Artificial Intelligence
Written by: Tathagata Sen
Updated 4:11 PM EDT, September 11, 2026

Meta launched Muse on September 8, a personal AI agent that can help consumers with everyday tasks and projects, according to a Reuters report.
A part of the company’s push into agentic AI, Muse is initially rolling out in the U.S. for adults through dedicated iOS and Android apps, the muse.ai website, and WhatsApp. It runs on Meta’s in-house Muse Spark model and can complete multi-step tasks with minimal supervision, including drafting a shopping list from a recipe, booking travel, or managing bills.
Vishal Shah, vice president of AI products at Meta, told Reuters, “It is impossible to say that there is never going to be a mistake, but every single part of the architecture has been designed to make this as safe, as secure, as private as we can possibly make it.”
It will be interesting to see whether consumers are ready to trust Meta with their personal data, especially given that the launch came less than two weeks after Meta agreed to an $18 billion multistate settlement over claims related to social media’s consumer harms.
Muse connects to a user’s existing apps and accounts, including email, calendar, payment methods, and services such as health, shopping, and smart home devices. It can carry out both one-off and longer-running tasks.
The agent continues working even after a person closes the app and checks back in when it needs approval for sensitive actions, such as sending a message on the user’s behalf or spending money.
That approval structure follows a pattern other agentic AI products have converged on this year: broad autonomy for low-stakes actions like drafting a plan, paired with a hard stop requiring explicit human sign-off before anything irreversible.
Users can also control which data and accounts the agent is allowed to see in the first place.
According to internal posts seen by Reuters, Meta employees testing Muse reported sharply mixed results. One tester said Muse was so effective at arranging vacation logistics that it felt like “the third participant” on a three-week honeymoon in Indonesia. Another employee flagged a serious security flaw: after being asked to identify toys in photos from a child’s birthday party, the agent routed around guardrails and exposed the person’s personal iCloud photos.
We don’t know whether these problems still persist. If they do, would consumers trust an agent that can plan a honeymoon…and accidentally expose their private photos?
Muse’s permission architecture is a real-world example of the access-control challenge that chief data officers (CDOs) are already grappling with in the era of agentic AI. How much should an agentic AI be allowed to see, how much should it be allowed to do, and where should the hard stops be? These are critical questions that must be answered before deploying agentic AI.
Given the scale and sensitivity of what Muse can access, such as health data, personal galleries, and payment methods, the stakes are especially high. That’s precisely why AI governance frameworks need to treat permissions as a first-order design decision prior to deployment.
Public acceptance of Muse will influence both the pace of consumer-facing agentic AI adoption and the level of scrutiny enterprise vendors offering similar agent capabilities can expect to face.
One thing is clear: interesting times lie ahead for consumer adoption and enterprise governance alike.