Meta's Muse AI Agent Is Useful but Demands Deep Account Access, Review Finds
Meta is offering Muse, a U.S. personal AI agent that can shop, send emails and complete online tasks, but a TechRadar test found the convenience came with discomfort over granting broad account access.
Muse is available as an app, through WhatsApp or at the Muse.ai portal, TechRadar reported. It is currently limited to U.S. adults. There is a free usage tier, while heavier users can pay $20 per month for Power or $100 for Maximum. Meta describes Muse as an agent that understands a user's goals and advances them independently. It works by opening a browser inside its own cloud-based virtual computer and moving between connected services, returning when it has finished a task, encountered a problem or needs permission for something sensitive.
TechRadar's reviewer began with shopping, asking Muse, nicknamed Scout, to find a pair of shorts. The agent asked for a size, spent a few minutes browsing and returned with options, pointing to a sale on one set. When the reviewer agreed to buy, Muse asked for an Amazon login to complete the purchase. TechRadar described the moment as reassuring and unsettling in almost equal measure, because it showed both how useful delegation can be and how much access it requires.
Meta says credentials entered this way are routed directly into secure credential storage and are not visible to the main Muse agent, according to TechRadar. Once stored, they can be inserted into the browser when needed without exposing the actual credentials to Muse's browser subagent. The reviewer remained responsible for deciding whether money actually left the account. TechRadar recommended this kind of shopping task as an easy first test because it demonstrates the agent without immediately granting access to years of personal correspondence.
The reviewer next gave Muse permission to go through an inbox and write on their behalf. Muse asked to use email to learn about the user. TechRadar said the resulting picture of the reviewer's life was as distorted as might be expected from an AI basing its impression solely on email. Scout also surfaced an unopened message from a power company about checking solar panels and offered to write a reply once the reviewer picked from suggested visit dates. A draft was waiting for approval a minute later.
TechRadar said the email task felt different from pasting a message into an AI chatbot because Muse could retrieve context itself instead of making the user act as a courier between the inbox and the AI. It also felt much more personal. Meta has acknowledged the sensitivity of this access and built defenses, TechRadar reported. Muse's email connector filters out one-time tokens, password-reset links and login links, while its Sentinel security layer controls what actions the agent is permitted to take outside its virtual machine. When an action requires approval, the request comes through Muse's interface rather than relying on the agent to interpret a conversational yes.
The review said convenience and discomfort grew together as the reviewer used Muse more. TechRadar found Muse more frictionless than similar services with virtual browsers, and said the combination of data Meta already holds and data the agent was permitted to access made it feel personal. Each improvement in Muse's ability to help came with another small moment of deciding how much access to grant. For email, TechRadar said it would keep the approval friction in place, arguing that saving three minutes responding to a utility company is not worth discovering that an AI assistant has developed an unexpectedly adventurous correspondence style.