It shops, and it pays
Muse takes a stated requirement, works the stores in its own browser, comes back with product cards, and pays with a one-time card from Link by Stripe once you approve the total. It works.
AI agent shopping arrived with reach: Meta's Muse browses stores in its own browser, narrows to product cards and pays with a one-time card from Link by Stripe. Every part of it lives on a computer Meta runs, under Meta's policies. A personal AI is personal only if you own it.
Meta shipped Muse on 8 September: an AI agent shopping for you in its own browser, narrowing the web to product cards and paying with a one-time card from Link by Stripe once you approve the total. It works, and every part of it lives on a computer Meta runs, under policies that in Meta's own words do not prevent Meta from accessing the data to support, secure or operate the service, at a company that paid the Federal Trade Commission a $5 billion penalty in 2019 for undermining its users' privacy choices and settled with 52 state attorneys general for about $18 billion thirteen days before this launch. A personal AI is personal only if you own it, so ask who Muse belongs to.
Start with the announcement, because it is careful and specific. Meta introduced Muse on 8 September as "a personal AI agent" that "doesn't just answer questions, it actually does the work." It runs on Muse Secure VM, "a dedicated secure computer with its own browser," a virtual machine "that houses both the agent and a person's data." It can "open a browser, fill out forms, and negotiate," keep working after you close the app, and come back for approval "before it sends an email or makes a purchase." It "remembers what matters to a person."
When it is time to pay, "Muse can checkout with Link built by Stripe," and it is "the first AI agent covered by Link's purchase protections." Link's wallet for agents "generates a one-time-use card so your real card details stay hidden." It is US only for now, free for most uses, with two paid plans that Sarah Perez at TechCrunch lists at $20 and $100 a month. A payment card is required to start.
That is agentic commerce in one product: an agent that browses, chooses and pays on a person's behalf, with a card that works. It is not a demo. On launch night Scot Wingo at Retailgentic gave it a real job, a coffee machine smaller than the one at his office, under a price, from three brands, and watched it work the sites in its own browser, come back with five product cards, and offer to pay through a one-time card at guest checkout. One of the three brand sites failed it, with 404s on its spec pages. Keep that for later.
3.60 billion
daily active people
Across Meta's apps in June 2026, on Meta's own reporting.
98%
of revenue from advertising
$59.4 billion of $60.8 billion in the quarter to June 2026, our arithmetic on Meta's figures.
1M+
businesses accept Link
Where Muse checks out with the person's saved payment method, per Stripe.
$20 to $100
a month, the two paid plans
Power and Maximum. Free for most uses, a card required to start, per TechCrunch.
Meta reported 3.60 billion daily active people across its apps for June 2026. No consumer agent before this one had a fraction of that in front of it. Reach was the missing piece for every agent that came before, and now it is not missing. Reach does not settle the other question: whose agent is it.
Mark where everything is. The muse.ai page says Muse Secure VM "runs on a persistent, isolated Linux virtual machine equipped with a full browser." Meta's announcement says Muse "runs on its own dedicated computer in the cloud," and then: "That is where Muse lives and where the data and credentials for any service a person connects are securely stored." The memory of what matters to you is on that machine. Your saved logins go to "a secure credential store Muse can't see," on that machine. The browser that visits the stores is on that machine. The product cards were chosen on it. In Meta's words: "Personal agents need a new kind of secure computer, so Meta built one for everyone."
Muse (a computer Meta runs)
An agent you own (your machine, or a host you chose and can leave)
The computer
A virtual machine in Meta's cloud, built by Meta, per its announcement
The computer
Yours, or one you picked and can leave
The browser that visits stores
On that machine
The browser that visits stores
On yours
What it remembers about you
On that machine; you can ask it to forget
What it remembers about you
On a disk you own
Your logins
A credential store on that machine, which Muse cannot see
Your logins
Wherever you keep them
Your card
Tokenised by Link; you approve each total in the chat
Your card
The same one-time card, if you choose it
Who can read the machine
Meta, when necessary to support, secure or operate the service, per its safety post
Who can read the machine
You
What you keep if you leave
An account
What you keep if you leave
The machine, the files and the history
The computer
Muse (a computer Meta runs)
A virtual machine in Meta's cloud, built by Meta, per its announcement
An agent you own (your machine, or a host you chose and can leave)
Yours, or one you picked and can leave
The browser that visits stores
Muse (a computer Meta runs)
On that machine
An agent you own (your machine, or a host you chose and can leave)
On yours
What it remembers about you
Muse (a computer Meta runs)
On that machine; you can ask it to forget
An agent you own (your machine, or a host you chose and can leave)
On a disk you own
Your logins
Muse (a computer Meta runs)
A credential store on that machine, which Muse cannot see
An agent you own (your machine, or a host you chose and can leave)
Wherever you keep them
Your card
Muse (a computer Meta runs)
Tokenised by Link; you approve each total in the chat
An agent you own (your machine, or a host you chose and can leave)
The same one-time card, if you choose it
Who can read the machine
Muse (a computer Meta runs)
Meta, when necessary to support, secure or operate the service, per its safety post
An agent you own (your machine, or a host you chose and can leave)
You
What you keep if you leave
Muse (a computer Meta runs)
An account
An agent you own (your machine, or a host you chose and can leave)
The machine, the files and the history
Now read the document that settles it, Meta's own launch-day post on how it built safety into Muse. It "restricts access to your data by Meta personnel through operational policies." Then the next sentence: "It does not prevent Meta from accessing data when necessary to support, secure or operate the service." The machine that would change that, Muse Confidential VM, "is intended to cryptographically and verifiably prevent Meta from accessing data in your VM," and Meta plans "to deliver this capability later this year." Today the computer your agent lives on is one Meta can read, by policy, and the thing that would stop that is the thing not shipped.
What Meta promises, in its words
"Muse doesn't share a person's conversations or the data in their VM with Meta's ad systems." People "can also opt out of their interactions being used to train Meta's AI models," and "can always tell it to 'forget' specific things it's learned." Access by Meta staff is restricted "through operational policies." Later this year, Meta says, a Muse Confidential VM will encrypt the whole machine "with a key only they hold, so not even Meta can access it."
Take every one of those at face value. The argument does not need Meta to break a promise. It needs you to notice what each one is: a policy. A policy is what you rely on when you do not own the thing. "You decide what your agent can see and what it can do," says the muse.ai page, and that is true. It is control of access. It is not ownership of the machine, the browser, the memory or the store of credentials. Those are Meta's, by design, and the design is the product.
So the question is not whether Muse is good. It is whether you would build the part of your life an agent holds on a policy from this company. Read the record before you answer. Every line below is from the regulator, the court coverage, or Meta itself.
2012
In the Federal Trade Commission's words, the 2012 order "prohibited Facebook from making misrepresentations about the privacy or security of consumers' personal information, and the extent to which it shares personal information."
April 2018
Facebook's chief technology officer, Mike Schroepfer, wrote that "the Facebook information of up to 87 million people, mostly in the US, may have been improperly shared with Cambridge Analytica."
July 2019
The FTC imposed a $5 billion penalty for violating the 2012 order: "Despite repeated promises to its billions of users worldwide that they could control how their personal information is shared, Facebook undermined consumers' choices."
May 2023
Ireland's Data Protection Commission fined Meta 1.2 billion euro after finding it "continued to transfer personal data from the EU/EEA to the USA" in breach of the regulation.
April 2025
The European Commission fined Meta 200 million euro for breaching "the DMA obligation to give consumers the choice of a service that uses less of their personal data."
October 2025
Meta announced: "We will soon use your interactions with AI at Meta to personalize the content and ads you see," effective 16 December 2025 in most regions.
August 2026
Meta settled with 52 state attorneys general over claims that its platforms were designed "to be addictive" and violated "federal privacy and consumer protection laws." Meta denies the allegations and any liability.
The sources, at the claim: the FTC's 2019 release, Facebook's April 2018 post, the Data Protection Commission's May 2023 decision, the European Commission's April 2025 finding, and Steve Kopack's report at NBC News on the settlement.
The line that matters most for Muse is the sixth one. Meta AI was a conversation too. On 1 October 2025 Meta announced that "your interactions with AI at Meta" would personalize "the content and ads you see, including things like posts and reels," from 16 December. The page points you to Ads Preferences to adjust what you see. It names no switch that keeps the conversations out. Muse's promise today, that its conversations and its machine stay out of the ad systems, is the same kind of promise, from the same company, less than a year later.
The terms of the company around the agent say what they say. Meta's privacy policy, effective 23 July 2026: "We personalize the ads shown to you using information from your account," and "we use your information so we show you ads." Meta's revenue in the quarter to June was $60.8 billion, and $59.4 billion of it was advertising, about 98 percent, our arithmetic on Meta's own figures.
None of this predicts what Meta will do with Muse, and Meta denies liability in the settlement. It shows what a promise about your data is worth at a company whose revenue is the use of it: it holds until an announcement changes it. Your requirement, your sizes, your budget, what you will not compromise on, what happened last time, your saved logins and the card behind them are what an agent holds. That is more of you than a feed ever held. Would you put it on that machine?
A feed decides what you see, in what order, and you cannot see why. For other people's photos that was a tolerable trade. An agent that shops is different. It holds your requirement and acts with your money. That is the part of an agent worth owning, for the same reason your wallet is.
Ownership is a stack: the hardware, the operating system, and the agent host that holds your files and logins. The case is made in the harness piece published this week. On Muse all three layers are Meta's, and the reach Meta has makes that the default for a very large number of people at once. Reach solves adoption. It does not settle who the agent serves. A billion users make Muse the widely used agent. They do not make it the shopper's agent. Own where your agent runs, or choose it and keep the right to leave, and then no promise is needed.
The retailer-hosted agent got the same question last week. It is the store's agent, honestly built. Muse is the platform's agent, honestly built. The shopper's agent is the one the shopper owns.
Stripe's own framing of the launch, in its announcement: "E-commerce was built for people. People browse websites, compare prices, enter cards, and complete checkout flows. For agents to become economic actors, they need to be able to navigate the internet as people do." That is now happening with a card that works. At more than 1 million businesses that accept Link, Muse checks out with the person's saved payment method. Everywhere else, Link "issues Muse a single-use virtual card scoped to the approved purchase." The agent arrives in a browser, reads your pages the way a person does, and pays at guest checkout. Remember the brand site with 404s on its spec pages. An agent filtering on size cannot read a page that is not there.
Muse is Meta's personal AI agent, launched on 8 September 2026 in the US on iOS, Android, muse.ai and WhatsApp. Per Meta, it runs on a dedicated virtual machine with its own browser, can fill out forms, negotiate, keep working after you close the app, and asks for approval before a purchase. It pays with a one-time card from Link by Stripe, and in the first week it shopped a coffee machine against a stated requirement and returned five product cards.
SIL is the shopping capability your agent loads: state the spec, hold every candidate against it, judge the result against it. Your specs live with you, across hosts. It runs on OpenClaw, open source under Apache-2.0.
Muse takes a stated requirement, works the stores in its own browser, comes back with product cards, and pays with a one-time card from Link by Stripe once you approve the total. It works.
The browser, what it remembers about you and your saved logins sit on a virtual machine Meta runs. Meta's own safety post says its policies do not prevent Meta from accessing that data to support, secure or operate the service.
A $5 billion FTC penalty in 2019 for undermining privacy choices, up to 87 million people's information shared with Cambridge Analytica by Facebook's own count, and AI conversations turned into ad signal by announcement in 2025.
Memory, credentials and authority on hardware you own, or on a host you chose and can leave. Own where your agent runs, and you need nobody's promise.