On Tuesday, September 8, Meta introduced Muse, its personal AI agent that can do more than just respond to queries.
The AI agent has been developed in a way to interact with the email, travel tickets, retail shopping, and payment transactions of the users, according to the announcement. The key point is that the forthcoming period of the race in the field of AI depends not only on the quality of the model but also on who runs this consumer-agent system and possibly wins consumers’ trust in controlling their inbox, calendar, and credit accounts.
Muse is capable of opening a browser, completing forms, negotiating deals, and executing various tasks. Meta claims it is capable of writing emails, arranging travel, reducing your expenses, and buying products.
While processing payments, Muse employs Stripe’s Link, which creates a one-time card, so that the agent does not see the user’s actual card number. Other payment options, such as Shop Pay or 1Password, are to be included soon.
According to the New York Times, Muse has access to services like Gmail, Spotify, Ticketmaster, OpenTable, and Shopify. The system is based on the Muse Spark family, which was launched by Meta on Apr 8 and updated to Muse Spark 1.3 on September 2.
At launch, Muse will be available only in the U.S. and will be accessible on the web, iOS, and Android; Meta’s AI glasses will come later. There will be a free version and subscriptions priced at $20 and $100 a month, per reports.
The main factor in Meta’s success is distribution. WhatsApp has over three billion users, making it easy for the company to deploy its AI virtual assistant into an app used round-the-clock by customers.
This builds up on Meta’s strategy of Meta as a merchant. Cryptopolitan has already reported on the AI virtual assistant used for scheduling and making payments on the company’s messaging applications, and now it reaches consumers directly.
According to Meta, Muse operates within a dedicated Muse Secure VM. Meanwhile, a distinct version of the Sentinel provides control of connector actions and network traffic, keeping its credentials inaccessible to the main agent in control of Muse. A technical post from Meta explains how sensitive actions may require authorization, how users can review an audit of their activities, and how Meta’s bug bounty may reward up to $300,000.
These protections are crucial as prompt injection continues to plague the industry. Meta itself believes that Muse could encounter malicious prompts hidden in the data it reads.
Emphasis on trust creates a reputational challenge for Meta. Muse emerged 13 days after Meta agreed to settle lawsuits involving Facebook and Instagram and pay up to $18 billion for potential damages caused to children through these social networks.
Thus, security is an integral part of the proposed product. According to the 2026 AI Trust Maturity Survey by McKinsey, two-thirds of the respondents named security and risk as the main obstacle to the full-scale implementation of agentic AI.
Muse is not the first AI that can act on the web. What makes it different is the combination of mass-market messaging, background execution, and payments.
The commercial stakes are large. Gartner forecasts that stand-alone AI agents and assistants will grow 13-fold from 2025 to 2030, creating a $222 billion opportunity. BCG estimates agentic AI could generate up to $200 billion in net new technology-services demand over five years, while the OECD warns that progress toward trustworthy systems still trails adoption.
Muse’s real test, then, is not whether it can book a trip. It is whether Meta can turn distribution into permission. If consumers say yes, the AI race will move further beyond chatbot answers and into payments, identity, security, and real-world transactions.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.