New Delhi: Meta’s new artificial intelligence agent, Muse, is rapidly gaining attention for its ability to carry out everyday digital tasks on behalf of users. Unlike conventional chatbots that primarily respond to prompts, Muse is designed to act on instructions, including sending emails, booking flights, managing schedules and shopping online.

The AI agent, launched earlier this month, has already reached the No. 1 position among free apps on Apple’s US App Store. According to data cited by India Today from Sensor Tower, Muse recorded about 7.3 lakh downloads within five days of its September 8 launch. Its first 13-day downloads crossed 4 lakh for Claude and 2 lakh for Grok, although ChatGPT recorded about 31 lakh downloads during a comparable period.

The rapid adoption has also brought greater attention to questions around privacy, cybersecurity and the amount of access an AI agent should have to a user’s digital life.

What is Meta Muse?

Meta has positioned Muse as a personal AI agent capable of working in the background after receiving instructions from a user.

The agent can connect with services such as email, calendars, payment platforms, shopping applications and smart-home systems. This allows it to perform tasks that traditionally require users to switch between multiple apps and complete them manually.

Muse runs on Meta’s Muse Spark AI model, developed by the company’s Superintelligence Labs, led by Alexandr Wang. Meta is offering the agent through a free tier as well as paid plans costing $20 and $100 per month, according to India Today.

The initial rollout is aimed at adults in the US, with access available through a dedicated application and WhatsApp.

Muse can act instead of simply answering

The biggest difference between Muse and a conventional chatbot is its ability to take action.

A user can give the agent an instruction and allow it to complete a task using connected services. This can include arranging travel, sending an email, maintaining schedules or purchasing products online.

Users can also transfer information from Facebook, Instagram and Threads, allowing Muse to build a broader understanding of their preferences and digital activities.

This approach reflects the broader shift in AI from systems that generate information towards so-called agentic AI, where software can interact with online services and complete multi-step tasks.

OpenAI and Anthropic also offer AI systems with agent-like capabilities, but Meta is placing greater emphasis on using Muse as a personal digital assistant.

Why Muse is attracting attention

The convenience offered by Muse is one reason for its rapid adoption.

Instead of separately opening a travel website, email application, calendar and payment service, users can potentially ask an AI agent to coordinate several steps. This could make routine digital activities considerably simpler.

Meta CEO Mark Zuckerberg has described Muse as an agent that understands users’ goals and can work around the clock to accomplish tasks. The company has also presented it as a system designed to operate continuously rather than simply respond during a chat session.

Meta’s shares rose more than 11% on Monday following the growing attention around Muse, according to the India Today report. Investment firm Evercore ISI described the product positively, while Zuckerberg’s reported net worth also rose alongside the increase in Meta’s share price.

Privacy concerns over personal data

The same capabilities that make Muse useful also create a larger privacy question: an AI agent needs access to personal information to perform tasks on a user’s behalf.

Meta says users decide which applications Muse can access and can revoke permissions. The company also allows users to prevent conversations from being used to train its AI models.

Zuckerberg has said Muse was designed with privacy and security in mind. According to Meta, user data and credentials are stored in a secure virtual machine, described as an isolated Linux computer with its own browser, CPU, memory and storage.

However, the India Today report cited testing described by Wired in which Muse reportedly suggested obtaining additional personal information or access, including information connected to finances. The report also said the agent suggested monitoring inboxes and using meal photographs for calorie estimates.

Meta says data used for training is sanitised to remove identifying information. However, India Today noted that the company has not publicly detailed how the sanitisation process works when information is obtained from connected services such as email or financial accounts.

Reported security vulnerability raises concerns

Security researchers have also raised concerns about the Muse application.

According to Ars Technica, macOS security researcher Patrick Wardle identified a reported zero-day vulnerability that could allow a local application or terminal command to modify undocumented Muse settings.

The report said an attacker could redirect the endpoint used for transcription and potentially obtain an authentication token associated with the user’s Muse account. Wardle said such access could potentially allow an attacker to manipulate the agent and use its privileges to perform actions, including writing malicious files or taking photographs.

These findings highlight a broader challenge with AI agents. A conventional chatbot generally provides information in response to a prompt, whereas an agent connected to email, shopping accounts and other services may have permissions to act in the real world.

That means security vulnerabilities can potentially have consequences beyond inaccurate AI-generated answers.

Amazon blocks Muse from its shopping platform

The concerns have also affected how other technology companies interact with Muse.

Amazon has reportedly blocked Muse from its shopping website, citing privacy and security concerns. According to the India Today report, Amazon said it had not been informed in advance and alleged that Muse could bypass certain personalisation features and capture or store customer credentials and account information.

Amazon’s position illustrates the challenge faced by online platforms as autonomous AI agents begin interacting directly with websites.

Traditional websites are generally designed for people to browse, search and make purchases. AI agents introduce another category of user — software that can navigate websites and potentially make decisions or transactions on behalf of a person.

Shopify takes a different approach

While Amazon has blocked Muse, Shopify is working with Meta on agentic commerce.

Shopify CEO Tobias Lütke has announced a partnership with Meta that will allow agentic checkout on Shopify stores, according to India Today. This means AI agents could potentially interact with participating Shopify merchants as part of a more structured purchasing process.

The contrasting approaches show that businesses are still working out how AI agents should interact with online services and what permissions they should have.

Meta says Muse was developed over a longer period

Meta has rejected suggestions that Muse was simply copied from another agentic AI platform.

Open-source agent platform OpenClaw creator Peter Steinberger said Meta had built its own agent, while acknowledging that the company had been inspired by existing work. Alexandr Wang also shared an internal document showing that Meta had been planning a personal AI agent since September 2025.

The development comes as Meta increases its focus on advanced AI and agentic systems under its Superintelligence Labs.

The bigger question around AI agents

Muse’s rise illustrates both the potential and the risks of AI agents.

For consumers, an agent capable of managing emails, travel, shopping and schedules could reduce the time spent on repetitive digital tasks. But the same functionality requires users to grant the system access to increasingly sensitive information and services.

The security of those connections, the way personal data is stored and processed, and the ability of users to control an agent’s actions will therefore become important issues as agentic AI becomes more widespread.

For now, Meta’s Muse remains available initially to adults in the US, while its growing popularity and the concerns raised around privacy and security are likely to influence how similar AI agents are developed and regulated.

Conclusion

Meta Muse represents a shift from AI assistants that primarily answer questions to AI agents that can perform tasks on a user’s behalf. Its ability to connect with email, calendars, shopping platforms and other services has helped the product attract significant attention since its September launch.

At the same time, the extensive access required by an autonomous agent creates new privacy and cybersecurity challenges. Reports of a security vulnerability and Amazon’s decision to block Muse from its shopping platform have added to the debate.

Meta says it has built Muse with privacy and security controls, including permission management and a secure environment for user credentials. How effectively those safeguards work in real-world use will remain an important question as AI agents take on more responsibilities in people’s digital lives.