Meta's New AI Agent Muse Will Shop, Email, and Book Travel for You. Should You Trust It?
Meta has launched Muse, an AI assistant that acts on your behalf online. The privacy questions are real, and the company's track record makes them harder to ignore.

Key points
- Meta launched Muse, a personal AI agent, in the United States on iOS, Android, and muse.ai in 2025.
- Muse can browse the web, fill out forms, and make purchases on a user's behalf, running in the background even when the app is closed.
- A second AI called Sentinel monitors Muse's activity to block it from reaching the internet without user approval.
- Meta says users can opt out of having their conversations used to train its AI models, though the default setting has not been disclosed.
- Meta has faced multiple privacy scandals, including a support chatbot that helped attackers take over more than 20,000 Instagram accounts.
Meta, the company behind Facebook, Instagram, and WhatsApp, has launched an AI assistant called Muse that goes further than most. You give it a goal. It works out the steps, opens websites, fills in forms, and can even haggle on your behalf. Close the app and it keeps going, checking back only when it needs your sign-off, such as before completing a purchase.
That kind of autonomy is exactly what makes AI agents, software programs that can carry out multi-step tasks on their own, so useful. It is also what makes them a security risk.
What does Muse actually do?
Muse handles everyday tasks: online shopping, sending emails, planning trips. It remembers details you share and uses them to make suggestions later, even if you only mentioned something once.
You talk to it through the Muse app or through WhatsApp. Meta says no technical experience is required. A free version is available for most users, and paid tiers are coming for heavier use, though Meta has not said what those will cost or what the free plan's limits are.
Muse runs on a virtual computer, a private, isolated environment hosted on Meta's servers, separate from other users' data. Meta says Muse cannot see your passwords or payment details directly. A second AI model called Sentinel watches everything Muse does on that virtual machine and blocks any action that would reach the internet without your approval.
For payments, Muse currently works with Stripe's Link checkout service. Support for 1Password (a password manager) and Shop Pay is coming later this year. Meta also plans a "confidential" version of the virtual machine, encrypted so that even Meta's own engineers could not access what happens inside it.
Should you be worried about privacy?
Yes, at least cautiously. Any assistant with access to your shopping habits, travel plans, and messaging carries real privacy weight.
Meta says you can opt out of your conversations being used to train its AI models. What it has not said is whether that opt-out is on or off by default, which matters a great deal.
The company's history gives reasonable grounds for caution. As first reported by The Verge AI, Meta has faced a string of privacy and safety failures: a "Discover" feature that accidentally showed other users' private AI conversations, a support chatbot that attackers used to compromise more than 20,000 Instagram accounts, and the Cambridge Analytica scandal, in which data on tens of millions of Facebook users was harvested without clear consent.
None of that means Muse is unsafe. But it does mean the trust Meta is asking for has to be earned, not assumed.
What should readers watch for?
Before handing an AI agent access to your accounts, check a few things. Find the data-training opt-out setting and switch it off if you prefer. Be specific about what Muse is allowed to purchase and set a spending limit if one is available. Watch for any confirmation requests that arrive unexpectedly, a sign the agent is about to do something with real-world consequences.
If something goes wrong, take a screenshot and report it through the app. Document the action the agent took and, if money moved, contact your payment provider immediately.



