch is that those controls protect a cloud computer holding your personal context; they do not remove Meta from the trust chain, and the default training policy still includes sanitized agent trajectories unless the user opts out. The free tier is a demo with a payment card, the $20 plan is a bet on routine delegation, and the $100 plan is a bet that Meta deserves to run a second computer for your life. Muse is worth trying for low-stakes tasks when the time saved matters more than the provider boundary. It is a poor fit for anyone who wanted a personal agent that was personal all the way down.

This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.

Related content

More from this channel