An $18 Billion Settlement Behind It, Meta Makes Its Biggest Consumer AI Bet Yet
Less than two weeks after Meta agreed to a massive $18 billion multistate settlement over social media’s harms to consumers, the company has made its boldest consumer AI bet to date — one that requires significantly more trust than social media ever did. On September 8, Meta officially launched Muse, a personal AI agent it calls “the world’s first personal AI agent built for everyone,” rolling out first to U.S. users aged 18 and over.
It’s the first concrete piece of CEO Mark Zuckerberg’s vision of “AI superintelligence available to everyone.” In the ChatGPT era, AI chatbots answered questions, served as sounding boards, even became digital companions. Muse is built for what comes next: AI that actually does things for you.

What Muse Does: An AI Worker That Opens Browsers, Fills Forms and Negotiates
Muse is positioned as a “personal AI agent.” Give it a goal, and it develops a personalized plan, coordinates your time and resources, then advances the work on its own: opening a browser, filling out forms, even negotiating on your behalf. Its task list includes:
- Email & scheduling: sending emails, managing calendars, arranging meetings
- Shopping & payments: online checkout via Stripe Link (with purchase protections), lowering bills
- Travel: booking flights and hotels, planning entire trips
- Everyday life: turning recipe reels into grocery lists, sending party invitations, booking restaurants
- Long-term goals: keeps working in the background even after you close the app
Notably, Muse learns from your conversations what matters to you and makes suggestions unprompted. It remembers details you mentioned only once and puts them to work in later conversations.
The Privacy Storm: Internal Tests Leaked a Child’s Private Photos
Muse works by connecting to the apps and services of everyday life — email, calendars, payments, health, smart home and more. That’s exactly where the controversy lies. To use Muse, you have to trust Meta more than ever before.
More awkwardly, as Straits Times reported, internal testing found that Muse incorrectly leaked a child’s private iCloud photos, and insiders had already voiced concerns that the technology “mismanages access to sensitive personal data.” That explains why “safety” and “privacy” were the words most repeated at the official launch.

Under the Hood: Muse Secure VM and the Sentinel Watchdog
To answer the skeptics, Meta built Muse on a distinctive two-layer defense architecture:
- Muse Secure VM: Muse runs on a “dedicated, secure computer” in the cloud with its own browser, fully isolated from other users’ agents. Meta says Muse has no visibility into your passwords or payment methods, and doesn’t share conversations with Meta’s ads systems.
- Sentinel: a separate AI agent runs on the same virtual machine but is walled off from Muse at the system level — anything Muse tries to send to the internet must pass Sentinel’s approval. Effectively, an AI watching the AI, 24/7.
- Confidential VM (later this year): encrypted so that even Meta itself cannot read it, as a higher-tier privacy option.
Users keep control too: connect apps one at a time, opt out of having conversations used for AI training, and instruct Muse to “forget” specific things it has learned.
Pricing: Free to Start, Power at $20 / Maximum at $100 per Month

Muse is free to use, but requires a payment card to get started — because once free usage runs out, subscriptions kick in:
- Power plan: $20/month
- Maximum plan: $100/month
The app includes a usage meter, warns when free usage is running out, and guides users to subscribe. Meta believes most people will stay on the free tier. Access points include muse.ai on the web, iOS/Android apps, and chats inside WhatsApp; an AI glasses version is “coming soon.”
The Trust Deficit: Meta’s Rap Sheet
Meta bills Muse as the first personal AI agent designed for everyone, but the market is hardly empty — OpenAI’s ChatGPT Work, Anthropic’s Claude Cowork, Microsoft’s Copilot Tasks and Google’s own attempts are all fighting over “AI that does things for you.” Muse’s differentiation is a bet on ease of use and privacy design: works out of the box, zero learning curve, as simple as sending a message.
But as TechCrunch put it bluntly: the problem isn’t technology, it’s trust. Meta’s record includes a 2011 FTC settlement over privacy deception; a then-record $5 billion FTC penalty in 2019 across eight privacy violations; another 2023 FTC charge of violating a privacy order; hundreds of millions of user passwords stored in readable formats discovered the same year; the Cambridge Analytica scandal that still lingers; and just last month, an $18 billion settlement with 29 states over youth-harm lawsuits — alongside a $942 million New Mexico judgment and thousands of pending personal-injury cases.
On launch day, Meta shares popped 1% before sliding into the red — the market, it seems, is still deciding whether to take “Zuckerberg says trust me” at face value.
Conclusion: The Agent Era Arrives — the Question Is How Much You’ll Hand Over
Muse marks a clear turn in AI’s evolution: from chatbots that answer questions to digital workers that run your life. Technically, the dual-agent isolation architecture is the industry’s first serious attempt of its kind; commercially, the $20–$100 subscription pricing sets a benchmark for the agent economy.
But the decisive factor isn’t model capability — it’s trust. A company that just paid an $18 billion privacy settlement is asking for the keys to your email, payments and health data. Will you hand them over? Muse’s fate will define the trust floor of the consumer AI agent era.
🎬 Related Video
Meta Launches Muse Personal AI Agent — After Leaking a Child’s Photos in Tests




