Meta Muse Is Live at $20 and $100 a Month, and It Wants Your Inbox
- What happened
- On September 8, 2026, Meta launched Muse, a US consumer AI agent powered by its Muse Spark model, with a free tier, Power at $20/month and Maximum at $100/month.
- Why it matters
- It asks for email, calendar, payments, health and smart home access, and every security guarantee around that access is Meta's own claim with no published independent audit.
- What to do
- If you try it, connect one low-stakes service first, and keep payments and health data out until an independent audit is published.
Our verdict: conditional. Meta Muse is worth a careful trial on one low-stakes connector. It is not yet the place for your payments or health data. Every security guarantee around that access comes from Meta, and Meta's own security post points to a bug bounty and to auditors still reviewing an unreleased system, not to a published audit.
What happened
Meta launched Muse on September 8, 2026, a consumer personal AI agent for users in the US.
| Detail | What Meta shipped |
|---|---|
| Free tier | Usage limits, an in-app meter showing how much usage is left, and a warning when free usage runs out |
| Power | $20 a month |
| Maximum | $100 a month |
| Signup | A payment card is required to get started, free tier included |
| Platforms | Web at muse.ai, iOS, Android and WhatsApp. Meta says its AI glasses are coming soon |
| Model | Muse Spark, per TechCrunch. Meta's security post names Muse Spark 1.3 as the model trained to resist prompt injection. We rate it conditional |
Muse connects to email, calendars, payments, health and fitness, smart home, dining, shopping, music and events. Checkout runs through Link by Stripe, which offers purchase protections. Shopify Shop Pay and 1Password integrations are coming soon.
Where a service has no built-in connector but offers a public API, Muse can connect using credentials the user provides. Where there is no API, it can use the service through a browser instead.
Meta's security claims, in Meta's words
Everything in this list is Meta describing its own system, from a technical post by Meta Superintelligence Labs published on launch day.
- Muse Secure VM. Meta says you and your Muse share "your own dedicated computer in the cloud", with a Chromium-based browser running behind a virtualization layer.
- Sentinel. Meta says Sentinel is "a separate host-side agent from your Muse" and the sole permission authority for connector actions and all network egress, with approval dialogs for sensitive operations.
- Credentials. Meta says what you enter "goes straight to secure storage and is not visible to your main agent".
- Payments. Meta says a single-use card number is issued for a purchase and passed to the merchant's website.
- Ads. Meta says "Muse doesn't share your conversations or the data in your Virtual Machine with Meta ad systems."
- Outside review. Meta says it has opened a bug bounty to anyone, awarding up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user. It also says it has begun giving external auditors the design and source code of Muse Confidential VM, a system it plans to deliver later this year, and is still taking their feedback.
TechCrunch's Sarah Perez writes that these claims "will require deeper investigation by security experts". Meta's post cites no published independent audit results. We attribute these claims. We do not endorse them.
Why it matters
The pricing is the honest part of this launch. $20 and $100 a month is a real product with a real bill. The hard part is how much access it wants. Muse asks one vendor to hold your inbox, your calendar, your health data and a payment rail, and the protections around all of that are self-published. It comes from the company that, as Facebook, took a then-record $5 billion FTC settlement in 2019, and TechCrunch notes the Cambridge Analytica scandal still lingers in some people's minds.
The credential path gives Muse even more reach. An agent holding API credentials you supply, or driving a website through a browser, can do whatever those credentials allow, on services that may not have been built with agent access in mind.
The bug bounty is a real step. A payout of up to $130,000 for a single-user prompt injection shows Meta is pricing that attack class seriously. But a bounty surfaces bugs after launch. It is not an audit. And Muse Confidential VM, the system Meta says is intended to stop Meta itself from accessing data in your VM, is something Meta plans to deliver later this year.
What changes for you
The order you connect things in matters more than whether you try Muse at all.
- Start small. Use the free tier and connect exactly one low-stakes service, such as a secondary calendar. You will still need a payment card to sign up.
- Hold back payments and health. Keep payments, health and fitness data disconnected until an independent audit is published.
- Treat credentials as production access. Whatever an API credential you hand Muse unlocks, Muse can drive.
- Do the subscription math. If you already pay for a general assistant, price Power at $20 and Maximum at $100 against it before adding another bill.
- Consider the self-hosted route. If you would rather keep the agent on your own hardware, see how Muse compares with the self-hosted, MIT-licensed OpenClaw in our Meta Muse vs OpenClaw comparison.
FAQ
How much does Meta Muse cost? Muse has a free tier with usage limits, Power at $20 a month and Maximum at $100 a month. A payment card is required to get started, even on the free tier.
Where is Meta Muse available? Meta introduced Muse for users in the US, on the web, iOS, Android and WhatsApp. Neither Meta's security post nor TechCrunch's launch report mentions availability in other countries.
Has Meta Muse's security been independently audited? Not publicly. Meta has opened a bug bounty and says external auditors are reviewing the design and source code of Muse Confidential VM, which it plans to deliver later this year. Meta's security post cites no published audit results.
What model powers Meta Muse? TechCrunch reports Muse is powered by Meta's Muse Spark model, and Meta's security post names Muse Spark 1.3 as the model it trained to resist prompt injection. Our directory rates Muse Spark 1.3 conditional.
What to do
- 1 If you evaluate Muse, start on the free tier and connect exactly one low-stakes service, such as a secondary calendar. A payment card is still required to sign up.
- 2 Keep payments, health and fitness data disconnected until an independent audit is published. Today, Muse's security claims are Meta's own.
- 3 Treat any API credential you give Muse as production access: whatever it unlocks, Muse can drive.
- 4 If you already pay for a general assistant, price Power at $20 and Maximum at $100 against it before adding another subscription.
- 5 If you would rather keep the agent on your own hardware, read the Meta Muse vs OpenClaw comparison before choosing.
Affected tools & models
Never need to catch up again
The weekly delta — only verdict changes and act-now items. No digest filler.