Meta tests Muse, a personal AI agent that can spend your money

The invite-only iPhone app connects to email, calendars, health and financial data, then asks for approval before acting.

By · Published

Primary source: TestingCatalog on X

Why it matters

Muse puts Meta's agent strategy inside a dedicated app with unusually broad access to personal data. Its approval system will determine whether users trust it to act.

A smartphone screen shows a chat with a digital assistant named Muse, which has filled out a field trip permission slip and is asking for approval to sign up for a chaperone role.

Meta is testing Muse, a standalone personal AI agent designed to manage schedules, make purchases, track spending and continue working after users close the app.

TestingCatalog reported in a September 7th post that Muse had moved into a limited test with invite codes. A Meta-authored App Store listing for Muse provides the clearest account of what Meta is building: an iPhone agent with access to email, calendars, health information, financial accounts and Meta's social apps.

Meta describes Muse as an agent that can handle an entire job rather than return an answer. Examples in the listing include negotiating a bill, selling a car, planning and booking a trip, auditing subscriptions and buying products after receiving approval. Muse can also run in the background, monitor unfinished work and notify the user when a decision is required.

The listing is public, although access appears restricted. TestingCatalog reported that Meta is using a waitlist and user-distributed invitation codes for the closed test. The App Store version history shows Meta released versions 4.0.0 through 4.3 over four consecutive days, evidence of an active test cycle rather than a static placeholder.

A separate app for the agent

Muse packages capabilities that Meta began adding to Meta AI this summer into a dedicated product built around persistent tasks.

On July 24th, Meta said Meta AI could connect to email and calendar services, prepare daily briefings and maintain recurring plans without receiving the same prompt again. Muse extends that approach into finance, health, shopping and transactions, while giving each assignment a continuing state after the user leaves the app.

The distinction matters because a chat assistant can fail and end a conversation. An agent connected to payment methods, health data and communications can fail while taking an external action. Meta's App Store description acknowledges that Muse may produce inaccurate results or take unexpected actions, and tells users to monitor its work and intervene when needed.

Meta's proposed control system centers on approvals. Muse asks before sending messages, spending money or canceling subscriptions, according to the listing. It also maintains an activity log and allows users to revoke individual connectors. TestingCatalog's screenshots show transaction approval screens, an embedded browser for completing bookings and a chat interface where Muse offers to sign a travel document and send it by email.

The available connectors shown in those screenshots include Gmail, Google Calendar, OpenTable, Peloton, Plaid, Function Health, Facebook and Instagram. Together, those services would give Muse a view across a user's communications, schedule, purchases, exercise and finances.

The permissions are the product

Apple's privacy section says Meta may link a wide range of information to a user's identity, including health and fitness records, payment and credit information, precise location, contacts, emails or text messages, browsing history and sensitive information. Apple notes that the disclosure comes from Meta and has not been independently verified by Apple.

That access explains how Muse could become more useful than a general chatbot. It also raises the cost of mistakes. Tasks such as disputing a charge, booking travel or changing a fitness plan require current personal information and the authority to act on it. Meta is betting that an approval screen and an audit trail will provide enough control for users to grant that access.

The timing follows Meta's September 2nd release of Muse Spark 1.3, a model update focused on coding and long-running agentic work. Meta AI chief Alexandr Wang told Axios that the update would support personal agents capable of working continuously toward users' goals. Meta has already positioned the Muse model family as the technical base for assistants that plan, use tools and coordinate multiple subagents.

Muse turns that model strategy into a consumer product with a narrower promise: hand over a task, connect the necessary accounts and approve the consequential steps. The closed test will measure whether that workflow is reliable enough for the inboxes, calendars and bank accounts on which the product depends.

Reader comments

Conversation for this story loads after sign-in.