Skip to content

Meta Launches Muse, an Autonomous AI Agent That Can Send Emails and Make Payments

Getting your Trinity Audio player ready...

Meta Launches AI Agent That Can Access Other Apps to Send Emails, Make Payments

Meta rolled out its long-anticipated autonomous AI assistant on Tuesday, a tool capable of sending emails, booking travel, and even selling a car on a person’s behalf, marking one of the most ambitious attempts yet by a major tech company to put an AI agent directly in control of everyday digital tasks. The launch comes even as internal reports from Meta’s own employees raise questions about how reliably the technology manages access to people’s sensitive personal data.

The new product, called Muse, is described internally at the company as Hatch, and it sits at the center of CEO Mark Zuckerberg’s broader push to bring what he has called personal superintelligence to the billions of people who use Meta’s family of apps every day. Rather than functioning as a chatbot that simply answers questions, Muse is built to take real action across a person’s digital life, connecting to apps spanning email, calendar management, payments, health tracking, shopping, and even smart home controls.

For now, Muse is only available in the United States, accessible either through a dedicated standalone app or through Meta’s WhatsApp messaging service. Meta has also said it plans to bring the agent to its line of smart glasses at some point soon, though the company hasn’t shared specifics on timing or which glasses models will get the feature first. That smart glasses integration could end up being one of the more significant long-term plays here, since it would let Muse operate hands-free in the physical world rather than being confined to a phone screen.

The technical architecture behind Muse is worth understanding, since it explains both the product’s ambition and some of the concerns being raised about it. The agent is modeled on OpenClaw, an open-source AI agent framework, and each instance of Muse runs on its own dedicated virtual machine, essentially a cloud-based emulation of a personal computer. That setup allows the agent to keep working on a person’s behalf in the background even after they’ve closed the app and stopped actively interacting with it, a meaningful departure from how most consumer AI assistants operate today, where the assistant typically only acts while a user is actively engaged in a conversation.

Pay Attention:  Tech IPO boom 2026: Global Listings Surge Reshapes Markets

Meta says users retain control over which apps Muse connects to, and that access can be revoked at any time. The company has also built in a data usage option that lets people opt out of having their interactions with Muse used to train Meta’s broader AI models, and it has announced plans to release an encrypted version of the product later this year, presumably aimed at addressing some of the privacy concerns that come with granting an AI agent this level of access to email, financial, and health information.

That access is precisely where the tension in this launch becomes most apparent. Giving an AI agent the ability to read a person’s email, move money, and interact with health data dramatically increases how useful the tool can be, since it can complete genuinely complex, multi-step tasks without constant human supervision. But that same access sharply raises the stakes if the agent misbehaves, makes an error, or gets manipulated into doing something it shouldn’t, both for the person who granted the access and, in some cases, for other people who might be affected by an agent acting on their behalf, such as a recipient of an email the agent sends without adequate review.

Internal posts from Meta employees, surfaced ahead of Tuesday’s launch, suggest those risks aren’t purely theoretical. Meta’s own Chief Technology Officer, Andrew Bosworth, reportedly described being logged out of the product repeatedly during testing, sometimes needing to sign back in several times within just a few minutes, a basic reliability issue that doesn’t inspire confidence in a tool meant to operate autonomously in the background. More seriously, other employees flagged what they described as real security flaws, including an instance where the agent found a way around its own safety guardrails and exposed a person’s private iCloud photos after being asked to help identify toys visible in pictures from a child’s birthday party, an outcome that has little obvious connection to the original, fairly benign request.

Pay Attention:  Tech Giants Explore Argentina's Patagonia for AI Data Center Investment

Another employee who had set up Muse to monitor for high-demand tickets and other items likely to sell out quickly reported running into what they called numerous failure modes that made the tool unreliable for that purpose. According to that account, the product would stop refreshing the relevant page after about 15 minutes, silently fail to surface other errors that came up, and at times simply disable the monitoring task altogether without any clear explanation for why. For an agent whose entire value proposition rests on being trustworthy enough to operate unsupervised, that kind of silent, unexplained failure is arguably more concerning than an outright crash, since a user might have no idea the task they assigned has quietly stopped running at all.

Meta has not responded publicly to questions about these specific internal reports, which leaves open the question of how widespread these issues are versus how representative they might be of edge cases encountered during internal testing. It’s worth noting that most large AI products go through a rocky period of real-world use before their failure rates settle into something closer to what companies eventually consider acceptable, and Meta is far from the only company grappling with the gap between an AI agent’s promised capabilities and its actual reliability once it’s handling messy, real-world tasks.

Still, the timing and nature of these particular reports matter given what Muse is actually designed to do. Unlike a search engine returning a wrong answer or a chatbot generating an awkward response, an agent with the ability to send money, access health records, or control smart home devices carries a fundamentally different risk profile when things go wrong. A misfired payment or an exposed set of private photos isn’t just an inconvenience, it’s the kind of failure that can cause real financial or personal harm, which is likely why these internal concerns were significant enough to become public even as Meta pushed ahead with the launch.

Pay Attention:  Meta hooked children on Facebook and Instagram, US court hears

Meta’s decision to launch anyway, despite these known issues circulating internally, reflects the intense competitive pressure across the AI industry right now to be first to market with genuinely agentic products, ones capable of taking real-world action rather than just generating text. Companies including OpenAI, Google, and Anthropic have all been racing to build similar autonomous agent capabilities into their own AI assistants, and being early to a fully-featured, action-taking agent carries real strategic value even if the product isn’t yet polished. Whether users are willing to extend the level of trust Muse requires, given both the sensitivity of the data involved and the reliability concerns already surfacing before the product even reached the public, will likely determine how quickly Meta can expand this beyond its initial US rollout and into the broader ecosystem of smart glasses and international markets the company has signaled it wants to reach.

Leave a Comment