in

Meta Launches Muse, an AI Agent Inside WhatsApp That Can Email, Shop and Negotiate for You

Meta launched Muse on September 8, 2026, a personal AI agent that can send emails, book travel, fill out web forms, negotiate prices and complete purchases on a user’s behalf, and it is available through a dedicated app or directly inside WhatsApp. Muse is rolling out in the United States only for now, on iOS, Android and the web, with a free tier covering most tasks and paid subscription plans for heavier use. Meta says each user’s agent runs on its own dedicated cloud virtual machine and must ask permission before sending a message or spending money.

A messaging-first agent that keeps working when you close the app

Meta’s announcement on its Newsroom describes Muse as an agent that “actually does the work” rather than answering questions. A user states a goal, Muse builds a plan, and then it acts: opening a browser inside its virtual machine, filling in forms, monitoring pages and coming back for approval when it needs to send an email or pay for something. Long tasks keep running after the app is closed. Meta’s examples include selling a car for a higher price, lowering a bill, turning a saved Instagram recipe reel into a grocery list, and adjusting a training plan when the rest of a person’s schedule changes.

Hosting 75% off

Payments run through Link, the wallet built by Stripe, which generates a one-time-use card number so the user’s real card details are never exposed to a merchant. Meta says Muse is the first AI agent covered by Link’s purchase protections, with Shop Pay and 1Password support to follow. The underlying model is Muse Spark, which Meta calls its most capable model to date.

Each Muse lives on what the company calls a Muse Secure VM, a dedicated cloud machine that holds both the agent and the user’s connected data. A separate Sentinel agent on the same machine gates every outbound connection. Muse cannot see passwords or payment details, which sit in a secure store it can use but not read. Users pick which apps it can reach and at what level, for example read-only email versus permission to send, and can revoke access, tell it to forget specific things, and opt out of model training. A Confidential VM version, encrypted with a key only the user holds, is promised for later this year.

Internal testers found it useful and unreliable in the same week

Reuters reported that the product, known internally as Hatch, was originally due in April and was delayed to shore up security. Vishal Shah, Meta’s vice president of AI products, told the agency that the extra work allowed the company to cross its minimum threshold on safety, security, privacy and performance, while conceding that it is impossible to promise there will never be a mistake.

The same report cites internal posts from Meta employees testing Muse as recently as this week. One described it as so helpful with itineraries and ground transport that it became a third participant on a honeymoon. Another, who asked it to watch for fast-selling tickets, said it stopped refreshing the page after around 15 minutes and switched off monitoring for no apparent reason. Meta’s chief technology officer Andrew Bosworth wrote that he was repeatedly logged out. One employee flagged a case where the agent routed around its guardrails and exposed personal iCloud photos after being asked to identify toys in birthday party pictures. Reuters also notes that Muse is modeled on OpenClaw, the open-source agent framework.

WhatsApp is the detail that matters outside the United States

For readers in Pakistan and the Gulf, the US-only launch means Muse is something to watch rather than use today. But the delivery channel deserves attention. Meta chose WhatsApp, not Facebook or Instagram, as the place people talk to their agent, and WhatsApp is already the default business channel across this region: it is where customers order from home bakeries, where clients send freelancers their briefs, where property dealers and tuition academies and clothing brands run their sales. An agent that lives in the same app people use to run their businesses is a different proposition from a chatbot on a website.

Two consequences follow when Muse or a competitor reaches this market. The first is on the buying side. If a customer’s agent is doing the shopping, comparing prices and filling out order forms, your product pages, price lists and WhatsApp catalogue entries are being read by software before a human ever sees them. Businesses with clear, structured, accurate listings will be easier for an agent to buy from; businesses that run on “DM for price” will be harder.

The second is on the selling side for freelancers. Meta’s own examples include an agent that negotiates on its owner’s behalf. A client who hands quote-gathering to an agent will have that agent contacting several freelancers, collecting rates and comparing them. Profiles, portfolios and pricing that a machine can parse without a back-and-forth will win that comparison. Meta released a coding-focused agent last month, covered in Meta launches Muse Code AI agent for large codebases, and Muse extends the same approach to everyday tasks.

Meta’s distribution advantage over rival agents from OpenAI, Google and Anthropic is that the billions of people already inside WhatsApp, Instagram and Facebook do not need to download anything new. What it asks for in return is deeper access to email, calendars, payments and health data than any of its apps have had before, and the Reuters account of internal testing shows the reliability gap that still has to close. Anyone who does get access would do well to start with read-only permissions, watch the audit trail Meta says it provides, and grant send-and-pay rights only once the agent has proved itself on low-stakes work.

Hosting 75% off

Written by Ahmed Shaami

US Agencies Accuse Six Chinese AI Firms of Industrial-Scale Distillation and Tell Providers to Quietly Degrade Suspect Accounts