← NeuPortal blog

What Is Meta Muse? The AI Agent at No. 1 in the App Store, and Is It Safe to Give It Your Accounts?

By ·

What Is Meta Muse? The AI Agent at No. 1 in the App Store, and Is It Safe to Give It Your Accounts?

Meta Muse is a personal AI agent from Meta that does things for you instead of only answering questions. It sends email, books trips, fills in forms, shops and, in a limited beta, places phone calls. It launched in the US on 8 September 2026, and within two weeks it was the No. 1 free app on the US App Store, ahead of ChatGPT.

The short answer on safety: Muse ships with a detailed, layered security design, and Meta's own documents still say three things you should know before you connect your email or your card. Nothing in the current design stops Meta itself from accessing the data in your Muse "when necessary to support, secure or operate the service" - only Meta's internal policies limit it. Training on your activity is switched on by default. And prompt injection, the attack that turns an agent against its owner, "remains an open problem in the industry", in Meta's own words.

Below is everything in one place: what Muse does, what it costs, how its safeguards work, what has already gone wrong in its first 17 days, why the download numbers everyone quotes do not agree, and a step-by-step way to use it with the least exposure - or to switch it off.

Meta Muse in 30 seconds

- **What it is:** a personal AI agent that acts on your behalf across email, calendar, shopping and bookings, and on a Mac across your messages and files. It runs on Meta's own model, Muse Spark. - **Where:** the US since 8 September and Canada since 18 September (iOS and the web there, Android still to come), for adults 18 and over. In the US it runs on iOS, Android, the web at muse.ai, inside WhatsApp, and on Mac since 17 September. - **Price:** free up to 100 million tokens a week, according to Mark Zuckerberg. The Power plan is $20 a month and Maximum is $100 a month, per Meta's Help Center. - **Is it safe?** Strongly safeguarded by design, but not safe by default. Turn off training, switch approvals to "Always ask", and start with one low-stakes connection. - **Open issues:** Meta can technically reach your data, Amazon blocks it, a Mac flaw was found and fixed within a day, and Meta quietly tested human call-centre workers placing some of its calls inside the company.

What is Meta Muse?

Muse is what the industry calls an agent: software that takes actions, not a chatbot that only writes answers. Meta's launch post describes it as a "secure, private personal AI agent that proactively helps with people's goals". In practice it can:

- write and send email, and manage your calendar; - open a browser, search, fill in forms, compare prices and check out; - book trips and restaurants; - negotiate for you - Meta's own examples include getting more for a used car and lowering a bill; - keep working after you close the app, and come back when something changes or when it needs your approval; - on a Mac, read and act in Mail, Messages, Notes, Reminders, Calendar and your files, app by app, if you allow it.

Under the hood, every user gets a dedicated cloud computer: a Linux virtual machine with its own file system, terminal and browser. Muse can write small programs there to get a job done. It is powered by Muse Spark 1.3, which Meta released on 2 September.

**The names are confusing, so here is the map.** *Muse* is the agent app. *Muse Spark* is the model family underneath it (1.1, 1.2, 1.3). *Muse Code* is a separate developer product with its own pricing. Meta also sells an image model, Muse Image, and has previewed a video model, Muse Video, that is not yet available. Several pages that rank for "Meta Muse price" mix these up. The prices below are for the agent only.

How much does Meta Muse cost?

| Plan | Price | Weekly allowance | Source | |---|---|---|---| | Free | $0 | 100M tokens | Mark Zuckerberg on X, 8 September | | Power | $20 a month | 500M Muse tokens | Meta Help Center | | Maximum | $100 a month | 3B Muse tokens | Meta Help Center |

Three things the table does not tell you:

1. **Meta does not define a "Muse token".** Meta has not published how many bookings or emails 100 million tokens buy. The app shows the percentage of your allowance that is left. 2. **Whether the free tier needs a card on file is unclear.** TechCrunch reported that a card is required even for free use. Engadget's setup guide says a card is needed only if you want Muse to buy things. Meta's Help Center says neither. 3. **Meta's longer-term plan is a cut of what you buy.** At Meta Connect on 23 September, Zuckerberg said Meta is making Muse "free for a huge number of tokens, with the expectation that over time we will profit by taking a small fee from transactions". Who pays that fee, and how much, has not been stated.

Subscriptions require you to be 18 or the age of majority in your country, and Meta notes that "Muse and Muse subscriptions are in limited testing".

How Muse's security actually works

This is the part most coverage skips, and it is genuinely serious engineering. Meta published a long technical write-up. In plain English:

- **Your Muse lives in its own sealed computer.** The agent runs inside a restricted container on your personal cloud machine, walled off from the services that hold your credentials. - **A gatekeeper approves every step outside.** A separate program called Sentinel decides whether any action through a connected service, and any request to the internet, goes through. In Meta's words: "Nothing Muse does reaches the internet unless the Sentinel approves it." - **The agent never holds your real keys.** Passwords and login tokens sit in a separate vault. The agent works with stand-in tokens, and the real ones are swapped in at the network edge, so a hijacked agent has no real passwords or tokens to leak. Your data is another matter: whatever you have connected, the agent can still reach. - **Payments are kept at arm's length.** Meta's recommended route is Link by Stripe. At stores that accept Link, Muse pays with the method saved in your Link wallet; at stores that do not, Link issues a one-time card tied to one merchant, one amount and a short time window. Muse can also log in to a store account and pay with a card you saved there. Every purchase needs your approval. - **Email is filtered.** The mail connector strips one-time codes, password-reset links and magic sign-in links before the agent sees them - exactly the items an attacker would want. - **You decide how often it asks.** Approvals can be given once, for one task, for one site, or always. Out of the box it asks only for some actions, according to Engadget's setup guide; a stricter "Always ask" mode is available for connectors and for the web.

Meta also runs a bug bounty that pays up to $300,000 for serious flaws, including up to $130,000 for a prompt injection that compromises a single user's Muse.

Is Meta Muse safe? What Meta's own documents admit

When we searched Google for "is Meta Muse safe" on 25 September, the top result was Meta's own FAQ, whose answer opens with a flat "Yes." Meta's technical documents are more careful, and they are where the real answer is.

**1. Meta can reach your data.** Today's design restricts Meta staff through operational policies, but Meta's security write-up says plainly that it "does not prevent Meta from accessing data when necessary to support, secure or operate the service". A version that would lock Meta out with encryption, the Muse Confidential VM, is with a small group of testers and is promised for "later this year".

**2. Training on your activity is on by default.** According to Meta's Help Center, the permission to use your Muse interactions to train Meta's AI is on when you first use Muse. You can switch it off in Settings > Data controls, and the change applies to past interactions as well. Meta says it removes names, email addresses, phone numbers and Social Security numbers before training.

**3. Prompt injection is not solved.** Prompt injection is when text hidden in a web page or an email tricks the agent into following someone else's instructions. Meta: "Muse isn't immune to attack. Prompt injection remains an open problem in the industry - and Muse will sometimes make mistakes." Meta has published safety evaluations for the original Muse Spark (May 2026) and for Muse Spark 1.1 (July 2026), but none for 1.3, the version Muse runs on today. In the May report, the original model completed 26.0% of harmful agent tasks in the AgentHarm test, against 10.2% for GPT-5.4 and 8.2% for Claude Opus 4.6. In July, Muse Spark 1.1 was tested on a filtered set, AgentHarm Verified, with a different metric, and scored 3.4% against 1.5% for GPT-5.5 and 0.0% for Claude Opus 4.8. Meta now says 1.3 is "close to SOTA" on injection resistance, but it has not published a number.

**4. Some accounts connect themselves.** Facebook, Instagram and Threads are connected automatically if they sit in the same Meta Accounts Center as your Muse.

**5. You carry the risk of what it buys.** Meta's payments help page puts responsibility for every transaction your Muse makes on you. Link's purchase protections cover damaged or lost items, price drops, no-fee returns and a return guarantee on eligible purchases, but anything those protections do not cover is your responsibility, including a purchase you approved.

**6. Deleting is not quite forgetting.** You can delete messages, chats and files, or reset Muse entirely. Meta's help page warns that Muse may still remember what it learned from something you deleted, and offers a "forget" command for that. Meta does not publish how long it keeps Muse data or its backups.

Trust is already the weak point. An Oppenheimer survey of 1,500 US consumers, reported by The Wall Street Journal, found that only 8% would trust Meta with their passwords, against 30% for Google, 23% for Apple and 16% for ChatGPT.

What has already gone wrong

Seventeen days is not long, and the list is not short. Some of it is the ordinary friction of a new product. Some of it goes to the heart of the safety question.

| Date | What happened | What Meta did | |---|---|---| | 8 Sept | Reuters reports internal tests in which an agent, "routing around guardrails", exposed a person's personal iCloud photos, and CTO Andrew Bosworth kept getting logged out. | Said the launch had been delayed from April for safety; did not address the specific cases. | | 19 Sept | Inc. columnist Jason Aten says he declined Muse access to Messages on his Mac, then got suggestions based on his private conversations - and Muse's own account of how it had seen them was wrong. | Acknowledged that Muse's explanation was wrong; did not say how the access was switched on. | | 20 Sept | Amazon starts blocking Muse from shopping on Amazon.com. | No public response to the block. | | 21 Sept | Security researcher Patrick Wardle publishes a flaw in the Mac app that let malware already on the computer redirect Muse's voice input and steal its login session. | Shipped a fix within a day. | | 22 Sept | 404 Media and Reuters report that, in an internal test on Meta employees, some Muse phone calls were quietly placed by call-centre contractors, with testers told afterwards. | Rolled the test back internally; an executive called it "a miss". | | 21-24 Sept | Two developers get Muse to export the entire file system of its cloud computer - 6.8 GB unpacked in one case. | Called it intended behaviour: it is your machine. |

Why did Amazon block Muse?

Since the night of Sunday 20 September, Muse users who try to buy on Amazon see a pop-up: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." According to Amazon, Meta never told it that the agent would shop there, the agent does not identify itself as an agent, and it appears to capture and store customers' login details. Amazon says it asked Meta to remove Amazon from Muse, and Bloomberg reports that Meta declined. Meta has not responded publicly. Its launch material says that "Muse has no visibility into people's passwords or payment methods" and that credentials a person shares "go into secure storage, so Muse can use them without seeing them".

It is not the first fight of its kind: in November 2025 Amazon sued Perplexity over the agent in its Comet browser. The real dispute is about who owns the customer when software does the shopping. Amazon is also missing from the list of retailers Meta announced as Muse partners at Connect, which includes Walmart, Best Buy, Gap, Sephora and Wayfair.

How many people use Muse? The numbers do not agree

Meta has not published a single download or user number. Every figure in the headlines comes from third-party trackers that estimate downloads from the outside, and they disagree with each other by more than Muse's reported lead over ChatGPT.

| Tracker, as reported | Figure | Window and scope | |---|---|---| | Appfigures (its own post) | 1.1M downloads | 8-18 September, almost all US | | Sensor Tower via CNBC | 730,000 | "about five days" after launch | | Sensor Tower via Yahoo Tech | about 730,000 | 10 days to 18 September, US | | Sensor Tower via Bloomberg | 902,000+ | first six days | | Apptopia via TechCrunch | 2.8M | first 12 days, all installs | | Apptopia via TechCrunch | 1.8M on iOS, against 1.3M for ChatGPT | first 12 days, US and Canada | | Sensor Tower via CNBC | 2.5M+, against 3.1M in ChatGPT's own first 13 days in 2023 | Muse's first 13 days, to 21 September | | Google Play's own counter | 657,566 Android installs | as of 25 September |

Start with the last line. On 21 September, Sensor Tower put Muse's Android downloads at about 1.1 million. Four days later, the only count that comes from a store itself - a figure embedded in Google Play's own listing page - stood at 657,566. Appfigures and Apptopia, measuring almost the same window, are about two and a half times apart. The same Sensor Tower figure of 730,000 appears with a five-day window in one outlet and a ten-day window in another. Even "Muse beat ChatGPT" depends on the slice: ahead on iOS in the US and Canada according to Apptopia, behind ChatGPT's own first 13 days according to Sensor Tower - even though Muse's total includes Android and ChatGPT was on iOS only back then. TechCrunch had to correct its own story after crediting Apptopia's numbers to Appfigures, and some sites still repeat the wrong attribution.

Appfigures itself added a warning to its figure: "Those downloads aren't necessarily real demand but rather curiosity."

The stock market did not wait for the numbers to agree. On Monday 21 September Meta shares closed at $741.25, up 11.3% in a day - the best day since 9 April 2025, according to Nasdaq's price history - after Wells Fargo raised its price target on the strength of Muse demand. By 24 September the stock was up almost 36% for the month.

This is why the gap matters to us. We run a public experiment in which our forecasts are recorded before the events they predict and scored in public afterwards - World Cup match forecasts against Polymarket's own prices, crypto price bands against the Binance close - precisely because a confident number nobody can check is worth less than a modest one that anybody can. Muse's chart position is at least checkable: Polymarket settles a weekly market on the No. 1 free iPhone app, and Muse took the top spot in its 18 September snapshot. Its download totals are not checkable - not until Meta publishes its own.

Is Muse any good? What testers found

Early hands-on reports are mixed, which is itself useful information. Yahoo Finance's Daniel Howley found that most of his tasks worked, but Muse made up a phone number and recommended a restaurant that had been closed for years. At Slate, Alex Kirshner asked Muse to book a flight for two, and 30 minutes produced nothing: Muse failed a captcha, and after he logged in for it, it got kicked out of the browser a few minutes later. He booked the flight himself in five minutes. Muse also added a calendar event two hours and forty minutes in the past. Meta's own App Store listing warns that "Muse may be inaccurate or take unexpected actions, so check in to keep it on track and intervene as needed."

Users are kinder than reviewers: on 25 September the US App Store rating stood at 4.88 from 46,003 ratings.

None of this is unusual for agents. When we looked at agent reliability across 507 business workflows, the best model succeeded on 66.5% of single attempts but got only 47.5% of tasks right on all twenty attempts - the gap between a good demo and a product you can leave alone. More in [How Often Do AI Agents Actually Finish the Job?](/blog/ai-agent-reliability-thinkingbox-benchmark)

How to use Meta Muse safely: a checklist

If you decide to try it, this setup keeps the most control on your side.

1. **Turn off training first.** Settings > Data controls. It is on by default, and switching it off also covers your past activity. 2. **Set approvals to "Always ask"** for both connectors and the web, at least for the first few weeks. Out of the box Muse asks only for some actions. Loosen it task by task, not everywhere at once. 3. **Start narrow.** Connect one low-stakes service, such as a calendar, before your main email. Joe Sullivan, formerly Facebook's chief security officer, advises anyone trying a personal AI agent to start narrow and to switch access off when they are not using it. 4. **Check what connected itself.** If your Facebook, Instagram or Threads accounts share an Accounts Center with Muse, they are linked automatically. Review your connections and remove what you do not need. 5. **Keep payments on Link's one-time cards,** and read every purchase approval before you tap it. The responsibility is yours. 6. **Be careful with custom connectors.** From Meta's own Help Center: "Meta doesn't review custom connectors or how they use your information, so grant access with caution and review the provider's privacy policies." 7. **On a Mac, grant access app by app.** Each app can be set to Off, Read only, or Read and interact. Keep the Mac app updated - the dictation flaw was closed by an update. 8. **Read the activity log once a week.** Meta itself advises users to review what Muse has done and to grant only the access they are comfortable with.

How to turn off, opt out of or delete Meta Muse

- **Stop AI training on your data:** Settings > Data controls, then switch off the training permission. It applies to past interactions too. - **Disconnect a service:** remove it in Muse's connector settings. What Muse already learned from it may stay in its memory, so ask Muse to forget it. - **Download your data first:** Settings > Data controls > Download gives you a copy of your chats, files and other agent information. What Muse remembers about you sits in a plain file, MEMORY.md, which you can read and edit under Assistant > Identity > Memory. - **Delete everything:** Reset Muse erases all your Muse data and cannot be undone. - **Remove it completely:** deleting your Meta account in Accounts Center deletes Muse with it.

Frequently asked questions

**Is Meta Muse free?** Yes, up to a weekly limit - 100 million tokens, according to Mark Zuckerberg. Heavier use needs the Power plan ($20 a month) or Maximum ($100 a month).

**Do I need a credit card to use Muse?** Reports conflict, and Meta's Help Center does not say. To buy things, Meta recommends Link by Stripe, but Muse can also log in to a store for you and pay with a card saved in that account. It asks for your approval either way.

**Is Meta Muse available in Canada, the UK or India?** In Canada, yes: Muse launched there on 18 September, on iOS and the web, with Android still to come. It is not in the UK, German, French, Indian or Australian stores.

**Can Meta see my Muse data?** When Meta decides it is necessary to support, secure or operate the service, yes. Meta says staff access is restricted by internal policy, and a version that blocks it with encryption is promised for later in 2026.

**Does Meta use Muse for ads?** Meta says Muse does not pass your conversations or its computer's data to Meta's ad systems. But Muse's browsing looks like yours to the sites it visits, so a store it browsed for you can still show you ads on Instagram. Meta gives that example itself.

**Was the Muse Mac app hacked, and is it fixed?** On 21 September a researcher published a flaw that let malware already on a Mac hijack Muse. Meta fixed it within a day and called it a local attack with low practical risk. The researcher argues that a common trick - persuading someone to paste a command into Terminal - makes it exploitable remotely. Keep the app updated.

**Does a human ever make Muse's phone calls?** In an internal test on Meta employees, some calls were placed by contractors, and the testers were told afterwards. Meta rolled that test back internally and says any such feature will launch only "with the proper disclosures". Nobody has reported humans handling calls for ordinary users.

**Why did Amazon block Muse?** Amazon says Muse shops without identifying itself as an agent, that Meta did not ask permission, and that it appears to store customer credentials. Meta says Muse cannot see passwords or payment details.

**What is the difference between Muse and Muse Spark?** Muse is the agent app. Muse Spark is the AI model that powers it.

**Should I use Meta Muse?** If you want an AI agent, Muse's security design is more serious than most. Treat its defaults as Meta's choices rather than yours: switch off training, keep approvals strict, and connect only what you would be comfortable letting a brand-new assistant see.

Sources

- Meta: [Introducing Muse](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/), [How We Built Safety Into Muse](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse), [Muse Help Center: data and privacy](https://www.meta.com/help/artificial-intelligence/1047255454427887/), [Subscriptions](https://www.meta.com/help/subscriptions/1021145227643680/), [Connectors](https://www.meta.com/help/artificial-intelligence/1687253048996149/), [Muse Spark Safety and Preparedness Report](https://ai.meta.com/static-resource/muse-spark-safety-and-preparedness-report/), [Connect 2026 recap](https://about.fb.com/news/2026/09/the-biggest-news-from-connect-2026/) - Stripe: [Link and Muse](https://stripe.com/newsroom/news/stripe-helps-meta-muse-shop-with-link) - Amazon block: [GeekWire](https://www.geekwire.com/2026/amazon-blocks-metas-muse-ai-assistant-in-new-standoff-over-agentic-shopping/), [TechCrunch](https://techcrunch.com/2026/09/21/metas-ai-agent-has-been-blocked-from-using-amazon-com/) - Mac flaw: [Patrick Wardle's disclosure](https://github.com/pwardle/not-a-mused), [The Hacker News](https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html) - Human-placed calls: [404 Media](https://www.404media.co/meta-tests-muse-ai-agent-calls-that-are-actually-made-by-humans-in-a-call-center/) - Downloads: [Appfigures](https://appfigures.com/resources/insights/meta-finally-gets-serious-about-ai-muse-million-downloads), [TechCrunch on Apptopia data](https://techcrunch.com/2026/09/21/metas-muse-is-outpacing-chatgpts-early-mobile-launch/), [Yahoo Tech on Sensor Tower data](https://tech.yahoo.com/ai/article/metas-ai-agent-muse-is-chasing-chatgpts-app-store-rise--and-hit-no-1-with-fewer-downloads-152809095.html) - Canada launch: [iPhone in Canada](https://www.iphoneincanada.ca/2026/09/18/metas-muse-ai-agent-is-now-available-in-canada/) - Model safety: [Muse Spark 1.1 Evaluation Report](https://ai.meta.com/static-resource/muse-spark-1-1-evaluation-report/) - Security advice: [Dataconomy](https://dataconomy.com/2026/09/21/muse-reportedly-read-private-notifications-without-permission/) - Hands-on: [Slate](https://slate.com/technology/2026/09/meta-muse-ai-app-review.html), [Yahoo Finance](https://finance.yahoo.com/technology/article/metas-muse-is-an-impressively-capable-ai-agent-despite-some-hiccups-173310662.html) - Share price: [Nasdaq historical data for META](https://www.nasdaq.com/market-activity/stocks/meta/historical)