ArticlesAgent-Based AI

Muse Can Shop, Make Reservations, and Negotiate on Your Behalf: Meta Moves Toward Agent-Based AI

Launchedby Meta on September 8, 2026, Muse is billed as a personal assistant capable of browsing the web, filling out forms, preparing purchases, booking certain services, negotiating, and continuing tasks in the background. What’s new is not simply that a model generates better recommendations: the system can act within a digital environment based on the permissions granted by the user. This delegation makes issues of control, security, consent, and accountability just as important as the capabilities of the model itself.

01

What Meta Actually Launched

Meta unveiled Muse on September 8, 2026, as a personal artificial intelligence agent. Unlike a chatbot, which primarily responds to a query, Muse can be given a task, use a web browser and connected services, and then perform a series of actions to attempt to complete it. Meta specifically cites sending emails, booking travel, filling out forms, searching for products, making certain purchases, and negotiating. These capabilities are documented by the company in its official presentation, but they should not be interpreted as proof that every task will be performed correctly on every website, through every interface, or in every situation.[1]

Muse runs in a dedicated virtual machine in the cloud, called Muse Secure VM. This architecture provides it with a browser, storage, and a separate runtime environment. The user chooses which services the agent can connect to and the level of access granted. For certain sensitive actions, such as sending an email or making a purchase, Meta states that human confirmation is required.[1][2]

The initial launch was limited to the United States. This information, which was accurate as of September 8, is now partially outdated. At Meta Connect 2026, Meta announced that Muse is now available in the United States, Canada, and Mexico, and that a rollout to other markets is planned, though no specific timeline had been set for the European Union as of October 2, 2026.[4]

02

What's Really New

Agency does not mean that artificial intelligence possesses a will of its own. In this context, the term describes a system capable of using a model, tools, memory, and orchestration rules to carry out a sequence of goal-oriented actions. What makes Muse innovative, therefore, lies less in any supposed absolute autonomy than in the integration—within a single consumer-facing product—of an agent, a browser, connected services, permissions, memory, and validation mechanisms.

This development shifts the risk threshold. An incorrect response from a chatbot can mislead the user. An incorrect action by an agent can—depending on the permissions granted—modify a calendar, send a message, fill out a form, or trigger a transaction. The more an agent can do, the more critical the quality of its control architecture becomes.

The shift from planning to execution also changes the concept of trust. For a personal assistant to be useful, they may need access to sensitive information: emails, calendars, preferences, task histories, third-party accounts, or payment methods. Thus, usefulness and risk exposure increase hand in hand.

Executive MBA in AI & Business Transformation, aivancity
aivancity

Executive MBA in AI & Business Transformation

The MBA Redesigned for the Age of AI. For experienced executives who want to lead the transformation of their organizations. Paris, Nice, and Dubai.

12 months — Part-time At least 10 years of experience Early bird: 20,000 € Paris · Nice · Dubai
03

How Muse Works

The architecture described by Meta is based on several layers. The Muse Spark model provides capabilities for reasoning, planning, and using tools. The Muse Secure VM offers a persistent environment where the agent can run programs, use a browser, and maintain the state of a task. Connectors enable interaction with third-party services. A second component, Sentinel, monitors external actions and network traffic.[2]

Key Technical Components

Brick Documented role Point to Watch For
Muse Spark A model used to plan, reason, and deploy tools for multi-step tasks. Performance varies depending on the task, the available tools, and the information encountered.
Muse Secure VM Dedicated virtual machine with a browser, storage, and runtime environment. Isolation reduces certain risks without eliminating operator errors or vulnerabilities in the client software.
Connectors Controlled access to services such as email, calendar, or other applications. Each additional permission increases the potential consequences of an error or a security breach.
Sentinel A separate authority that monitors connector activity and network output. A control layer reduces the risk but does not provide an absolute guarantee of security.
Human Validation Request for Approval of Certain Sensitive Operations. Effectiveness depends on the selection of actions requiring validation and the clarity of the consent interface.

Meta also describes a mechanism for separating secrets: the main agent is not supposed to see actual passwords or tokens directly. Specialized components store the credentials and inject them when necessary. This design applies the principle of least privilege, according to which a component should have only the access strictly necessary for its task.[2]

For purchases, Meta announced the integration of Stripe’s Link using one-time-use cards, as well as the planned arrival of Shop Pay and 1Password. However, it’s important to distinguish between what is available and what has only been announced: at launch, some integrations were still pending.[1]

04

Buy, Book, and Negotiate: From Advice to Digital Mandate

Muse illustrates a shift toward what might be called a digital mandate: the user defines an objective and a scope of authorization, and then the agent carries out part of the sequence of actions. In business, this distinction is important. Recommending a product involves providing information; searching for an offer, comparing terms, filling out the necessary fields, and preparing or completing the purchase amounts to intervening in the transaction.

Negotiation is even more revealing. Meta claims that Muse can, in certain scenarios, attempt to reduce a bill or secure better terms. This feature should be presented as a capability announced by Meta, not as a generalized performance demonstrated by an independent evaluation. The success of a negotiation depends on the website, the service, the commercial rules, the context, and the actual room for maneuver available.[1]

For businesses, the arrival of agents capable of interacting with websites may have several consequences: an increase in automated requests, the need to make pricing and contractual information more structured, the emergence of new sales pathways, and the development of interfaces designed for both agents and humans. These consequences, however, remain speculative. There is not yet sufficient data to measure the proportion of transactions that will actually be initiated or executed by personal agents.

05

What the evidence actually allows us to conclude

Meta’s documents confirm the existence of the announced features, the architecture of the Secure VM, the role of Sentinel, and the use of human validation for certain operations. They serve as useful primary sources for understanding what Meta has built, but they are not sufficient to demonstrate the product’s average reliability in everyday use or to establish that it is more secure than another agent.[2]

The first independent tests available in late September 2026 paint a more nuanced picture. Journalists reported successful tasks, but also limitations related to the sites, integrations, or the accuracy of the actions. This early feedback is useful for identifying specific problems, but it does not yet constitute standardized evaluations based on large samples.[11]

It is therefore premature to conclude that Muse can replace a human assistant or that it can reliably execute arbitrary workflows. To truly evaluate an agent of this type, one would need to measure, at a minimum, the task success rate, the number of human interventions required, the frequency of errors, the severity of incorrect actions, its robustness against malicious content, and its ability to recover from a failure.

MSc in Generative and Agent-Based AI at aivancity
aivancity

MSc in Generative,
, and Agent-Based AI

Become an expert in generative and agent-based AI: LLMs, transformers, and enterprise deployment. Includes a learning trip to Silicon Valley. RNCP Level 7 certification (equivalent to a 6-year post-secondary degree).

12 months — 6 years of post-secondary education Master's degree (Bac+5) with experience Part-time — Fridays & Saturdays Paris-Villejuif Campus
Learn more about the program → RNCP Level 7 Certification
06

When Security Becomes a Matter of Architecture

Meta explicitly acknowledges that an agent like Muse can make mistakes and can be compromised by the data it accesses. The best-known risk is indirect prompt injection: a malicious instruction embedded in a web page, email, or document can attempt to hijack the agent’s behavior. OWASP also identifies tool abuse, privilege escalation, data exfiltration, and memory poisoning as risks specific to agent-based systems.[2][6]

Muse combines several layers of protection: virtual machine isolation, separation of secrets, network output control, granular permissions, human validation, and logging. This defense-in-depth approach is consistent with cybersecurity best practices. However, it does not make the system invulnerable.

A concrete example brought this to light a few days after the launch. On September 21, 2026, security researcher Patrick Wardle published a proof-of-concept regarding the Muse app for macOS. The vulnerability allowed a local process already running under the user’s account to modify an undocumented setting and hijack dictation traffic, posing a risk of the Muse authentication token being compromised. It is important not to overstate the scope of the incident: the attack already required local code execution and did not, on its own, constitute a remote intrusion into a healthy Mac. Meta subsequently released a quick fix, according to several specialized media outlets.[7][8]

This incident illustrates a structural challenge: the more permissions an agent has, the more significant the consequences of a vulnerability in the software hosting it can be. An agent’s security therefore depends not only on its resistance to prompt injections, but on the entire software chain: client, authentication, permissions, connectors, browser, operating system, and update mechanisms.

07

Personal Data, Consent, and the European Framework

Muse’s personalization relies on the storage of information and connections to third-party services. Meta states that users can choose which apps to connect, modify permissions, request that certain information be deleted, and disable the use of their interactions for model training. The company also states that Muse conversations and data from its virtual assistant are not shared with its advertising systems. These are commitments made by Meta; a comprehensive assessment of them also requires an examination of the contractual policies and the actual processing carried out.[1]

In the European Union, the relevant legal framework is not limited to the AI Act. If Muse were offered there, the processing of personal data would have to comply with the GDPR, among other requirements. The obligations would depend on the nature of the data, the purposes, the responsible parties, and the connected services. For interactions with an AI system, Article 50 of the AI Act has, since August 2, 2026, imposed certain transparency obligations so that individuals know when they are interacting directly with an AI. These rules do not mean that all personal assistants are automatically classified as high-risk systems.[9]

Purchases or reservations also raise issues related to consumer law and proof of consent. While an agent can technically process a transaction, the user’s identification, understanding of the total price, the terms of the contract, the return policy, and the ability to dispute an error remain critical. Automation does not eliminate these obligations.

08

Where Muse is available as of October 2, 2026

Muse's availability has expanded rapidly. On September 8, Meta announced a rollout in the United States on iOS, Android, and the web. On September 24, the company stated that the service was now available in the United States, Canada, and Mexico, with additional markets to be announced in the future.[1][4]

Muse is also available on Mac, and Meta has announced its integration with AI glasses. These expansions show that Meta no longer positions Muse as just an app: the company is seeking to turn it into an assistance layer accessible across multiple devices and services.[4]

As of October 2, 2026, Meta has not announced a specific launch date for Muse in France or, more broadly, in the European Union. It would therefore be incorrect to present the product as already available to the French public. Any changes regarding this matter must be verified before the article is published or updated.

09

What to Watch for Now

Muse is a particularly prominent example of the shift from conversational AI to action-oriented AI. But the crucial question is not merely how many tasks the agent can perform. It is to determine under what conditions delegation becomes sufficiently reliable, reversible, and understandable to be acceptable.

Several indicators will be key in the coming months: the actual frequency of errors, security incidents, the quality of consent mechanisms, changes in permissions, the ability to explain the actions taken, international availability, and any adjustments required by regulators. It will also be important to observe whether users choose to grant an agent long-term access to the most sensitive aspects of their digital lives.

The major change introduced by Muse, therefore, is not simply that an AI can make reservations or purchases. It is that generative software can become an active intermediary between a person and the digital services they use. As this delegation expands, trust will need to rely less on the promise of ever-more-autonomous intelligence and more on verifiable guarantees of control, security, and accountability.

Learn more

To explore in greater depth the transition from conversational assistants to agents capable of performing actions, four articles on the aivancity blog provide further analysis.

Sources

[1] Meta, September 8, 2026. Introducing Muse: The World’s First Personal AI Agent Built for Everyone. View source

[2] Meta AI Research, September 8, 2026. How We Built Safety Into Muse. View source

[3] Meta AI, 2026. Muse: Your Personal AI Agent. View the presentation

[4] Meta, September 24, 2026. Meta Connect 2026: Meta Announces New AI Glasses, Updates for Muse, and the Meta VR Glasses. View source

[5] Meta AI, 2026. Download Muse. Visit the page

[6] OWASP, 2026. AI Agent Security Cheat Sheet. View the recommendations

[7] InfoQ, September 24, 2026. Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client. Read the article

[8] The Verge, September 2026. Meta Patches Muse Exploit That Let Attackers Control the AI Agent. Read the article

[9] European Commission, July 20, 2026. Guidelines on Transparency Requirements for AI System Providers and Deployers. View the guidelines

[10] European Commission, February 17, 2026. Two years of the Digital Services Act ensuring safer online spaces. View source

[11] Business Insider, September 2026. 5 BI Staffers Who Put AI Agents to Work Share What Worked and What Went Wrong. Read the article

Don't miss our upcoming articles!

Get the latest articles written by aivancity experts and professors delivered straight to your inbox.

We don't send spam! Please see our privacy policy for more information.

Don't miss our upcoming articles!

Get the latest articles written by aivancity experts and professors delivered straight to your inbox.

We don't send spam! Please see our privacy policy for more information.

Related posts
Agent-Based AIInnovation & Competitiveness Through AI

Gemini 3.8 Flash and Flash Cyber Take on the Cyber Challenge

Unveiled by Anthropic on September 1, 2026, Claude Fable 5.1 and Claude Mythos 5.1 are based on the same model but do not provide access to the same sensitive uses. Fable is widely available with safeguards in place…
Agent-Based AI

Claude Fable 5.1 and Mythos 5.1 Face Off Against the Guardrails

Unveiled by Anthropic on September 1, 2026, Claude Fable 5.1 and Claude Mythos 5.1 are based on the same model but do not provide access to the same sensitive uses. Fable is widely available with safeguards in place…
Agent-Based AIInnovation & Competitiveness Through AI

GPT-6 Astra: What Its Agent-Like Capabilities Really Change

Launched by OpenAI on September 3, 2026, GPT-6 Astra combines reasoning, tool use, and control of digital interfaces to perform tasks that go beyond simple text generation. The published results show significant progress…