The short version

Muse app icon
Muse Launched Sept 8, 2026
  • AvailabilityUnited States only, 18+
  • PriceFree tier, then $20 or $100 a month
  • PlatformsiOS, Android, muse.ai, WhatsApp
  • ModelMuse Spark
  • Made byMeta (Facebook, Instagram, WhatsApp)
  • Needs access toEmail, calendar, payment, and more
Visit the official Muse site

What Muse is

Muse is a personal AI agent from Meta. The distinction Meta is drawing is between an assistant that tells you things and an agent that does things: in Meta's own words, Muse "doesn't just answer questions, it actually does the work."

In practice that means Muse connects to services you already use — your email, your calendar, a payment method — and then carries out multi-step tasks against them. You ask it to find a flight, and rather than listing options for you to book yourself, it can go and book one. It breaks a goal into a plan, works through the steps, keeps running after you close the app, and comes back when something changes or when it needs your approval to do something consequential.

That is a meaningfully different product from the chatbots most people have used, and the difference is the whole story from a privacy standpoint. A chatbot that gives bad output wastes your time. An agent with your inbox and your card attached can take an action you didn't intend, and actions are harder to take back than sentences.

Meta's announcement

Meta introduced Muse on September 8, 2026, alongside a dedicated app and a new account on X:

The framing — "across every part of life" — is not marketing exaggeration so much as a description of the access model. Muse is designed to sit across categories that have historically been kept in separate apps by separate companies, and the value it offers is precisely that it can see all of them at once.

What Muse can actually do

Meta's launch materials and early hands-on reporting describe a fairly wide task surface:

  • Email and admin. Drafting and sending email, filling in forms, chasing paperwork.
  • Travel. Researching and booking trips, then adjusting them when details change.
  • Shopping and payments. Making purchases on your behalf, including comparison work beforehand.
  • Negotiation. Meta specifically pitches Muse on lowering bills and getting better prices — for example when selling a car.
  • Turning saved content into actions. A recipe reel saved on Instagram becoming a grocery list; a set of dates becoming party invitations.
  • Long-running goals. Holding a plan over days or weeks, monitoring it, and resurfacing when something needs a decision.

The connector list is broad: email, calendars, payments, health and fitness apps, smart home, dining, shopping, music, and events, with other services reachable through public APIs or through Muse simply using a browser the way a person would. Meta says you choose "which apps Muse connects to and exactly how much access it gets," which is the right design — though as always, the default settings matter more than the available settings.

Purchases run through Link by Stripe, which generates a one-time-use card number for a transaction rather than exposing your real card. Meta has said Shop Pay and 1Password integrations are coming.

Muse Spark, the model behind it

Muse runs on Muse Spark, which Meta describes as its "most capable model to date, built for real-world agentic work." Reporting at launch referred to the shipping version as Muse Spark 1.3.

The phrase "built for agentic work" is doing real work in that sentence. A model tuned for conversation optimises for a good answer; a model tuned for agentic use has to plan, use tools, recover from a failed step, and know when to stop and ask. It is also the component that determines how badly things go when a web page it is reading contains text designed to hijack it — a problem the whole industry is still working on, and one worth understanding before you attach an agent to your inbox.

Which countries Muse is available in

At launch, Muse is available in the United States only, and only to users aged 18 and over.

Meta has not published a timetable for other countries. It's reasonable to expect the European Union and the United Kingdom to lag, as they have for several previous Meta AI features: an agent that reads your mail and spends your money raises questions under the GDPR and the EU's AI Act that a chatbot does not, and Meta has historically staged its AI rollouts to those markets separately. India, Canada, and Australia have no announced date either.

If you are outside the US, the honest answer today is that there is no legitimate way to use Muse, and the workarounds carry real risk — which is the subject of the next-but-one section.

Muse pricing and the free tier

Muse has a free tier and two paid plans:

Muse plans at launch, September 2026
PlanCostWhat you get
Free$0Reported at 100 million tokens per week, with an in-app meter showing what's left
Power$20 / monthHigher usage allowance
Maximum$100 / monthThe highest usage allowance

The free allowance figure of 100 million tokens per week traces back to a post by Mark Zuckerberg rather than to formal documentation, so treat it as indicative. Meta's own framing is that Muse is "free for most of what people need," with subscriptions for heavier use. The app shows a percentage meter and warns you before the free allowance runs out.

One detail is worth flagging because it is easy to miss at signup: multiple outlets reported that Muse asks for a payment card on file to get started even on the free tier. That is unusual for a free AI product, and the likely reason is structural rather than sneaky — an agent that books restaurants and buys things needs a funding source to be useful at all. But it does mean "free" here means "no subscription fee," not "no card." If that matters to you, check the signup flow before you commit.

How to download Muse — and the APK problem

The legitimate routes are the Apple App Store, the Google Play Store, and the web app at muse.ai. Meta has also said Muse will come to its AI glasses.

Because the app is US-only, a predictable thing is happening in search: people outside the United States are looking for "Muse APK" and "Muse download" to sideload the Android package from a third-party mirror. This is a bad idea, and it is a materially worse idea for this app than for most.

Why sideloading an agent app is a poor trade

A repackaged APK from an unofficial mirror can be modified before you install it. With an ordinary app, the worst case is bad but bounded. With an agent app, the entire purpose of the software is to hold live credentials for your email, your calendar, and a payment method — so a tampered build is being handed the keys to all of them at once, by design.

Geo-restricted launches reliably attract fake builds precisely because demand outruns availability. If you are outside the US, waiting is the cheap option; a compromised inbox is not.

The same reasoning applies to sites offering "Muse Pro unlocked" or early access. If you want the background on how stolen credentials get used once they leave your device, our explainers on credential stuffing and phishing attacks cover the mechanics, and what a data breach is covers what happens after.

Muse vs the Meta AI assistant

These are two different products and the search traffic suggests plenty of confusion between them.

Meta AI is the assistant already embedded in Facebook, Instagram, and WhatsApp. It answers questions, generates images, and lives inside apps you were already using. Muse is a separate, standalone agent with its own app, its own subscription tiers, and — crucially — its own connections to services outside Meta.

The practical difference is permissions. Meta AI mostly works with what is already in front of it. Muse asks you to grant it standing access to accounts elsewhere, so that it can act while you are not watching. Someone comfortable with the first is not automatically agreeing to the second.

What Muse Code is

Muse Code is the developer-facing sibling: a coding agent rather than a life-admin one. It shares the Muse Spark lineage but is aimed at writing and modifying software rather than booking dinner.

If you arrived here searching for Muse pricing and found figures that didn't match the $20 and $100 tiers above, this is the likely explanation — the coding product and the consumer agent are priced and packaged separately.

Is Muse on WhatsApp or Facebook?

Muse is reachable through WhatsApp at launch, alongside the standalone apps and the website. It is not a Facebook feature, and "Facebook Muse" is not a separate product — the association is simply that Meta owns both.

The WhatsApp route is convenient and worth thinking about for a moment. WhatsApp's selling point is end-to-end encryption, meaning ordinary messages can't be read in transit. A conversation with an AI agent is different in kind: the agent is a participant, and it has to be able to read what you send in order to act on it. That is not a flaw, but it is a distinction people conflate. We cover what the platform does and doesn't protect in our guide to WhatsApp privacy features.

How Muse handles your data

To Meta's credit, the architecture here is more considered than a simple "trust us." The design has three named parts.

Muse Secure VM. Each user's agent runs on its own dedicated virtual machine in Meta's cloud, holding both the agent and that person's data, isolated so that no other user's agent can reach it. This is a recognisable application of the same principle behind browser isolation — contain the risky thing in a disposable box rather than letting it run next to everything else.

The Sentinel agent. A second agent runs on the same machine, kept separate from Muse at the system level, and nothing Muse does reaches the internet unless Sentinel approves it. This is a sensible answer to the prompt-injection problem: if a malicious web page convinces Muse to exfiltrate your data, there is a second check between that decision and the open internet.

Credential handling. Meta says Muse has no visibility into your passwords or payment methods; credentials you share go into secure storage that Muse can use without reading. Combined with Stripe's one-time card numbers, this meaningfully limits what a compromised agent could walk away with.

On top of that, Meta says Muse checks with you before sensitive actions such as sending an email or making a purchase, shows a complete audit trail of what it has done and plans to do, lets you disconnect any service at any time, lets you tell it to forget specific things it has learned, and lets you opt out of your interactions being used to train Meta's models.

Meta also states plainly that Muse "doesn't share a person's conversations or the data in their VM with Meta's ad systems."

The privacy questions worth asking

That is a genuinely stronger starting position than most agent products have shipped with. The questions that remain are less about what Meta has built than about what is enforcing it.

The gap between a policy and a guarantee

Meta has announced Muse Confidential VM, coming later this year, in which the whole VM — your data and your conversations — is encrypted with a key only you hold, "so not even Meta can access it." Mark Zuckerberg has said he recruited Moxie Marlinspike, the founder of Signal and the architect of WhatsApp's end-to-end encryption, to build it.

That is a serious hire and a serious commitment. But read the tense: the protection that would make Meta technically unable to read your data is a future feature. Its existence as a roadmap item is itself the clearest available statement that, today, the separation between your Secure VM and Meta is a policy the company has adopted rather than a barrier the architecture enforces.

None of that means Meta is reading your inbox. It means the difference between "won't" and "can't" is not academic here, and right now the answer is "won't." For some people that is fine. For anyone whose threat model includes a subpoena, a rogue insider, or a future change of corporate policy, "won't" and "can't" are very different products, and the second one has not shipped yet.

Two further points are worth holding in view:

The ad-system separation is the load-bearing promise. Meta's revenue comes from advertising, and an agent that knows what you buy, where you travel, and what you are planning would be extraordinarily valuable to an ad business. Meta says that data does not cross over. That commitment is doing an enormous amount of work, and it is worth revisiting whenever the terms change. If you want the background on how that machinery works in the first place, we've written about targeted advertising in detail.

Aggregation is its own risk. Even with perfect intentions, a single service holding live access to your email, calendar, payments, health data, and smart home is a concentration of risk that didn't previously exist. The convenience is real, and so is the blast radius. Our look at Gemini's notebook privacy covers similar ground for Google's assistant, and the question of signing in with Google or Facebook versus a regular signup is the same trade-off in miniature.

Why the reaction has been cautious

Coverage at launch has been notably focused on one question, which TechCrunch put directly: will consumers trust it?

The scepticism is not really about the engineering. It is that the company asking for access to your inbox and your card is the one that settled with the FTC over privacy deception in 2011, paid a $5 billion penalty over the Cambridge Analytica period in 2019, and has faced substantial child-safety litigation since. A well-designed Secure VM does not erase that history, and Meta is asking for a larger grant of trust than it ever has before, at a moment when public patience for AI products is thin.

The counter-argument is that this is exactly why Meta built the architecture it did, and hired the person it hired. Both things can be true. The reasonable position is to judge the Confidential VM when it ships rather than on the strength of the announcement.

Should you connect your accounts?

If you are in the US and curious, a measured way in:

  • Start with low-stakes connectors. Calendar and dining reservations before email and payments. You learn how it behaves without much downside.
  • Use the granular access controls. Meta says you choose how much access each service gets. Actually use that, rather than accepting whatever the setup flow proposes.
  • Read the audit trail early on. It's the only way to know what the agent is actually doing when you aren't watching, and it is most useful in the first week, before you stop looking.
  • Opt out of model training if you don't want your interactions used that way. The setting exists; it is not the default in most products.
  • Keep the Meta account itself well defended. A single credential now unlocks an agent that can spend money and read mail, so it deserves a strong unique password in a password manager and two-factor authentication.
  • Consider what your email actually holds before connecting it. For most people an inbox is the recovery mechanism for every other account they own — a point we get into in Proton Mail vs Gmail.

If you are outside the United States, there is nothing to do yet, and the sideloaded builds circulating are not a shortcut worth taking.

Muse is a real technical step forward and its security design is better than the category norm. The open question is not whether Meta built something capable — it clearly did — but whether the guarantees catch up with the access before the access becomes habit.

Frequently asked questions

What is Meta Muse?

A personal AI agent from Meta, launched September 8, 2026. Unlike a chatbot, it connects to services such as your email, calendar, and payment method, and carries out multi-step tasks on your behalf — sending mail, booking travel, filling forms, and making purchases.

Which countries is Muse available in?

The United States only at launch, restricted to users aged 18 and over. Meta has not announced a date for other countries, and EU and UK availability may take longer given data protection and AI regulation there.

How much does Muse cost?

There is a free tier, reported at 100 million tokens per week, plus two paid plans: Power at $20 a month and Maximum at $100 a month. Several outlets reported that a payment card is required at signup even for the free tier.

How do I download the Muse app?

Through the Apple App Store, the Google Play Store, or the web app at muse.ai. Avoid third-party APK mirrors: the app is designed to hold live access to your email, calendar, and payment method, so a tampered build is far more damaging than it would be for an ordinary app.

What is Muse Spark?

The model powering Muse, described by Meta as its most capable model to date and built specifically for agentic work. Reporting at launch referred to the shipping version as Muse Spark 1.3.

Is Muse the same as the Meta AI assistant?

No. Meta AI is the assistant built into Facebook, Instagram, and WhatsApp. Muse is a separate standalone agent with its own app and subscription, and it asks for standing access to accounts outside Meta so it can act when you are not watching.

Can Meta read my Muse conversations?

Today, technically yes. Muse runs in a dedicated Secure VM that Meta says is isolated from its advertising systems, but that separation is a policy commitment. Meta has announced a Muse Confidential VM, coming later in 2026, that would encrypt the VM with a key only the user holds — that is the feature that would make it technically impossible, and it has not shipped yet.

Does Muse use my data for advertising?

Meta states that Muse does not share a person's conversations or the data in their VM with Meta's ad systems. That is a company commitment rather than something enforced by the current architecture, so it is worth rechecking if the terms change.

Is Muse safe to give my email and card details?

Meta says Muse cannot see your passwords or payment methods — credentials go into secure storage it can use without reading, and purchases run through one-time card numbers from Link by Stripe. It also asks for confirmation before sensitive actions and keeps an audit trail. The residual risk is concentration: one service with live access to email, calendar, and payments is a large blast radius if anything goes wrong.

What is Muse Code?

A separate, developer-focused coding agent from Meta, packaged and priced separately from the consumer Muse agent described here.