Meta Muse: the AI agent that writes your emails, books your trips and negotiates for you. What it means for your business

September 9, 2026

Meta Muse: the AI agent that writes your emails, books your trips and negotiates for you. What it means for your business

On September 8, Meta launched Muse: a personal AI agent that sends emails, books travel, fills out forms in a browser and negotiates on your behalf. Meta's official announcement puts it plainly: "It doesn't just answer questions, it actually does the work." For now the app works only in the United States, only for adults, and you need to add a payment card before you can start.

So if you run a company in Warsaw, Berlin or Manchester, you cannot switch it on today. This is not a sign-up guide. It is about two things Meta did along the way that matter to your business regardless of when Muse reaches Europe. First, Meta showed what an agent looks like when millions of people are about to hand it their inbox and their card. Second, it built a set of safeguards into the product that is worth holding up against every AI agent you consider putting inside your company.

What Muse does (according to Meta, not the headlines)

I am sticking to Meta's announcement and the two documents the company published the same day: one on safety and one on how Muse was designed. The only thing I take from the press is pricing, which the announcement leaves out.

Task Example Meta gives
Email and bookings sends an email, books travel
Working in a browser opens a site, fills out a form, signs you up for an event
Negotiation sells a car for more, lowers a bill
Long-term goals a training plan it adjusts on its own when the rest of your week changes
Memory a recipe reel saved on Instagram becomes a grocery list; it remembers your friends' dietary restrictions before it sends the invites
Purchases pays through Link by Stripe with a one-time card and buyer protection

The most important sentence in the announcement is not about any of these features. It is about how the agent works: for longer tasks Muse keeps going after you close the app and comes back "when something changes or when it needs approval, like before it sends an email or makes a purchase". That is the difference between a chatbot and an agent. A chatbot waits for you. An agent waits only for your permission.

You talk to it the way you talk to a person, in the Muse app or directly in WhatsApp. Under the hood runs the Muse Spark 1.3 model. The basic version is free. According to TechCrunch, the paid plans cost $20 and $100 a month, and what you buy is more agent usage, not extra features.

The day after launch, Meta's chief AI officer Alexandr Wang wrote on X that users are using Muse ten times more than the testing cohorts did. That is his number, with no methodology behind it. I note it and build nothing on it.

Five safeguards Meta built into the agent

This is the part worth reading even if Muse never interests you. Meta had to answer the question I hear in every conversation about an agent inside a company: "what if it sends something it shouldn't?" The answer is architectural, not marketing.

Safeguard in Muse What it means in practice The question to ask any agent vendor
1. A separate computer for the agent and its data (a dedicated virtual machine with its own browser) the agent shares its environment with nothing else Where does my agent physically run, and who else has access there?
2. A guardian (Sentinel) separated from the agent at the system level; nothing reaches the internet without its approval a second layer the agent cannot bypass What sits between the agent and a sent email? If the answer is "the prompt", nothing does.
3. The agent never sees passwords or cards; logins go into a vault it uses without reading them a leak from a conversation is not a leak of a password Does the agent have my passwords in the conversation context?
4. It asks before sending an email or making a purchase; a full log of what it has done and plans to do every action is auditable Can I see today a list of everything the agent did last week?
5. Access per app and per scope: email as "read only" or "read and send"; disconnect at any time least access needed Does the agent that drafts quotes also have the right to delete emails?

On top of that, three commitments: conversations and data on the agent's machine do not feed Meta's ad systems, you can opt out of model training on your interactions, and later this year there is meant to be a version where the whole machine is encrypted with a key only the user holds. Whether Meta keeps those commitments is a separate debate, and TechCrunch has it by way of the fines the FTC has imposed on the company in the past. The list itself, though, is a good one. Better than what I see in most "AI agents for business" offers.

Why this list matters to me more than the features

Because point 4 is exactly where one of the projects we audited this month fell over. An assistant on a client's website, in one of its language versions, spent several weeks "accepting" enquiries. Not one of the sixteen reached the database. An access token had expired, nobody got an alert, and the assistant kept politely thanking people for getting in touch. Four enquiries from real customers were lost.

An agent with no action log and no alarm on failure is not a cheaper employee. It is an employee who does not tell you it has stopped doing the job.

That is why our own deployments follow the same rule Meta wrote into point 4. Every outward action, meaning an email to a customer, a quote, an entry in a system, goes through an approval queue in the first weeks: the agent proposes, a human clicks. Only after a few weeks without corrections does the scope of approvals narrow. In the tender-monitoring system we run for a client, the decision about what counts as relevant lives in written rules, and the model only summarises. If the model decided, there would be no way to check why it skipped something.

What Muse changes for your business, even if you never use it

Two things, on both sides of the counter.

On the customer's side. Muse books, reserves and fills out forms on a person's behalf. In the launch video the agent signs the user up for a race by filling out the organiser's entry form, and at checkout it shows an "Allow / Deny" screen. If this pattern takes hold, some of your customers will stop calling you. They will send their agent. And the agent will go wherever something can be arranged at 9:40 pm without waiting for a callback: to the practice with an online booking system that works, to the company that answers email within minutes, to the service where an AI voice assistant picks up after hours instead of voicemail.

I do not know when Muse will reach Europe. Meta's announcement says nothing about it. I do know it is not the only agent of its kind on the market, and the direction is the same for all of them.

On the owner's side. What Muse does for one person, a business agent has been doing for companies for a while: it reads the inbox and logs enquiries in the CRM, drafts a quote from a price list, watches a tender portal, answers the phone and books the appointment in the calendar. The difference is scale and fit. Meta built one agent for billions of people, so it had to be general. In a company you build an agent for one process, with your rules and your exceptions. That is why it works where a general one would fall over.

If you want to check which of your processes is the right first one, book a 30-min call.

Where to start: three processes to check first

Not "let's implement AI". One process with a clear outcome and the agent's right to say "I don't know, handing this to a human".

  1. The enquiry inbox. How many customer emails a week have the same shape: a question about price, a date, availability? An agent that reads the inbox, drafts a reply for approval and logs the enquiry in your system is the most common first deployment, because the result shows within a week. That is what process automation looks like when the numbers add up.
  2. Phone and bookings. If customers book by phone and you answer during office hours, that is where a customer's agent will hit first. I wrote separately about what decides whether an AI voice agent actually answers the phone.
  3. Forms and portals. Everything someone in your company clicks through the same way every week: government portals, procurement platforms, supplier panels, the bank. Muse does exactly this in a browser for consumers. The same mechanism inside a company takes hours off a person's plate that nobody was counting.

For each of them, apply the five questions from the table above. A vendor who answers the question about an action log with "the model is very accurate" has not run this in production yet.

What Muse does not solve

Two things, so you do not leave this text thinking it is simpler than it is.

Availability: the US, on iOS, Android and muse.ai, with AI glasses to follow. No date for Europe. The version where not even Meta can see your data is promised "later this year", which means it does not exist today.

The law: an agent with access to a company inbox processes your customers' data. Who the controller is, where the data lives and whether the agent tells customers it is an AI are questions that already have concrete answers in EU law. From August 2, 2026, a chatbot has to disclose that it is AI, and the EU AI Act applies to small companies too. Muse will not settle that for you. Neither will a business agent, unless somebody designed it in.

Update, 10 September: a week after Muse launched, an Anthropic researcher quit saying the labs are "gambling with our lives". How that story connects to the five safeguards above: Jacob Coxon quit Anthropic: what it means for your business.

Summary

Meta showed what an agent for billions of people looks like: it works in the background, asks before sending and buying, has a separate guardian and keeps a full log of its actions. For a business, that list matters more than the app itself. It is the standard you can demand, from today, of any agent that gets access to your inbox, your calendar or your systems.

The second conclusion: customers with agents will go wherever the job can be done without waiting. The company where you can book, ask and order without a human on the other end will get them first.

Book a 30-min call. We will walk through your three processes and check which one has a clear outcome and is the right first agent. You will leave with a concrete answer, even if the answer is "not yet".

More on how we approach these deployments: AI agents for business and process automation.

Sources: Meta Newsroom, "Introducing Muse", Sept 8, 2026 · Meta, "How We Built Safety Into Muse" · TechCrunch, Sept 8, 2026 · PBS NewsHour / AP, Sept 8, 2026 · @AIatMeta on X · @alexandr_wang on X