Back to FeedTechnology

Meta launches Muse AI agent for tasks across connected apps

Meta launched Muse in the United States, an action-taking personal AI agent that can work across connected apps while a separate Sentinel system controls permissions.

3 min read|Mefico News News Desk|
Aa
AI core inside a secure virtual chamber with controlled connections to email, calendar, travel and document tasks
Representative image generated with artificial intelligence.

Meta launched Muse, a personal artificial intelligence agent designed to take action across connected apps, in the United States on September 8, 2026. According to the company, Muse can do more than answer questions: it can prepare and send emails, help plan travel, fill in forms and carry out approved tasks through linked services. The initial release is available to people aged 18 and over through a dedicated Muse app and WhatsApp.

Meta is positioning Muse as a step beyond the conventional chatbot. Instead of producing a single response to a prompt, the agent is intended to break longer jobs into steps, connect with different services and continue working in the background. Reporting by Reuters, the Associated Press and Axios says the system can interact with workflows involving email, calendars, shopping and travel. The exact capabilities depend on which services a person connects and which permissions are granted.

How Muse Secure VM and Sentinel work

Meta’s technical explanation describes two central parts of the security architecture. Each Muse instance runs inside a separated virtual machine called Muse Secure VM. The environment is designed to isolate the agent’s browser and connected application data from other sessions. A second component, Sentinel, operates separately from Muse and acts as a permission authority. When Muse proposes an action through a connector, Sentinel evaluates whether network access or the requested connector operation should be allowed.

The company also says OAuth tokens for third-party services are stored in a separate credential component, while the main agent does not directly see passwords or payment methods. Users can revoke access to connected applications and review records of completed actions. These are Meta’s claims about its own system; independent security testing under real-world conditions will become increasingly important as the service reaches more users and services.

Security questions are central to the launch

Reuters reported that Muse arrived later than originally planned because Meta carried out additional security work. The report also described concerns raised during internal testing, including disconnections, data transfers that users had not requested and possible exposure of sensitive information. Meta said the product meets its safety and privacy standards while acknowledging that artificial intelligence systems can still make mistakes.

That distinction explains why action-taking agents require a higher safety threshold than ordinary chatbots. A wrong text answer can often be corrected before it has any effect. Sending an email, completing a form or initiating a payment step can create an immediate real-world consequence. Narrow permissions, clear user confirmation for sensitive actions and understandable activity logs will therefore be important if Muse is to gain trust.

AI competition is shifting from answers to actions

The release reflects a broader change in the artificial intelligence market. Major technology companies are trying to move beyond assistants that summarize information toward agents that can complete multi-step tasks. Meta is combining its Muse Spark models with application connectors in an effort to offer an agent that does not require technical expertise. Starting only in the United States gives the company a smaller market in which to monitor reliability, safety and user behavior.

Muse’s success will not be measured only by whether it finishes tasks. It will also depend on whether people are comfortable connecting personal communications, calendars, shopping data and other services to a Meta product. The company says conversations and connected data are not shared with its advertising systems, but Meta’s history makes independent scrutiny and transparent controls especially significant.

Muse makes the transition from an assistant that recommends actions to an agent that performs approved actions more visible. That change could reduce routine work, but it also expands questions about privacy, accountability and control. The product’s early performance, the clarity of its permission system and the speed with which Meta addresses reported failures will shape whether personal AI agents become a mainstream service or remain a feature used cautiously by a limited audience.

Sources

This article was prepared with AI assistance and its sources were checked by the Mefico News News Desk.

Like/dislike buttons become active once you finish reading the article.