This review draws on Meta’s documentation and Help Center plus published third-party testing, as of September 28, 2026. We have not tested Muse hands-on, and the ratings are provisional.
Meta launched Muse in the US on September 8, 2026, and in Canada ten days later. It’s a personal AI agent, and Meta means the “personal” part. Each user’s Muse lives in its own cloud virtual machine, a Linux environment with a Chromium-based browser, and works across whatever apps that person connects. People reach it through the iOS and Android apps, on the web at muse.ai, in WhatsApp or through a Mac app that shipped September 17. Meta still calls Muse a limited test, and availability varies by location.
It spread fast. Sensor Tower counted 2.5 million downloads in the first 13 days, and Muse reached No. 1 among free iPhone apps in the US.
On September 28, Meta announced Meta Enterprise Platform, a new business unit that will initially bring Muse, Meta Business Agent, the Muse API and Muse Code to companies. Chirantan “CJ” Desai, formerly MongoDB’s president and CEO, will lead it as Chief Enterprise Platform Officer. The announcement gave business customers no availability date. Pricing and admin controls weren’t covered either.
For now, Muse is a consumer product.
Paid subscribers must be 18 or the age of majority where they live, and we found no publicly documented team workspace or central IT admin console. That leaves B2B companies facing what we’d call the bring-your-own-agent problem. The question is less whether to roll Muse out and more what happens when your people install it on their own.
What It Does Well
- Setup that feels like messaging: You talk to Muse the way you’d text a person. Apps get connected one at a time, either by asking (“connect my Gmail”) or through Settings. There’s no conventional visual workflow builder, though Muse can create scheduled tasks, custom skills and its own connectors.
- Checkout with a person in the loop: Muse can work through a checkout and prepare the purchase, and Meta says every payment stops for your approval with the exact details on screen. Where your card isn’t on file, Muse pays through Link by Stripe. Link issues a single-use card number tied to one merchant and one amount, and the number expires after a short window. Meta says Muse is the first agent covered by Link’s purchase protections on eligible purchases.
- Scoped permissions: Sending an email or making a purchase brings up an approval prompt. Grants come in five kinds (one-time, session, task, time-bounded and permanent), and Meta says read-only or already approved actions can run without a new prompt. Where a service supports it, you can let Muse read an inbox without letting it send. The email connector also filters out one-time passcodes, password-reset links and magic login links, so inbox access doesn’t hand the agent a way into your other accounts.
- Background work with a record: Long tasks keep running after the app closes. Each user gets an activity log showing what Muse has done and what it plans to do next.
How Each Role Puts It to Work
- Operations: Governance is the first job. Pull the list of third-party apps with access to your Google Workspace or Microsoft 365 tenant and check it for Muse. Then decide whether Muse belongs on corporate accounts. OAuth grants won’t tell the whole story. An API key an employee hands to Muse creates no OAuth grant, so check API-key issuance logs and service-side audit logs too. At a ten-person firm with no IT function, Muse can also pick up admin work like vendor forms or rebooking travel when a flight moves. At Connect, Meta pitched its coming Mac computer-use feature partly as help for running a small business.
- Salesperson: For a seller who lives on the road, or a solo consultant, the useful jobs are small ones:
- Find a new slot when a client meeting slips.
- Book the client dinner through OpenTable.
- Draft a follow-up from the Gmail thread and hold it until you approve it.
Granola, the meeting-notes app, was among the connectors Meta named at Connect, which could help with post-call follow-ups. Meta’s launch and Connect announcements named no Salesforce or HubSpot connector. Community-built CRM connectors exist, but Meta doesn’t review custom connectors, so any CRM hookup should clear IT first.
- Higher-risk or less-developed fits: Researchers, HR teams and finance leaders should keep client interviews, candidate records, employee data and company financials out of an unapproved consumer agent. Muse’s model-training setting starts switched on. Users can turn it off, and Meta says that before training it strips specified personal identifiers and separates interactions from the account. Marketers get connections to Facebook, Instagram, Threads and Messenger. Meta hasn’t announced any ad-management or marketing-analytics connectors.
Where It Could Be Better
The biggest gap for a business is structural. VentureBeat reported on September 22 that it found no IT admin console, SIEM audit export or DLP integration in Muse’s launch documentation or in the consumer product it tested. Each activity log belongs to one user, which leaves your security team with no central view of what an employee’s agent touched.
Meta’s own security write-up is candid about operator access. Today’s architecture limits Meta staff access through operational policy, and Meta says it doesn’t prevent the company from reaching user data when needed to support, secure or operate the service. The Confidential VM planned for later this year is meant to close that gap with encryption.
Some websites don’t want an agent there at all. In late September Amazon blocked Muse from shopping on Amazon.com. Amazon said Meta never asked permission and that the agent doesn’t identify itself as automated. It also said Muse appeared to store customer credentials. That fight is a consumer story for now. For a business, it’s a warning that an employee’s agent working inside a vendor portal could run afoul of that site’s terms of use.
Custom connectors carry their own risk. Muse can build one for any service with a suitable API or CLI, and Meta says it reviews neither those connectors nor how the connected providers use your information. Your exposure depends on the code Muse generates and the permissions you give it. It also depends on the service at the other end.
The Mac app has already had one security scare. Researcher Patrick Wardle disclosed a flaw that let code already running as the logged-in user redirect dictation traffic and capture Muse authentication material, with no special macOS permissions needed. Meta hot-fixed it within a day. The flaw didn’t break Muse’s cloud-VM isolation or its Sentinel controls. A captured token could still have let an attacker take over the victim’s Muse session and use whatever capabilities that user had already approved.
Meta says plainly that Muse will make mistakes and that prompt injection is an unsolved problem. Early outside tests line up with that. In a Tom’s Guide personal-shopping test, three of seven prompts worked. A Lenny’s Newsletter test watched Muse return wrong results and fail to finish a sneaker purchase. Two reviewers is a small sample. Still, both ran into trouble with shopping, which Meta calls one of the most popular things people use Muse’s browser for.
Pricing is hard to map onto real work. Power costs $20 a month for 500 million Muse tokens a week, and Maximum costs $100 a month for 3 billion. Meta hasn’t said how many tokens a typical week of tasks burns.
Why Not Just Use ChatGPT, Gemini, or Claude?
For organization-wide knowledge work, the business tiers of ChatGPT, Claude and Gemini come with better-documented administration and governance today. ChatGPT’s agent mode also runs its own cloud browser and connects to Gmail and Google Calendar. It’s available in more countries, too.
Muse’s clearest differentiators are its built-in payment flow and its design as an always-on personal agent with consumer-service connectors. Those help most with personal errands. We haven’t tested whether Muse is easier to use than its rivals.
Security & Compliance
What Meta documents:
- Each user gets a dedicated cloud VM. The agent runs in an isolated container inside it, walled off from the security services.
- OAuth tokens and passwords sit in a separate credential store inside the user’s VM. The agent works with stand-in tokens, and the real credential is swapped in only after a request is approved.
- A separate process called Sentinel is the sole authority for connector actions and outbound network traffic.
- Meta says Muse conversations and VM data aren’t shared with its ad systems. It also notes that Muse’s browsing counts as your activity on third-party sites, which can indirectly shape the ads you see.
- The model-improvement setting is on when you first start Muse. You can switch it off under Data controls, and Meta says the change also covers past interactions.
- Meta runs a public bug bounty for Muse that pays up to $300,000 for valid reports, prompt injection included.
- Meta plans a Confidential VM later in 2026, encrypted with a key only the user holds so that Meta can’t reach the data. It isn’t available yet.
What we couldn’t locate: as of September 28, 2026, we found no Muse-specific public documentation confirming SOC 2 or ISO 27001 attestation, a HIPAA/BAA offering, SSO, SCIM or role-based access control. Treat each as an open diligence question for Meta before anyone connects a corporate account.
Data & AI Connectivity
Connectors named at launch include Gmail, Google Calendar, Google Docs, Outlook, Plaid, OpenTable, Spotify and Peloton. Meta’s own apps (Facebook, Instagram, Threads and Messenger) connect through Accounts Center. At Connect, Meta named GitHub, Granola, Notion and Expedia as connectors and announced retail partnerships with Best Buy, Gap, Sephora, Walmart and Wayfair, with Instacart coming. The announcement didn’t establish that every integration is live in every account. Meta has also opened a developer platform for third-party connectors and says it got more than 1,500 applications in under a week.
For anything else, Muse can build a custom connector against a suitable API or CLI, and it falls back to the browser when there’s none. With macOS permissions, the Mac app can work with local files, Messages, Notes, Reminders, Mail and Calendar. Meta has announced that Muse will soon be able to operate any Mac app and that it’s working on giving Muse its own email address.
Meta’s launch and Connect announcements didn’t name Salesforce, HubSpot, a major data warehouse or an advertising-management platform as a native connector. Meta publishes no fixed, complete connector list and is adding integrations quickly, so treat that as a snapshot from September 28.
Teams that want Meta’s model inside their own tools can use the Meta Model API instead of the app. On the Standard tier, Muse Spark 1.3 costs $1.25 per million input tokens ($0.15 cached) and $4.25 per million output tokens, and your prompts aren’t used for training. The Contributor tier drops that to $0.10 input ($0.002 cached) and $0.20 output in exchange for letting Meta train on your prompts and completions. Anyone handling client data should stay on Standard.
Ratings (provisional)
| Dimension | Rating | Rationale |
|---|---|---|
| Usability | 4.0 / 5 | Built around messaging and one-at-a-time connector setup. We haven’t tested it hands-on. |
| Power | 3.0 / 5 | Meta documents a capable, well-sandboxed agent, but early third-party tests of browser tasks are mixed. |
| Flexibility | 2.5 / 5 | Connectors are expanding (Notion, GitHub, Granola), but there are no documented team features or native CRM or ad connectors. |
| Cost | 3.5 / 5 | A free tier exists with a limit the Help Center doesn’t quantify. Power is $20/month for 500M weekly Muse tokens and Maximum is $100/month for 3B. No team pricing is published. |
Best-Fit Roles
It can help individual sellers and small-firm operators with their own admin work. For everyone else in a B2B company, it’s a governance item for Operations and IT.
Conclusion
Muse packs a dedicated cloud computer, scoped permissions, approval gates and a payment flow into one consumer agent, and Meta has published a detailed account of how it’s built. That account is Meta’s own. No independent compliance audit has been made public.
Meta Enterprise Platform may turn Muse into a business product, but the September 28 announcement came without a business launch date. Pricing and admin controls went unaddressed as well. Until those arrive and hold up to scrutiny, handle the bring-your-own-agent problem the way you’d handle any shadow AI. Watch OAuth grants and API-key issuance, and restrict corporate-account connections where policy calls for it. If you allow experiments, keep them to low-sensitivity tasks with read-only access and training switched off. A person should approve every send and every purchase.
Last updated: 9/28/2026.