AI Tools

Meta Muse Tested: What Its Free AI Agent Can Actually Do

Direct Answer

Muse is most interesting when the work already lives inside Meta's ecosystem. In Andrew Warner's hands-on conversation with Michael Galpert, it reads Instagram data, prepares a portable follower export, drafts Marketplace messages, uses a cloud browser, and suggests recurring work based on a user's interests. It is not a general promise that every website or integration will work: the export stopped at 749 accounts in Michael's test, and a Costco shopping task failed.

The advantage is a combination of first-party connections, a persistent agent, and a dedicated cloud computer. The trade-off is that one personal agent needs extensive context and permissions to be useful, while actions such as sending messages still require approval. Meta says the product is free for most everyday use and is rolling out in the United States; this is not a guarantee of unlimited usage or availability elsewhere.

Use the right starting point: begin with a read-only Instagram or Marketplace research task. Check the result and audit trail before granting messaging, purchasing, or access to additional accounts.

Watch Andrew and Michael Test Muse

Credit and evidence: the demonstrations and Michael's opinions come from Andrew Warner's interview with Michael Galpert, published on 15 September 2026. Product availability and security details are from Meta's launch post and technical security explanation, checked on 16 September 2026. The video is presented by Zapier.

What Muse Actually Adds to an AI Chat

Meta positions Muse as an agent that can act across connected services rather than simply answer questions. Each user gets a dedicated virtual computer with a browser. Muse can continue a multi-step task after the app closes, return for approval when needed, and use connected Meta services alongside third-party tools.

Michael shows one main persistent agent with memory, identity and personality settings, plus side chats for narrower work. That design keeps context in one place, but it differs from running separate agents with isolated roles and accounts for business, personal, or family tasks.

LayerWhat was shown or documentedPractical question
Meta connectionsInstagram and Facebook data and messagingWhich account and data scope are you granting?
Cloud computerDedicated virtual machine and browserWhat can the browser access or submit?
Persistent contextMemory, profile, main chat, and side chatsWhich details should be retained or forgotten?
ApprovalsHuman review for sensitive actionsWhat must wait for you?
ConnectorsBuilt-in services and potential custom API/CLI integrationsHas the connection actually been completed and tested?

The Instagram Export Was Real, but Limited

Michael asked Muse to export his Instagram followers, examine followers of those accounts, and visualize relationships. It produced a spreadsheet-format file and a network view. The export itself impressed both speakers because portable data is more useful than a pretty dashboard trapped inside an app.

The test did not complete an unlimited graph of followers. It stopped at 749 accounts; Michael could not tell whether the cause was an API limit or another cutoff. He also judged the visualization attractive but not very functional. The demonstrated value is a first-party data handoff, not a proven full social-graph analytics product.

For a business test, ask for a small, clearly permitted export; inspect row counts and fields; then compare sample records against the source account. Do not assume an agent's visualization has preserved every relationship correctly.

Messages Need a Human Approval Gate

Michael shows Muse drafting Facebook Marketplace messages and asking for approval before each send. That is slower than an agent that fires off a batch, and Andrew points out the friction. The friction is also the control: a wrong or spammy message cannot be quietly sent on the user's behalf in this demonstrated flow.

For Marketplace negotiation or customer replies, review the recipient, item, price, promises, and tone before approving. If an agent is responding to several people, make sure it does not mix private details or commit to conflicting terms. Meta's launch materials describe approvals for sensitive actions such as sending email and making purchases; the exact rule for every channel should be checked inside the current product.

A Cloud Computer, Browser, and WhatsApp Interface

Muse's computer is not merely a browser tab on the user's laptop. Meta says it gives each user a dedicated VM with an isolated workspace. Michael shows the agent operating a web browser, researching products, and letting the user take control. He also demonstrates communicating with Muse through WhatsApp, which makes an agent feel closer to an everyday message thread than a developer tool.

Meta says the browser can read pages and fill forms, while user takeover pauses the agent. This is useful for sites without APIs, but it is not universal computer control. Authentication flows, anti-bot defenses, site rules, and browser limitations still matter. Michael's failed Costco attempt is a concrete reminder.

Built-In Integrations and Connectors on the Fly

Michael moves between Muse's connector list and a request to connect another service. A Todoist integration already exists in the flow he opens. When asked about Basecamp, Muse proposes an API-based connection and setup steps. That is an interesting ability, but the video does not show a completed Basecamp authorization or a verified task executed through it.

Meta says Muse can create custom connectors when a service offers a suitable API or CLI. Treat that as a capability to test, not permission to paste an API token into an unreviewed prompt. Check what the connector can read and write, where credentials are stored, whether it needs a paid API plan, and how to revoke it. Tailscale is also discussed as a route to other computers, but network reach should be granted narrowly and only for a concrete workflow.

What Meta's Security Design Does and Does Not Promise

Meta's technical description is unusually specific. The agent runs inside an isolated runtime cell in the user's VM, while credential storage and connector code sit behind separate boundaries. A Sentinel component decides whether connector actions and network requests are allowed, denied, or sent to the user for approval. Meta says the model does not see real credentials and that users can inspect an audit trail.

Those controls reduce risk; they do not make prompt injection or mistakes disappear. Meta explicitly says Muse can still make mistakes. Its launch architecture also does not guarantee that Meta itself can never access user data: Meta says operational access may be necessary to support or secure the service, with a stronger Confidential VM design planned for later. Conversations and VM data are not shared with Meta's ad systems, according to its launch post, but that is different from saying the service is completely private from its operator.

Permission ladder: read-only account access first; limited drafts and summaries second; actions with per-item approval third. Purchases, bulk outreach, network access to other computers, and sensitive records deserve a separate review.

Where the Demo Hits Its Limits

  • Follower export: stopped at 749 accounts in Michael's test.
  • Visualization: interesting to look at, but not yet a useful analysis interface for him.
  • Web shopping: Muse could not complete his Costco task even with his assistance.
  • Approval workload: each outbound Marketplace message needed review.
  • Role separation: Michael prefers separate agent personalities for distinct personal and professional contexts.
  • Custom integration proof: the Basecamp connector was proposed, not shown completing a real action.

These are observations from one early user's short test period, not a benchmark of every Muse account or future release. The most defensible claim is that Muse looks especially strong where Meta already controls the account surface.

Personalized Feeds and an Ideas Tab

Michael shows a feed shaped around his interests, calendar, and Marketplace searches. He also points to an Ideas tab that suggested recurring desk searches after it learned he was looking for office furniture. This is the shift from a reactive assistant to a proactive one: the agent notices context and proposes work before the user writes the next prompt.

The right test is whether those suggestions save real time without becoming another feed to manage. Choose a narrow recurring task, such as monitoring a specific Marketplace item, and set clear frequency, price, location, and notification rules. Keep the approval gate before any message or purchase.

A Low-Risk Muse Test You Can Run

  1. Check whether Muse is available in your region and which free limits apply to your account.
  2. Connect only the account needed for one task, ideally with read access first.
  3. Ask for a bounded result: for example, summarize your last ten Instagram posts and export a small table of dates, formats, and engagement.
  4. Compare several rows with the source account and inspect Muse's activity trail.
  5. Give one correction and see whether it improves the next result.
  6. Only then try a draft message, with approval required before sending.

This test is intentionally smaller than the video demo. It establishes data quality, access scope, and review effort before the agent becomes a persistent part of your workflow.

Video Chapters

TimeTopicTimeTopic
00:00Introducing Muse07:34A Free Computer in the Cloud
00:19Exporting Instagram Followers07:53Using Muse Through WhatsApp
01:38What Makes Muse Different08:57Muse Controls a Web Browser
02:00Messaging on Facebook and Instagram10:29Connecting Tools Without Built-In Integrations
02:46Inbox, Memory, and Agent Identity11:20Creating Connectors on the Fly
03:25Human Approval for Messages12:51How Fast Is Muse?
04:05Bulk Messaging13:18What Muse Is Good For
04:29Muse's Personality and Memory13:33Muse for Facebook and Instagram
05:11One Persistent Agent and Side Chats14:27Security and Privacy
06:12Muse's Connectors15:10Where Muse Still Falls Short
15:47One Agent vs. Multiple Personalities16:17Trying Agents for Free
16:42Muse's Personalized Feeds18:02Muse's Ideas Tab
18:47Michael's Muse Hot Take

Verdict

Muse is a credible everyday agent for people whose work already runs through Instagram, Facebook, Messenger, and WhatsApp. Michael's strongest evidence is the first-party data and messaging workflow, not the 3D visualization. Meta's cloud computer, persistent memory, and approval system make it approachable without requiring a spare machine or a self-hosted agent stack.

The product still needs judgment. It failed a real shopping task, a follower export stopped early, and the single-agent design is less clean for people who want strict role separation. Try it with bounded, reversible work and measure the quality of the output before giving it more of your digital life.

Sources and Links

Common questions

Is Meta Muse free?
Meta says Muse is free for most everyday needs, with subscription plans for heavier use. Availability and limits may change. At launch, Meta said the rollout was in the United States on iOS, Android, and muse.ai.
Can Muse send Instagram or Facebook messages by itself?
In the demonstrated workflow, Muse drafts messages and asks for human approval before sending them. That makes bulk outreach slower by design and reduces the risk of unwanted messages.
Does Muse have its own computer?
Yes. Meta describes a dedicated virtual machine for each user with a browser and isolated storage. The agent can use it for web tasks while the user can observe or take over the browser.
Can Muse connect to apps without an existing integration?
Meta says Muse can create custom connectors for services with suitable APIs or CLIs. In the video, a Basecamp setup is proposed on the fly, but the connection is not completed or proven in that segment.
Is Muse private from Meta?
Meta says Muse conversations and VM data are not shared with its ad systems and that credentials are kept outside the agent runtime. Its launch architecture does not prevent Meta personnel from accessing data when needed to operate or secure the service; a stronger Confidential VM mode was described as forthcoming.
Share
X LinkedIn Reddit
Build Yours

Want a system
like this one?

Book a free 30-minute call. We map your situation, identify the highest-impact automation, and figure out if we are a fit.

Book Free 30-min Call