SAN FRANCISCO — Strip the proposition down to its essentials and it sounds remarkably consequential: give an AI agent access to your email and calendar; connect it to your payment methods, health applications, smart home systems and shopping history; then allow it to make decisions on your behalf around the clock, including after you have closed the application.
That is the proposition Meta is now making to consumers with Muse, a personal AI agent the company launched in the United States on September 8. To persuade users to grant an AI system that level of access, Meta must convince them that it has earned their trust.
Whether the company’s recent record provides enough reassurance is less clear. Less than two weeks before the launch, Meta agreed to an $18 billion settlement with 29 US state attorneys general, who had argued in court that the company’s platforms, Facebook and Instagram, had been deliberately designed with features that harmed younger users.
The settlement, one of the largest in the history of consumer-protection litigation, brought the trial to an end before a verdict was reached. It resolved the case, but it did not settle the broader question of whether Meta has established a sufficiently trustworthy relationship with users over the handling of their personal data.
Muse is built on Meta’s proprietary Muse Spark family of foundation models and operates within a dedicated virtual environment known as the Secure VM. Meta describes the environment as a contained space with its own browser that operates separately from the company’s advertising infrastructure.
Within that environment, the agent is designed to carry out tasks delegated by users, including sending emails, booking travel, completing forms, negotiating recurring bills, monitoring home security cameras and executing multi-step objectives without requiring the user to oversee every individual action.
Its reach extends across a wide range of services and applications, including email, calendars, payment platforms, health and fitness trackers, smart home devices, dining reservations, shopping, music and events.
The system is also designed to learn from conversations over time. Meta says this allows Muse to develop a persistent understanding of a user’s goals and preferences, potentially making its decisions more personalized as the relationship with the agent develops.
That personalization is central to the product’s appeal, but it also raises the stakes around data access. The more effectively an agent understands a person’s routines, preferences and priorities, the more useful it can become — and the more consequential the information it potentially handles.
Meta is offering Muse through a tiered pricing structure. The free version covers most everyday use, while the Power plan costs $20 a month and the Maximum tier costs $100 a month.
The initial rollout is limited to the United States and is available on iOS, Android and the web. Meta has also announced plans to eventually expand the system to its AI-powered glasses.
For consumers, the central proposition is therefore not simply whether Muse can perform tasks that would otherwise require manual work. It is whether users are willing to place an increasingly broad portion of their digital lives inside an AI system — and whether Meta can persuade them that the convenience is worth the trust required to make that system genuinely useful.
The launch is the most tangible product so far from Mark Zuckerberg’s stated ambition to deliver what he has called “personal superintelligence,” his phrase for an AI system capable of acting as a knowledgeable, tireless assistant across every domain of a user’s life. The company has committed more than $130 billion in AI infrastructure investment in 2026 alone. Muse is where that spending is supposed to convert into something consumers pay for, rather than a service they use for free while their behavioral data flows to advertisers.
That distinction matters, because what happens to the data generated inside Muse is the detail most users will not read carefully enough. Meta says it will scrub what it calls “critical personally identifying information” from Muse conversations before using them to train its AI models, but users must actively opt out for their data not to be used this way. The default is that conversations contribute to training. The company has not publicly defined what qualifies as “critical personally identifying information,” leaving unclear what a conversation about a medical appointment, a disputed credit card charge, or a family travel itinerary looks like once it enters the pipeline with only the critical elements removed.
The data questions do not stop there. Reuters reported before the launch that engineers inside the company had raised concerns that the agent could mishandle access to sensitive personal data. Meta’s response was that Muse runs in a controlled environment and never sees actual passwords or payment details. Those two statements are not mutually exclusive. In March 2026, a separate internal incident drew scrutiny after a Meta AI agent exposed user-related data to engineers who lacked the appropriate access permissions. At the time, Meta said “no user data was mishandled.”

TechCrunch reported that the central question Muse raises is not whether the agent can do what Meta says it can, but whether the company deploying it has built a foundation of trust sufficient to justify the depth of access being requested. Early testing suggests the agent performs as described.
For European users, the question is partly regulatory. Meta confirmed in its launch announcement that Muse will not be available in Europe until the company has completed a review of compliance with the General Data Protection Regulation and the European Union’s AI Act, which imposes specific requirements on AI systems that handle sensitive personal data. The timeline for that review has not been disclosed.
For the $18 billion settlement, the central allegations were never adjudicated: the case resolved before a jury could return a verdict. What the settlement established is that 29 state governments found Meta’s conduct serious enough to pursue at trial. The company that resolved those allegations is now asking users to grant it more intimate access to their personal information than any of those attorneys general were examining.
Whether that is a risk worth taking is what the app’s download numbers will answer over the coming weeks. The privacy dashboard will not. This week’s debate over AI credit and accountability, illustrated by the OpenAI Navier-Stokes controversy, showed how quickly the gap between what AI companies announce and what they actually deliver becomes visible. With Muse, that gap is now personal in a way an argument over a math proof was not.

