Meta introduced Muse, a personal AI agent that books travel, answers email, and handles routine admin work on a person's behalf, with an approval gate built into every sensitive action.

An operations lead who needs a flight rebooked, an inbox triaged, or a customer service call handled usually routes that work to an assistant, a travel desk, or a support line. Meta wants to put an AI agent in that seat instead. On September 8, the company introduced Muse, a personal AI agent it describes as doing the work itself rather than just answering questions, sending emails, booking travel, filling out forms, and negotiating on a person's behalf, reachable through a dedicated app or directly inside WhatsApp.

Muse runs on what Meta calls Muse Secure VM, a dedicated virtual machine that pairs the agent with its own browser and holds a person's connected data and credentials. According to Meta, a separate "Sentinel" agent sits on the same machine and has to approve anything Muse sends to the internet, and Muse itself is never shown the passwords or payment details it uses. The agent is powered by Muse Spark, which Meta describes as its most capable model built specifically for this kind of multi-step, real-world task work, according to Meta's product page.

The task list Meta names is deliberately mundane: sending an email, booking an appointment, adjusting a training plan, lowering a bill, selling a car for a better price. For anything that takes longer than one sitting, Muse keeps working after the app is closed and comes back when it needs a decision or when something changes. Purchases route through a one-time-use card built with Stripe's Link, with purchase protections Meta says are a first for an AI agent, including coverage for damaged or lost items and no-fee returns. The rollout starts in the US on iOS, Android, and muse.ai, with AI glasses support coming later. It is free up to a usage limit, with paid tiers for people who want more.

For a business reader, the interesting part is not that an agent can book a flight. It is the mechanism Meta built around letting it act. Every sensitive step, an email going out, a purchase clearing, requires the person's approval, and Meta says people can see a full audit trail of what the agent has done and what it plans to do next. People also choose which apps Muse can reach and how much access each one gets, down to whether it can read a mailbox versus send from it. That is close to the shape a lot of teams already ask for when they evaluate AI tools for real operational work: scoped access, visible logs, and a checkpoint before anything consequential happens. Whether or not a given team ever uses Muse itself, it is a preview of what the market may start expecting from any agent asked to touch a calendar, an inbox, or a company card.

The honest limitation is that everything above comes from Meta's own account. Independent coverage of the launch exists, but it was not reachable for this article, and no outside labor-cost figure could be verified to size what a personal or executive assistant's equivalent work actually costs. So there is no dollar comparison here, only the workflow Meta says the agent replaces. It is also a consumer product, not a business tool, launching in one country on a handful of platforms, and Meta's safety and privacy claims have not yet been tested by outside researchers or a security incident. The approval gate is a design choice, not a guarantee.

Meta is betting people want an agent with a leash, not one without. That is a reasonable starting position for booking a flight. Whether the same amount of leash is enough once an agent like this is handling a recurring business process instead of a dinner reservation is the question worth sitting with.