Meta’s New AI Agent Can Send Emails and Make Purchases for You
Meta launched Muse, a personal AI agent that can use connected services to send emails, book travel and make purchases. A separate Sentinel controls its permissions and network access, but the strongest privacy mode is still forthcoming and independent evidence about reliability remains limited.
Meta has released Muse, a personal artificial intelligence agent that can send email, book travel, fill forms and make purchases through connected accounts. The launch moves consumer AI beyond answering questions into taking actions with real financial and privacy consequences.
The 30-second summary
- What happened? Meta launched Muse in the United States on September 8 for adults using iOS, Android, the web and WhatsApp.
- Why does it matter? Muse can work after the user closes the app and act through email, shopping, calendar and other connected services.
- What is the catch? Its strongest privacy upgrade is not available yet, while reliability and security evidence remains mostly controlled by Meta.
Key Fact: Every connector action and every request to reach the internet must pass through Sentinel, a separate permission authority that Muse cannot override.
From conversation to action
According to Meta's September 8 announcement, Muse can open a browser, complete forms, negotiate bills, organize long projects and continue working in the background. It pauses for approval before sensitive steps such as sending an email or completing a purchase. Checkout initially uses Stripe Link, which creates a one-time card so the agent does not see the user's actual payment details.
The service is rolling out in the United States to users aged 18 or older. People decide which services Muse can connect to, whether it may only read or also act, and can revoke those permissions.
A security agent watches the working agent
The unusual part of Muse is its architecture. Each user receives a dedicated cloud computer called Muse Secure VM. The main agent operates inside a restricted Linux container and cannot directly access stored passwords or tokens. Privileged workers use those credentials on its behalf.
A separate host-side system called Sentinel evaluates connector requests and all outbound network traffic. Muse proposes an action, but Sentinel decides whether it may proceed, must be blocked or needs the user's approval. This split is designed for a familiar danger: an agent can encounter hostile instructions hidden in emails, websites or files. Recent research has shown that apparently harmless steps can accumulate into a harmful plan.
Meta also provides an audit trail of completed and proposed actions. Its technical account says the launch system was hardened through internal use, red teaming and a private bug bounty.
Before we trust the agent with everything
- The security design is promising, but most evidence about its performance comes from Meta. Independent researchers have not yet had enough time to test the deployed service at scale.
- Meta acknowledges that Muse will still make mistakes. Reuters reported internal problems involving reliability, connections and unintended data handling during development.
- The planned Confidential VM, which Meta says would encrypt the whole environment with a user-held key so even Meta cannot access it, is due later in 2026. It is not part of the launch configuration.
What to watch next
The real test is whether Sentinel can stop manipulated or mistaken actions without making Muse frustratingly cautious. Evidence should include independent prompt-injection testing, error rates for sensitive actions, recovery after mistakes and clear records of when human approval was required. An earlier real-world incident showed how an AI agent could chain weak permissions across several services.
Muse is therefore important less as proof that personal agents are solved than as a public experiment in giving one broad authority. Its value will depend on whether the permission boundary works when the agent meets messy accounts, ambiguous instructions and adversarial content outside Meta's laboratory.
Verified topics and entities
Sources and citations4 sources
External references used to support the reporting in this article.
Published by
NewTqnia Artificial Intelligence Desk
An institutional editorial team within NewTqnia