Handing an agent your inbox and your wallet sounds reckless until you look at how the thing is actually built. Meta launched Muse in the United States on September 8, 2026: a personal AI agent that reads your goal, splits it into steps, and carries them out across your connected accounts. It drafts and sends email, books travel, shops, fills forms, and keeps long-term plans moving while the app is closed. It runs on the Muse Spark model family from Meta Superintelligence Labs, on a free tier plus paid subscriptions that several outlets reported starting around $20 a month.
The interesting part is not the task list. It is the containment. Every user gets an isolated cloud VM. A separate safety agent called Sentinel reviews what Muse does. Payments go through Stripe Link one-time card numbers, so the model never touches your real card. Sensitive actions, like sending an email or completing a purchase, stop and ask you first. Low-risk steps run on their own.
That architecture is why this launch is worth thirty minutes of your attention even if you never install the app. Muse is the clearest template yet for how consumer agents will balance autonomy against trust, and the same pattern is about to reach the tools you use at work. Before you let any agent act for you, run the review below.
Who this is for, and what done looks like
You want this if you would hand a competent assistant real accounts: an inbox, a calendar, a shopping profile. The outcome of this guide is a Muse (or any consumer agent) configured so that you can name, right now, what it is allowed to do alone, what it must confirm, and what it cannot touch. Prerequisites: a US account, the app or muse.ai, and about twenty minutes. Done means you have completed one low-risk task end to end and checked each of the five gates in the map below.
The permission map: five gates to review
Capability | How it works today | What can go wrong | What to check first |
|---|---|---|---|
Email and calendar | Drafts and sends email, schedules and books travel | Wrong recipient, double booking, tone you did not approve | Which accounts are connected; whether send requires your confirmation |
Shopping and payments | Buys through a built-in browser; pays with a Stripe Link one-time card number | Unwanted orders, returns hassle | Order confirmation behavior; any spending cap on offer |
Connectors | Links Google Workspace, Ticketmaster, Spotify, Apple Health; Meta says it can even write its own connectors from public APIs | Over-broad access to accounts you forgot about | Revoke every connector you do not actively need |
Memory | Stores preferences you allow, like diets or taste, and reuses them in plans | Stale memory quietly steering new decisions | Read the memory list, delete anything wrong or sensitive |
Autonomous runs | Tasks continue after you close the app; Muse checks back when status changes | A stalled task repeating itself at the worst moment | Notification settings; how to pause or cancel a running task |
Keep this table next to you during setup. It maps to the exact screens you will see, and it doubles as the audit list for the next agent product that copies this design, because one will.
The 20-minute trust review
Inventory your connections. Open settings and list every connected account with the permissions it granted. Quality check: nothing on the list is an account you would not hand to a human assistant. Recovery: disconnect first, decide later.
Set the confirmation gates. Leave sensitive-action confirmations on, which is the default. Verify them: have Muse draft an email to yourself and watch whether it stops for approval before sending. If an agent ever offers to batch-confirm, read that screen twice.
Read the memory and prune it. Memory is what makes an agent useful and what makes it confidently wrong. Quality check: nothing in there would embarrass you read aloud. Delete stale entries rather than editing around them.
Decide your data posture. Meta says you can opt out of having interactions train its models, and that conversations are not shared with the ads system, while purchases may still influence ads indirectly. Choose deliberately instead of accepting defaults, and note the choice, because the data posture is the first thing people forget they set.
Rehearse one low-risk task. Pick something reversible: build a shopping list from saved recipes, or draft a plan for a trip you have not booked. Quality check: the task completed and the agent paused exactly where you expected. That pause point, not the marketing page, is your real trust boundary.

The five checks, in the order that catches problems earliest.
What a consumer agent changes for AI visibility
Here is the part most coverage skips. An agent that acts is also an agent that reads, and everything it reads comes from the open web. When Muse books your trip or buys your supplies, it is interpreting pages, product data, and policies that someone published. That makes consumer agents a new reader class for your site, and the audit routine for agent-written content applies here in reverse: instead of checking what agents wrote, you check what they can read. Three practical consequences.
Offers must be machine-readable. Price, availability, shipping, and returns that live inside an image or a paragraph of marketing copy are friction for an agent deciding whether to buy. Structured product data is no longer just a rich-result play; it is purchase infrastructure.
Entity consistency decides who gets picked. An agent resolving "which vendor is this?" across your site, your listings, and third-party profiles behaves like an answer engine. Same name, same facts, same claims everywhere, or the agent hedge-bets and picks the competitor it could verify. The citation base that AI answers lean on by industry is the same evidence surface an acting agent consults before it commits.
Public interfaces become discoverable surfaces. Meta says Muse can build its own connectors from public APIs. A documented feed or API is therefore not only an integration convenience; it is a channel an agent can find and use without your sales team in the loop. Publish machine-readable facts the way you already publish human-readable ones, and measure whether agents can complete a task on your site, not just whether they cite it.
Limits worth stating plainly
Muse is US-only and adults-only at launch, so treat it as an early signal rather than a global default. Pricing beyond the free tier comes from press reports, not from a page you can verify in every market. The security architecture, including the isolated VM and Sentinel, is Meta's own description; independent audits do not exist yet. And the sensible floor stands regardless of architecture: never connect an account whose compromise would ruin your week, and review the memory after the first month, when stale preferences start to accumulate.
FAQ
Is Muse free?
There is a free tier, and paid subscriptions reported starting around $20 per month. Check the current tiers in the app, since promotional pricing at launch may not last.
Is it actually safe to let it buy things?
The one-time card numbers and confirmation gates are real friction against the worst failures, and purchase protections apply to eligible transactions. Safety still depends on the gates you reviewed above staying on. Turn them off and you have a different product.
Do I need to change my website for agents like this?
Not urgently, and not for Muse specifically, which is a US consumer launch. But the direction is clear: agents that act on the web favor sites with structured offers, consistent entity data, and documented public interfaces. Those are cheap upgrades you can make before your competitors do, and cheap agent-native small models mean more of these agents will be running per task, not fewer.
Author: Gabriel Finch, Search Retrieval Researcher, 1,200+ AI Answers Reviewed at Auspia. Gabriel writes about retrieval systems, agent-readable content, and what AI discovery changes for publishers.




