Meta's Muse AI Can Read Emails and Make Payments: Here's How Much Access It Really Has
Muse AI manages tasks but permissions control its access to accounts

Meta has launched Muse, an artificial intelligence agent capable of reading emails, browsing websites, filling in forms and completing purchases on a user's behalf.
Unlike a conventional chatbot, Muse can continue working after its app is closed. However, it does not automatically gain access to a person's inbox, payment details or other accounts.
Users choose which services to connect and which permissions to grant. Meta says Muse must also request approval before sensitive actions, including sending an email or making a purchase.
What Can Muse Access?
Meta introduced Muse on 8 September 2026 as a personal agent designed to manage everyday tasks and longer-term goals.
Muse can connect to email and calendar services, operate a web browser, complete forms and make bookings. It can remember information from previous conversations and use those details to offer suggestions without being prompted.
For example, Muse could monitor emails for important dates, add events to a calendar or turn a recipe saved on Instagram into a shopping list. It can also perform scheduled tasks in the background.
The amount of access depends on the user's choices. Email access can be limited to reading messages, while sending emails requires additional permission.
Users can review Muse's audit trail, change access levels or disconnect services.
Can Muse Make Payments Without Permission?
Muse can complete online purchases, but Meta says it pauses before checkout and displays the transaction details for approval.
Payments are initially supported through Link by Stripe. The service generates a single-use card number linked to a particular merchant, amount and limited period instead of providing the website with the user's regular card details.
Shop Pay support is expected later, alongside a planned integration with 1Password for saved login credentials.
Meta says Muse itself does not see passwords, card numbers or authentication tokens. Credentials are stored separately and inserted only when required.
Where Does Muse Store Personal Information?
Each user receives a dedicated cloud-based virtual computer called a Muse Secure VM. Connected account data, files and credentials are stored within that environment.
A separate system called Sentinel assesses Muse's requests and controls its internet access. It can approve an action, reject it or ask the user for permission.
Meta says Muse filters one-time passcodes, password-reset links and login links from connected inboxes. This is intended to prevent email access from becoming a route into unrelated accounts.
However, Meta's security disclosure acknowledges that Muse can make mistakes and that prompt injection remains an unresolved industry problem.
Does Meta Use Muse Data?
Meta says conversations and data stored in a Muse VM are not shared with its advertising systems. However, websites may treat browsing performed by Muse as the user's activity, which could indirectly affect the advertisements they see.
Meta says sanitised records of conversations and tasks may be used to train its AI models. Users can opt out through Muse's settings.
Meta personnel may access data when necessary to operate, support or secure the service. A Confidential VM planned for later in 2026 is intended to prevent Meta from accessing the encrypted environment.
Muse is rolling out in the US on iOS, Android and muse.ai. Meta has not announced a UK release date.
© Copyright IBTimes 2026. All rights reserved.

























