Onpode
Cover art for Meta just rolled out Muse, an AI agent that autonomously sends emails and books travel

Meta just rolled out Muse, an AI agent that autonomously sends emails and books travel

September 9, 2026 · 9 min

Eliza Ward & Brian Reed

Meta launched Muse, a personal AI agent, on September 8th — it autonomously sends emails, books travel, and makes purchases via one-time virtual cards through Link by Stripe, running on background execution even after users close the app. Reuters reported internal data-mishandling concerns before launch; Meta shipped anyway, with opt-out training data defaults.

On September 8, 2026, Meta launched Muse, a personal AI agent designed to autonomously execute real-world tasks on behalf of users rather than simply answer questions. Muse is available in the United States via a dedicated iOS and Android app, a web interface at Muse.ai, and through WhatsApp direct messaging; Meta has indicated it will also be accessible through its AI smart glasses "soon."

0:009:27
Get the next episode on Artificial Intelligence

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Artificial Intelligence

About this episode

Meta launched Muse on September 8th — a personal AI agent that sends emails, books travel, makes purchases, and negotiates on your behalf, then keeps running after you close the app. It surfaces only when it needs your approval. That's a genuinely different user experience from anything a chatbot does. The episode doesn't spend much time on the feature list. It spends time on what actually matters: the gap between Meta's claimed safeguards and any independent verification of them. Reuters reported internal concerns about Muse mismanaging access to sensitive personal data before launch. Meta shipped anyway, to every U.S. user over 18, with inbox, calendar, health data, and payment access all in scope. There's also the opt-out default — users have to actively choose to stop Meta from training on their Muse interactions — and the distribution asymmetry that makes user skepticism largely academic. Through WhatsApp alone, Muse reaches a scale no competitor's agent tool is close to. OpenAI, Google, Anthropic, and Microsoft are mostly business- or developer-facing. Muse is free, frictionless, and already there. What the episode keeps returning to is a specific, concrete question: does Meta publish an independent audit of its VM architecture before the first significant public failure, or after? Because those are very different trust positions — and right now, no audit has been announced.

Frequently asked

What is Meta Muse and what can it do?

Meta Muse is a personal AI agent that autonomously sends emails, books travel, makes purchases using one-time virtual cards through Link by Stripe, and negotiates bills — all while running in the background after users close the app. It operates on Meta's Muse Spark model, built specifically for agentic, not conversational, work.

Is Meta Muse available now and where can I use it?

Meta Muse launched on September 8th and is live on iOS, Android, WhatsApp, and Muse.ai for U.S. users over 18. A free tier offers 100 million tokens per week before hitting the paid automation tier. WhatsApp distribution gives Muse immediate access to billions of existing users with zero download friction.

What are the privacy risks of using Meta Muse?

Meta Muse defaults to using interactions — including flight searches, health data touches, and bill negotiations — to train its Muse Spark model. Users must actively opt out. Reuters also reported internal concerns about Muse mismanaging sensitive personal data before launch, yet Meta proceeded with a full U.S. release.

How is Meta Muse different from OpenAI, Google, and Anthropic AI agents?

Meta Muse's core agentic capabilities are similar to tools from OpenAI, Google, Anthropic, and Microsoft, according to The Verge. The key differentiator is distribution: Muse is embedded in WhatsApp, giving it access to billions of existing users — a scale no competitor's agent tool currently reaches.

Has Meta Muse been independently audited for security?

No independent audit of Meta Muse's security architecture has been announced. Meta claims isolated virtual machines per user and one-time virtual cards via Link by Stripe, but those are Meta's own claims about its own product. No third-party review has been cited, and Reuters reported internal data-mishandling concerns before launch.

Grounded in 12 sources
Meta launches personal AI agent, Muse, emphasizes safety and privacy - AP News · apnews.com
Meta debuts Muse, its long-planned personal AI agent - axios.com · axios.com
Meta pushes into personal AI agents as company faces public reckoning over privacy and safety · cnbc.com
Meta Introduces Muse, an A.I. Agent That Can Send Your Emails and Book Your Travel · nytimes.com
Meta launches personal AI agent, Muse, to help with everyday tasks · pbs.org
Meta launches AI agent that can access other apps to send emails, make payments · reuters.com
Meta Launches a Personal AI Agent Designed to Be Easy to Use · wsj.com
Meta launches Muse, a personal AI agent that books, buys and negotiates for you - The Next Web · thenextweb.com
Meta bets on AI agent Muse to catch up in AI race - The Verge · theverge.com
Muse, Meta’s New Personal AI Agent, Needs You to Trust It - WIRED · wired.com
Introducing Muse: The World’s First Personal AI Agent Built for Everyone · about.fb.com
Muse – Meta’s personal AI agent · ai.meta.com
Read transcript

Eliza Ward: Hey. Good to be back.

Brian Reed: Yeah, good. Though I have to say — I've been sitting with something all morning that I can't quite shake.

Eliza Ward: Meta shipped Muse. September 8th. Yesterday.

Brian Reed: That's the one. And the way I'd describe it — imagine giving a very capable friend access to your email, your calendar, your bank account. And then closing the app while they handle it.

Eliza Ward: That's — yeah, that's actually exactly it. This isn't a chatbot. Muse does things. Books travel, sends emails, makes purchases using one-time virtual cards through Link by Stripe.

Brian Reed: And it runs on Muse Spark — Meta's most capable model to date, built specifically for agentic work. Not just answering questions. Acting.

Eliza Ward: It's live on iOS, Android, WhatsApp, and Muse.ai. Free tier, paid tier for heavy automation. The distribution alone is — wait, that's actually the thing worth sitting with.

Brian Reed: The reach. Right. Through WhatsApp alone that's already global.

Eliza Ward: And that reach is actually where I want to slow down on the 'first ever' claim — because The Verge basically said Muse is very similar to what OpenAI, Google, Anthropic, and Microsoft already have. So what's Meta actually claiming here?

Brian Reed: That's — yeah, that's the part that needs pulling apart. Because 'world's first personal AI agent built for everyone' is doing a lot of work in that sentence. OpenAI has agent tools, Google has agent tools, Anthropic has Claude Cowork. So if you strip the framing, what's left?

Eliza Ward: The background execution. That's actually new in terms of UX.

Brian Reed: Say more — because this is the thing that stands out to me. Muse keeps working after you close the app. It only surfaces again when it needs your approval. No chatbot does that. That's not a subtle distinction.

Eliza Ward: Right — it's the difference between a tool you operate and something acting on your behalf while you're not watching. Which is either very useful or — actually, the framing depends on whether you trust the entity doing it.

Brian Reed: And that entity is Meta Superintelligence Labs — the unit Zuckerberg stood up roughly a year before this launch, specifically to chase OpenAI and Anthropic at the frontier. This wasn't a side project. It was a competitive response.

Eliza Ward: Zuckerberg put societal-scale language around it publicly. Which — okay, that's a big frame for a product that's, wait, also available free through WhatsApp. But that WhatsApp on-ramp is genuinely different. That's billions of existing users, zero download friction.

Brian Reed: So the technology may not be unique. The distribution absolutely is. And that's what sets up every harder question that follows — because at WhatsApp scale, even a small percentage of users is an enormous number of people handing autonomous access to an agent Meta built.

Eliza Ward: And that scale is exactly where the take I keep seeing falls apart — the one that says Meta's safeguards are adequate because they sound technically reasonable. Isolated virtual machines per user, one-time virtual cards through Link by Stripe. That architecture might be fine. But here's what actually happened: Reuters reported internal concerns about Muse mismanaging access to sensitive personal data before launch. Meta launched anyway. Full release.

Brian Reed: Wait — before launch? Not after some beta period?

Eliza Ward: Before. One Reuters piece. And then Meta ships it to every U.S. user over 18 — which is itself telling, the age restriction signals Meta knows the risk surface — with inbox access, calendar access, health data, payment systems. All of it.

Brian Reed: So the question isn't whether isolated VMs are technically sound. It's — hang on — it's that we have no way to verify any of it. No independent audit. No third-party review cited anywhere. That's Meta's claim about Meta's own security.

Eliza Ward: Which is the whole problem. And then layer the opt-out default on top. Users have to actively opt out to stop Meta from using their Muse interactions to train models. We're talking about data from someone booking a flight, negotiating a medical bill — and the default is Meta gets it. Every major platform moved toward opt-in after Cambridge Analytica. Meta went the other direction. That's not an oversight.

Brian Reed: No, I don't buy that it's accidental either. But — let me test the weaker version of this — is part of what's troubling us just that it's Meta making the claim? Because if Google said 'isolated VMs, no cross-user data,' would we accept it faster?

Eliza Ward: That's actually the right question. And my answer is — maybe, but the Reuters reporting changes it. This isn't 'uncomfortable because it's Meta.' It's 'Meta had a specific internal flag about data mishandling and shipped anyway.' That's a different category.

Brian Reed: Right — one is about track record, one is about this specific product, this specific warning. And those don't resolve the same way.

Eliza Ward: Neither does. And the part I think we still need to get to — whether WhatsApp distribution just makes user skepticism irrelevant in practice, and what happens the first time Muse autonomously makes a costly mistake — that's where this either holds or breaks.

Brian Reed: The costly mistake scenario is where that actually cashes out. So picture someone — Friday afternoon, they're at work, they delegate a medical bill negotiation and a flight rebook to Muse and they close the app. Muse keeps running. It's still acting. And then, I mean, what if it books the wrong fare? Or negotiates a settlement rate on that bill that locks in before the person even sees it? Via Link by Stripe on a one-time card. The action is already done.

Eliza Ward: And the recourse spans — what, email, WhatsApp, the Muse app, the airline's own system, Stripe. That's not one conversation.

Brian Reed: Right, and none of Meta's competitors have that surface problem at the same scale — because none of them have WhatsApp. OpenAI, Google, Anthropic, Microsoft — their agent tools are mostly business or developer-facing. Muse lands in the app a billion people already use to text their families.

Eliza Ward: Which is exactly the distribution asymmetry. That's not a feature gap — that's a different adoption curve entirely.

Brian Reed: And the free tier accelerates it. A hundred million tokens a week before you hit paid. That is not targeting developers. That is targeting — actually, no, that's eliminating the friction for anyone who would have said 'I don't want to pay for this.'

Eliza Ward: So user skepticism — the privacy concerns, the Reuters flag about data mishandling before launch — does any of that actually slow adoption? Or does convenience just absorb it?

Brian Reed: I think it gets absorbed until the first public failure. And when that happens — a wrong booking, a bad negotiation, whatever — that's the moment that shows whether Meta's support architecture across all those integrated surfaces actually works.

Eliza Ward: And by then, the opt-out training default means millions of those interactions — the flight queries, the health data touches — have already fed Muse Spark's next version. That's the asymmetry that doesn't reverse.

Brian Reed: So the concrete thing to watch is: does Meta publish an independent audit of the VM architecture before that first public mistake surfaces — or after? Because those are very different trust positions.

Eliza Ward: And that's — yeah, that's actually where I land. Not 'is Muse dangerous in theory.' It's: Muse launched September 8th, it's already in people's hands through WhatsApp, and we have no independent check on whether the architecture holds. That's the confirmed state. Everything else — whether the first failure comes before the behavior is embedded — that's genuinely open. I don't know the answer.

Brian Reed: What I'm watching is the sequence. Because Zuckerberg framed this in broad societal terms — which is, I mean, that's a lot of weight to put on a product where the design, by Wang's own description, prioritizes low friction over deliberate user understanding. Those two things don't sit easily next to each other. And if the first significant public mistake arrives before anyone's asked for an audit — that's not recoverable in the same way.

Eliza Ward: No independent audit announced. That's the gap.

Brian Reed: That's the gap. And we're not wrapping this up — because it isn't.

Meta just rolled out Muse, an AI agent that autonomously sends emails and books travel · Onpode