Muse: Meta’s AI Takes Action?

·

Meta’s personal AI agent promises to handle tasks beyond the chat window. Its early clash with Amazon shows why user control and access to the wider web will matter as much as capability.

Meta introduced Muse on September 8, 2026, as a personal AI agent designed to help people turn goals into action. The company says it can browse websites, fill out forms and continue working after a user closes the app. These capabilities suggest a more substantial form of delegation than asking a chatbot for advice, according to Meta’s launch announcement.

But delegation involves more than the relationship between a person and an assistant. On September 20, GeekWire reported that Amazon said it had blocked Muse from shopping on Amazon.com on customers’ behalf. The dispute brings an immediate practical question into focus: where will an agent actually be allowed to work?

Editorial note: On Tech Now has not independently tested Muse. This article examines the company’s documentation and attributed reporting, alongside our editorial analysis.

From conversation to delegation

Consider a simple task: planning a weekend trip.

In a basic chat exchange, an assistant might suggest destinations and help organize an itinerary. The user then checks availability, compares prices and completes any bookings.

An agent workflow delegates some of those intermediate steps. The user supplies a goal and boundaries; the software works through the tasks its tools and permissions allow.

Split-screen comparison of a chatbot exchange on one side and an agent workflow on the other
A chatbot answers and waits; an agent works through steps toward a goal.

These are overlapping capabilities, rather than completely separate product categories. A conversational interface can also provide tools that take action. The useful distinction is how much work the system performs and how it keeps the user informed.

Muse’s product team describes a browser that can navigate sites and complete transactions, along with the ability to create documents and other outputs. It also describes ongoing tasks that respond to schedules or relevant events, as set out in How We Designed Muse. These are the company’s descriptions of the product, rather than results from OTN testing.

For a user, the potential benefit is less coordination between websites and services. Whether that becomes a meaningful saving depends on the time needed to check results, correct mistakes and handle interruptions.

Human approval needs to be meaningful

Meta’s design explanation describes structured approval cards, an activity log and adjustable controls. It says default behavior allows routine browsing while pausing for actions that are difficult to undo (How We Designed Muse).

Graphic depicting the interaction between a person and an AI system
The handoff between person and agent is where control is won or lost.

That is a useful design principle, but its value depends on what the person sees at the moment of approval.

For a purchase, the relevant information could include the seller, item, quantity, total cost and delivery details. An approval button without enough context would shift the burden of checking onto the user without making that burden obvious.

There is also a balance between supervision and interruption. Frequent, repetitive requests could encourage automatic acceptance. Infrequent requests could leave users surprised by decisions they expected to review.

Our test would be whether the system pauses at appropriate moments, explains the proposed action clearly and makes rejection straightforward. Approval should happen before a consequential action, wherever that point falls within a longer task.

Privacy and memory require usable controls

An assistant that remembers preferences could reduce repetitive instructions. It could also retain information that becomes outdated or that a user would prefer to remove.

Meta’s product team says Muse’s memory files can be read and edited directly. That makes the accessibility of those controls an important part of evaluating the experience (How We Designed Muse).

The company also says users can change connected-service permissions, disconnect access and opt out of having their interactions used to train its models. It says conversations and data in Muse’s virtual machine are not shared with Meta’s advertising systems. These remain commitments attributed to Meta, as stated in its privacy and control disclosures.

A practical review should examine how easily someone can find those settings, understand their effect and correct stored information. The existence of a control is only the starting point; people need to be able to use it confidently.

What Sentinel is designed to do

Meta describes Muse as operating in a dedicated cloud environment. Its technical documentation identifies a separate component, Sentinel, as the authority for connector permissions and outgoing network access. The stated purpose is to enforce boundaries outside the main agent’s control, according to Meta’s security explanation.

This automated protection layer is distinct from a person approving a transaction. Both may be relevant to a task, but they serve different roles.

The same technical documentation acknowledges that Muse can make mistakes and encounter attacks through information it reads. That qualification matters: describing a security architecture does not establish that every action will be safe or correct.

For OTN, reliability would need to be assessed through repeated use, including situations where the system encounters misleading information, incomplete instructions or failed actions.

Amazon introduces another boundary

According to GeekWire’s September 20 report, Amazon said Muse accessed its store without adequately identifying itself as an agent and raised concerns about customer-account access and credentials. These are Amazon’s stated allegations and concerns.

Meta’s launch documentation says Muse cannot see users’ passwords or payment methods and that credentials are held in secure storage. That is Meta’s description of its protections, rather than an independent resolution of Amazon’s objections.

The dispute illustrates a limitation that users may encounter even when an agent understands their request: the service involved may object to the method of access.

A person’s willingness to delegate therefore does not guarantee that every task can proceed. Website policies, technical restrictions and relationships between service providers can affect the result.

This makes access part of the product’s usefulness. An assistant should explain when a service blocks it, what remains unfinished and what the user can do next.

Availability and pricing

Meta announced an initial US rollout on iOS, Android and the web, with communication also available through WhatsApp. It describes free access for common uses and subscriptions for heavier usage (launch announcement).

TechCrunch reports Power at $20/month, Maximum at $100/month, and a payment-card requirement at signup.

These are launch terms; prospective users should check the current offer and usage conditions.

The value calculation also includes the effort required to supervise the assistant. A subscription could be worthwhile if it consistently saves time on useful tasks. That case becomes weaker if setup, correction and verification consume the time it was supposed to free up.

What OTN would test next

A convincing evaluation would use ordinary tasks with clear success criteria. We would record whether each task was completed, how often intervention was required and how much time the full process took.

We would also examine failures. Does Muse recognize missing information? Does it stop appropriately when access is refused? Can the user understand what happened and continue without repeating the entire task?

Summary graphic showing how the Muse agent operates within the limits and permissions it has been given
How Muse works inside the boundaries it is given — the parameters that decide what it may do on its own.

Those results would provide a stronger basis for judging usefulness than a polished demonstration alone.

Muse’s proposition is appealing because everyday work often consists of small steps spread across several services. Coordinating those steps could make an assistant valuable. The early Amazon dispute shows why that value will also depend on the conditions under which it operates.

Our judgment will turn on whether Muse can complete useful work consistently while giving people enough visibility to understand, correct and control what happens.

Watch: our video on Muse


Sources

By On Tech Now
Updated September 22, 2026

Editorial transparency: This article was drafted with generative AI under human editorial direction. On Tech Now is responsible for its final review, accuracy and publication.

Follow On Tech Now for daily coverage.