Mark Zuckerberg posted a video to Instagram on September 8 to introduce Muse, Meta’s new personal AI agent, and used it to show off what he actually does with the thing. He has Muse order the ingredients before a baking session with his daughters. He uses it to sort out permits for a mountain climbing trip. He tracks his MMA training through it and lets it go find researchers he wants to talk to. None of that is just a chatbot answering a question, but a piece of software running someone’s week.
- What Muse actually does that a chatbot doesn’t
- How the checkout actually works
- The isolation Meta built around it
- Why WhatsApp is the whole play
- What it means for people who run a creator business
- India isn’t in this yet, and the reasons are more than a rollout schedule
- Why it’s called Muse, and who had to give up the name for it
Muse is live in the US only, for users 18 and over, on iOS, Android, the web at muse.ai, and inside WhatsApp chats. There’s a free tier metered at 100 million tokens a week, and two paid plans, $20 and $100 a month, for people who burn through that faster.
What Muse actually does that a chatbot doesn’t
Ask a chatbot to write an email and it hands you a draft but someone will still have to copy it, open their inbox, pick the recipient, and hit send.
Zuckerberg’s own framing of Muse on X was: “Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.” The pitch is that the agent finishes the chain a chatbot only starts, opening a browser, filling out the form, sending the email itself, and coming back to ask permission only when money or something sensitive is involved.
Meta’s launch examples lean towards: selling a car for more, getting a bill lowered, turning a recipe reel someone saved on Instagram into a grocery list, remembering a friend’s dietary restriction before the dinner invites go out. This is the kind of admin tasks nobody enjoys doing, which is exactly the bet Meta is making on where the demand sits.

The demo that actually spread on launch day came from AI reviewer Alex Volkov, who ran a small race between Muse and a rival agent called Instinct. He gave both the same task, research and book tickets for a Rosh Hashanah dinner, and posted a screenshot showing Muse had already booked while Instinct was still searching. One person’s test on one evening isn’t proof of anything at scale. But it points at the actual thing Meta built here, which is an agent wired directly into a payment rail, so that when it decides to buy something, it can.
How the checkout actually works
Muse pays through Link, built by Stripe. The agent never sees a real card number, and every purchase total has to be approved inside the chat before the money moves. Meta says Muse is also the first AI agent covered by Link’s purchase protections: damaged or lost items, price drops, no-fee returns, a return guarantee. Alexandr Wang, Meta’s chief AI officer, added on X that the deal comes with a refund guarantee specifically for cases where the agent itself makes the mistake.
All that agents have been able to do up till now is browse and compare prices, what they could not do was actually buy something because nobody wanted to take the blame when the bot bought the wrong item. Link’s protections fix that: a bad purchase becomes a normal refund claim instead of a dispute nobody knows how to resolve. That’s the real product here, and competitors don’t have an equivalent yet.
The isolation Meta built around it
Every Muse user gets a dedicated virtual machine, an isolated computer running in Meta’s cloud with its own browser, where the agent and all its connected logins live. A second, separate agent called Sentinel sits on the same machine and has to approve anything before it leaves for the internet.
Zuckerberg described the mechanism in his own post: “A Sentinel agent separate from your Muse runs on your VM. Every action or piece of data that goes out to the network has to be approved by the Sentinel.”
Passwords sit in storage the agent can use but never actually see, so an agent that gets tricked by a malicious prompt has nothing to hand over even if it tries. Access is granted connector by connector, email can be read-only or read-and-send, and everything the agent does or plans to do lands in a log the user can check. A fully encrypted version, where Meta itself can’t see inside the VM, is promised later this year.
Why WhatsApp is the whole play
The personal-agent category so far has mostly belonged to people who already know what a terminal is. Whereas Muse is far more simple, living inside a chat thread. There’s no setup because talking to it works exactly like messaging a friend, which means the person actually using it doesn’t need to be an engineer. It could be a parent, a shopkeeper, someone’s domestic help who’s never touched a command line in their life.
Meta didn’t need to win this on having the smartest model. It won distribution the day it decided Muse would just show up where a billion people already are, on WhatsApp.
What it means for people who run a creator business
Muse connects to Instagram, Facebook, Gmail, Google Calendar, Ticketmaster, OpenTable, Spotify, Apple Health, and Plaid at launch. For anything else, it can build its own connection or just use the website directly.
For a one-person creator business, the obvious use is everything nobody wants to do between shoots: chasing a brand that hasn’t paid an invoice, rebooking a flight after it moves, sourcing props against a fixed budget and actually buying them.
The uncomfortable use case sits right there in Meta’s own launch reel. Someone saves a recipe video on Instagram, and Muse turns it into a grocery order and buys the ingredients. In that sequence, the video that took someone hours to shoot, edit and post isn’t being watched, it’s being mined for a shopping list, with the actual transaction happening off-platform through Link.
Nobody in that chain gets credit for the recommendation. There’s also a permissions problem specific to creators: reviewers have already flagged that Muse can’t be scoped to a single Instagram account. It’s all or nothing at the login level, which is awkward for anyone whose personal handle and their brand’s page sit under the same credentials.
India isn’t in this yet, and the reasons are more than a rollout schedule
Meta hasn’t given India a date, and the launch announcement is silent on when that might change. That’s despite India being Meta’s biggest WhatsApp market by a wide margin.
Two things are actually in the way. MeitY has already floated mandatory human-in-the-loop approval for agentic AI payments, which happens to be roughly the shape Muse already ships with, just arrived at commercially rather than by regulation. And Parliament’s Standing Committee on Finance tabled a report on August 10 pushing for the Digital Competition Bill to be widened to cover exactly this category of product. Neither is law yet. The bigger obstacle is: Link is a card wallet, and Indian retail runs on UPI, where the rules for letting an agent pay on someone’s behalf are still being written by NPCI. An agent that can’t complete a purchase is just an expensive way to get a chatbot.
Why it’s called Muse, and who had to give up the name for it
Meta has never explained the name in public. What’s on record is that the label already belonged to a family: Muse Spark launched in April, Muse Image in July, Muse Code in August, and this consumer agent inherits the surname. But the more telling detail happened off the press release entirely.
Muse, the English rock band with 2.7 million Instagram followers and two Grammys, had held the handle @muse on Instagram for years. The day Meta launched its agent, the band’s account was quietly renamed to @museband, and @muse now belongs to Meta’s AI. The same swap happened on X.

