Would you give an AI your credit card?
Meta’s new Muse agent can book, buy and pay for you. Here are five questions to ask before you let any AI act on your behalf.
Most AI you’ve used so far talks. You ask, it answers, and then you do the actual doing: you send the email, book the table, pay the bill.
Meta’s new app, Muse, is built to do the doing. It launched in the US on 8 September. You give it a goal in plain language, and it opens its own web browser, fills in forms, sends emails, books things and pays for them. It keeps working after you close the app, and it lives in its own app, on the web, on the Mac and inside WhatsApp.
People are clearly curious. Within about two weeks, reports had it as the most downloaded free app on the US App Store.
A note on honesty: we haven’t tested Muse. At launch it’s only available to adults in the US. Everything below comes from Meta’s own announcement and published reporting, linked at the end. If we get our hands on it, we’ll tell you what actually happened.
What’s actually new here
Think of the difference like this. A chatbot is a friend giving you directions. An agent is a friend you hand your car keys to.
Handing over the keys can save you a lot of time. It also means the questions you ask change. It’s no longer “is the answer right?” but “what exactly is it allowed to do while I’m not looking?”
What Meta says keeps it in check
According to Meta:
- Each person’s Muse runs on its own dedicated computer in the cloud, sealed off from everyone else’s.
- A separate watchdog, which Meta calls the Sentinel, checks everything Muse tries to send out to the internet, and asks you when needed.
- Muse asks before sensitive actions like sending an email or making a purchase. You can allow once, always allow, or say no.
- You choose what each connected app allows. For email, for example, you decide whether Muse can only read your mail or can also send on your behalf.
- There’s a complete activity log of what it has done and what it plans to do next.
- You can change access or disconnect a service whenever you want.
- Meta says Muse can’t see your passwords or payment details. They’re kept in secure storage it uses without reading.
That’s a thoughtful set of guardrails, on paper.
What still gives us pause
- It makes mistakes. Meta’s own help pages reportedly warn that Muse may be inaccurate or take unexpected actions. That’s honest of them, and a good reason to go slowly.
- Hidden instructions are an unsolved problem. A web page or an email can contain text written to trick an AI agent into doing something you didn’t ask for. This is an industry-wide issue, not just Meta’s, and it matters most when the agent can act.
- A card up front. Several reports say Muse asks for a payment card even on the free plan. The paid plans are reported at $20 and $100 a month.
- Your data and Meta. When Meta launched the AI model behind Muse in April, Axios pointed out that Meta’s privacy policy sets few limits on how it can use what you share with its AI. Worth knowing before you connect your email, calendar or health apps.
It has already hit a locked door
Around 20 September, Amazon blocked Muse from shopping on Amazon.com. Amazon says Muse is an unauthorised agent that doesn’t identify itself when it browses, and that this breaks its conditions of use. People who send Muse to Amazon now get a message saying so.
Meta’s position, as noted above, is that Muse never sees your passwords or payment details.
Whoever is right, it shows something useful: your AI helper won’t be welcome at every checkout. Expect more of this, because shops want to know who, or what, is buying.
Five questions to ask before you let any AI act for you
Muse is the first mainstream AI agent, but it won’t be the last: ChatGPT, Google and others are heading the same way. These questions work for all of them.
1. What can it see? Connect only what the task needs. Start with read-only access, and add more once it has earned it.
2. What can it do without asking? Keep approvals on “ask every time” for anything that sends, buys, deletes or shares. “Always allow” is convenient, and it’s exactly where surprises come from.
3. What can it spend? Look for a spending limit. If there isn’t one, keep purchases on “ask every time”, and consider connecting a card with a low limit rather than your main one.
4. What does it remember? Muse is designed to remember details you mention once. Find out where those memories are listed, and whether you can delete them.
5. Can you check its work, and pull the plug? Find the activity log and the disconnect button before you need them. If you can’t see what it did, don’t let it do much.
Our take
AI agents are coming to the apps you already use, and some of them will genuinely take chores off your plate. The smart way in is small and boring: let it turn a saved recipe into a grocery list (one of Meta’s own examples) before you let it anywhere near your inbox or your wallet.
Would you let an AI spend your money? Reply to our newsletter or tell us on social. We read everything.
Sources (checked 29 September 2026)
- Meta, “Introducing Muse: the world’s first personal AI agent built for everyone”: https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/
- Axios, on Meta’s Muse Spark model and its privacy policy (April 2026): https://www.axios.com/2026/04/08/meta-muse-alexandr-wang
- Reporting on availability, pricing, the card requirement and App Store rankings: https://tech-insider.org/meta-muse-personal-ai-agent-launch-2026/ and https://chatmaxima.com/blog/meta-muse-ai-agent-businesses-whatsapp-messenger/
- On Amazon blocking Muse: GeekWire, https://www.geekwire.com/2026/amazon-blocks-metas-muse-ai-assistant-in-new-standoff-over-agentic-shopping/ and Bloomberg (21 September 2026), https://www.bloomberg.com/news/articles/2026-09-21/amazon-blocks-meta-s-muse-ai-agent-from-its-retail-site
- On Meta’s help-page warnings and hidden-instruction risks: https://gingerlabs.ai/blog/meta-muse-agent-capabilities-and-how-to-use-it