i
DATAIST
News · 2026-09-10

Meta's Muse agent runs on WhatsApp and pays through Link

@neuronium_ai @neuronium_ai

Meta has launched Muse, an agent that lives in its own cloud virtual machine, takes instructions through WhatsApp, and can spend money without the user touching a checkout page. It books trips, sends email, fills in forms, and — according to Meta — negotiates on the user's behalf: selling a car for more, talking down a bill, reshaping a training plan. Payments go through Link, the service built by Stripe, which issues a single-use card for each transaction. Muse ships first in the United States on iOS and Android, with a free allowance that refills and subscriptions above it.

Cover: Meta's Muse agent runs on WhatsApp and pays through Link

Meta has launched Muse, an agent that lives in its own cloud virtual machine, takes instructions through WhatsApp, and can spend money without the user touching a checkout page. It books trips, sends email, fills in forms, and — according to Meta — negotiates on the user's behalf: selling a car for more, talking down a bill, reshaping a training plan. Payments go through Link, the service built by Stripe, which issues a single-use card for each transaction. Muse ships first in the United States on iOS and Android, with a free allowance that refills and subscriptions above it.

The agent is meant to keep working after the app is closed. Meta says Muse plans its own steps, allocates its own time and resources, and reports back when something changes or when it needs a confirmation — before an email goes out, before a payment clears. It also retains details about the user and volunteers suggestions, drawing on the rest of Meta's products: a recipe clip saved in Instagram becomes a shopping list, a dinner menu gets built around friends' food allergies.

The payment layer is the part with the most commercial weight. Link hides the real card details behind a one-time card at every purchase, and Meta calls Muse the first AI agent covered by Link's purchase protection, which applies to damaged or lost goods, price drops and returns. Shop Pay and 1Password are supposed to connect later, at which point Muse would be able to use credentials the user has already saved elsewhere.

Muse asks for confirmation before a purchase, and the payment runs through Stripe's Link service

Muse asks for confirmation before a purchase, and the payment runs through Stripe's Link service

Source: the-decoder.com

This is precisely the ground OpenAI gave up. The company dropped its own payment function inside ChatGPT and handed checkout back to merchants: users could still find products in the chat, but they completed the purchase outside it, and onboarding each merchant stayed a manual job. Meta is now doing the harder version — holding the credentials, carrying the card, owning the protection policy — while its competitor retreated to referrals.

Source: the-decoder.com

Most of the announcement went to security, with the detail pushed into a separate post. Muse Secure VM is described as a dedicated cloud machine isolated from outside agents, and it also holds the login data for connected services. A second agent, Sentinel, runs on the same machine but separately from Muse; nothing Muse does is supposed to reach the internet without Sentinel's approval. Meta says Muse itself sees neither passwords nor payment methods — credentials land in a protected store the agent can use but cannot read.

Sensitive actions require a confirmation and a full history of the steps that led there. The user chooses which apps the agent connects to and what it may do inside them — read email only, or also send it — and can change or cut off access at any point. Later this year Meta plans Muse Confidential VM, which is meant to encrypt the entire virtual machine with a key held only by the user.

What Meta does not publish is any reliability figure for that architecture. That absence matters more than the architecture diagram does, because the attacks on agents of this kind are already public: security researchers have shown that manipulated content can take over an agent's control flow, and in Perplexity's Comet browser a forged calendar invitation was enough to seize a password manager account. An agent that holds live credentials, runs unattended after the app closes, and reads content from the open web is the exact shape of target those attacks were written for. Sentinel is a reasonable answer to that risk. Whether it works is a number Meta has chosen not to give.

The data terms have a seam in them too. Users can opt out of having their interactions train Meta's models, and Meta says Muse passes neither conversations nor virtual machine data to its advertising systems, and that the agent will forget what it learned if asked. None of that applies to Meta AI, where since December the company has used assistant interactions to personalize ads and content across Facebook and Instagram in most regions, excluding sensitive categories such as religion, health and political views. So the company is running two different privacy regimes under one assistant brand, and the stricter one sits on the product that has barely any users yet.

Source: the-decoder.com

Meta frames all of this as a step toward what it calls "personal superintelligence," one of the most transformative technologies in its telling, and the subject Mark Zuckerberg made central to the company's recent essay. Muse is presented as the first instance of it.

The model underneath tells a plainer story. Muse Spark, released in April, would score 31 on the current Artificial Analysis Intelligence Index v4.3. Since early September, version 1.3 scores 44 at the xhigh tier available to users and 48 at the max tier, which is open only to partners. GPT-5.6 Sol at Max scores 47; GPT-6 Astra at Max and Claude Fable 5.1 score 53 each.

Read the numbers the way a user experiences them and the gap is not closing as fast as the five-month improvement suggests. The 48 is a partner-only figure. What a person talking to Muse through WhatsApp actually gets is 44 — below GPT-5.6 Sol and nine points behind the two frontier models. Meta's bet is that this is enough, because the agent's value comes from the wallet, the virtual machine and the billion-user messaging app rather than from reasoning quality. That is a defensible bet for booking a flight. It is a much worse one for the negotiation scenarios Meta chose to lead with, where the whole promise is that the model argues better than you do.

The lineage supports the reading. In May, Meta was reported to be training an agent called Hatch in isolated web environments built on simulations of real sites including DoorDash, Etsy and Reddit; Muse was probably built on it. Reports followed of a paid product costing up to $200 per month. The eventual plan is to link Muse to Meta's AI glasses.

Meta has built the trust infrastructure first and the intelligence second, which is the opposite order from every other lab shipping agents. If it works, the company owns the payment rail that OpenAI walked away from, and the model gap stops mattering. If an injection attack drains a real user's one-time card before Sentinel catches it, Meta will have spent its distribution advantage proving the scenario researchers have been demonstrating all year.