
Key Points
- Meta unveils Muse, an AI agent controlled through WhatsApp that Meta says handles tasks like booking travel on the web on its own. According to Meta, it fills out forms and negotiates on the user’s behalf.
- Muse completes purchases after a user’s approval through Stripe’s Link service, using one-time cards Meta describes as secure. That gives Meta a direct payment feature, which OpenAI recently dropped from ChatGPT.
- Muse runs on what Meta calls a walled-off virtual machine, monitored by an oversight agent. Meta says the setup keeps passwords hidden and that interactions don’t flow into its ad system.
Meta’s new agent Muse is built to handle tasks on its own, from booking travel to shopping. It runs on its own virtual machine and you control it through WhatsApp.
Users can hand Muse simple jobs like sending an email or booking a trip, but Meta also claims it can take on bigger goals. For those, Meta says Muse plans the steps and coordinates time and resources. The agent opens a browser, fills out forms, and negotiates on the user’s behalf. According to Meta, Muse can sell a car for more, lower a bill, or adjust a workout plan.
For longer tasks, Muse is supposed to keep running even when the app is closed. Meta says it checks in when something changes or when it needs approval, like before it actually sends an email or makes a purchase.
Muse also remembers what matters to users and makes suggestions on its own, according to Meta. The assistant taps into Meta’s ecosystem here. Meta says it can turn a recipe reel saved on Instagram into a shopping list, or suggest a menu for a dinner party while accounting for friends’ food allergies.
Meta builds the payment feature OpenAI walked away from
Muse can pay through Link, the service Stripe built. Meta calls Muse the first AI agent covered by Link’s purchase protection, which is meant to handle damaged or lost items, price drops, and returns. For each payment, Link creates a one-time card, so the real card details stay hidden. Shop Pay and a connection to 1Password are set to follow, so Muse can use existing logins.

That puts Meta ahead of OpenAI, which stopped its direct payment feature in ChatGPT and handed checkout back to merchants. Users researched products in the chat but didn’t buy there, and connecting merchants stayed a manual job.
Meta relies on isolation to protect data
Meta spends a big chunk of the announcement on security and offers a deeper look in a separate blog post. Muse Secure VM is supposed to run on its own machine in the cloud, walled off so no outside agent can reach it. According to Meta, that’s also where the login credentials for connected services sit.
Meta says a second agent called Sentinel runs on the same machine, separate from Muse. Nothing Muse does is meant to reach the internet unless Sentinel clears it. Muse itself sees neither passwords nor payment methods, according to Meta. Credentials are supposed to land in a secure store that Muse can use but not view.

Before sensitive actions, Muse is supposed to ask first and show a full record of every step. Users decide which apps the agent can connect to and how far its access reaches, like whether it only reads emails or also sends them. Access can be changed or cut off at any time.
Meta doesn’t share numbers on how robust the system is. Security researchers have shown how agentic systems can be hijacked through manipulated content. With Perplexity’s Comet browser, a doctored calendar invite was enough to take over a password manager account.
Meta’s ad system already uses AI chats
Users can opt out of letting Meta use their interactions to train AI models. Muse doesn’t share conversations and data from the VM with the company’s ad systems, according to Meta. The agent is supposed to forget what it learned if you ask it to. Later this year, Meta also plans to launch Muse Confidential VM, which is meant to encrypt the entire VM with a key only the user holds.
That doesn’t apply to Meta AI. Since December, the company has used interactions with the assistant for personalized ads and content on Facebook and Instagram in most regions, leaving out sensitive topics like religion, health, or political views.
Meta talks about “personal superintelligence”
Meta calls “personal superintelligence,” which Zuckerberg also made the central theme of a recent essay, one of the most transformative technologies there is, and it calls Muse a first step toward it.
The model behind it has closed the gap sharply in five months. Muse Spark, released in April, would score just 31 points on the current Artificial Analysis Intelligence Index v4.3. Since early September, version 1.3 reaches 44 points on the available xhigh tier and 48 on the max tier, which so far is open only to partners. GPT-5.6 Sol (Max) sits at 47, while GPT-6 Astra (Max) and Claude Fable 5.1 land at 53.
In May, word got out that the company was training an agent called Hatch, which learns in walled-off web environments on simulations of real sites like DoorDash, Etsy, and Reddit. Muse is likely based on it. Most recently there was talk of a paid product costing up to $200 a month.
Muse launches first in the US for iOS and Android, with a link to Meta’s AI glasses to follow. Users get a free usage limit that refills on a regular basis. For more, Meta offers subscriptions.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.







