ChatGPT Dots Explained: How OpenAI's Always-On Agents Work
ChatGPT Dots are always-on agents with their own cloud computers. Learn how they work across apps, approvals, availability, and what is still unproven.
Meta Muse is a personal AI agent for everyday tasks in WhatsApp and its own app. Learn what it does, how the Secure VM works, pricing, and limits.
Meta launched its own personal AI agent on September 8, 2026 in the US, calling it the first personal AI agent built for everyone. Named Muse, it lives in a dedicated app, on the web, and inside WhatsApp, and it is designed to do things for you rather than just answer questions: send emails, shop, book travel, fill out forms, and negotiate on your behalf.
This guide explains what Muse is, how it works, what it connects to, what it costs, where the honest concerns sit, and who should or should not rely on it. If you are comparing it against work-focused agents, read our Dots versus Muse comparison alongside this piece.
Muse is a personal agent, not a business platform. The distinction matters because the marketing for every agent product sounds similar. A personal agent acts on your behalf in your own accounts: your inbox, your calendar, your shopping carts, your travel bookings. It remembers your preferences, works while you do something else, and checks back when a decision involves money or a message sent in your name.
Meta's framing is that this is for everyone, not just technical users. Meeting people inside WhatsApp is part of that strategy. Instead of asking you to learn a new work tool, Muse shows up in a chat app hundreds of millions of people already open every day. The dedicated app and the web at muse.ai cover longer tasks, while a Mac app added on September 17 extends it to desktop. Support for AI glasses is described as coming soon.
The person who benefits most is someone with a busy personal admin load: travel to book, purchases to compare, emails to send, forms to fill, appointments to schedule. The person who benefits least is an owner looking for customer-facing automation, because Muse has no answer for calls, quotes, dispatch, or pipeline.
Two technical pieces are worth understanding, even if you never touch a setting.
First, the underlying model is called Muse Spark, Meta's in-house model built for this agent. What matters is the behavior it enables: carrying a task across steps, using a browser, filling forms, and pausing for approval at the right moments.
Second, the agent runs on what Meta calls a Muse Secure VM. A virtual machine is simply a separate computer running in the cloud, dedicated to your agent and your data, rather than software installed on your phone. Meta's argument is that this separation is safer than giving an agent full access to your device. Meta also says a more secure confidential encrypted version is planned later in 2026, which would add stronger protection around the data inside that workspace.
For a non-technical reader, the takeaway is straightforward: your agent works in its own locked room, not at your desk. That is better than the alternative, and it is not a reason to hand over accounts or permissions the task does not require.
Meta lists a practical set of capabilities. Muse can autonomously send emails, sell a car, book travel, shop, open browsers, fill out forms, and negotiate on your behalf. It keeps working in the background after the app is closed and returns when approval is needed, for example before completing a purchase.
The connections define the ceiling. Email and calendar cover scheduling and correspondence. Payments through Stripe Link cover checkout. Health and smart home connections cover personal routines. Support for 1Password and Shop Pay is described as coming, which would widen the range of logins and checkouts the agent can handle.
A reasonable way to think about it: if the task starts and ends in your personal accounts and a browser, Muse can probably attempt it. If the task needs your business systems, your staff, or your customer records, it is outside what this product was built to do.
Muse launched in the US on September 8, 2026. Access runs through the dedicated Muse app on iOS and Android, muse.ai on the web, and inside WhatsApp. The Mac app followed on September 17.
On price, Meta says Muse is free for most of what people need, with paid subscription plans for heavier use. Details of those plans were not fully specified at launch. That is a common launch pattern: a broad free tier to build habit, with paid tiers for people who run far more tasks. Until the paid details are published, treat any heavy-use planning as provisional and watch what counts toward the paid tier.
A balanced review has to include the critical reporting. Reuters reported that Meta launched Muse even after internal tests showed the product stalling and exposing sensitive data without authorization. Meta proceeded with the launch.
Three points keep this in perspective. First, this is reported test behavior before launch, not a published incident log of the shipping product, and products change between testing and release. Second, stalling and over-sharing are known failure patterns for new agents across the industry, which is why approval gates and narrow permissions exist. Third, the concern is still relevant to your setup decisions today, because an agent with broad account access can do more damage from a single mistake than a chatbot that only writes text.
Practical rules follow from that. Connect only the accounts a task needs. Require approval before purchases, payments, and anything sent in your name. Do not connect business systems or client data to a consumer agent. Review what the agent did each week, at least for the first month. Our AI agent security guide turns those rules into a setup checklist, and our internal assistant service shows how business tasks get the logging and access controls a consumer app does not provide.
Muse is a reasonable fit if you want help with personal admin and you are comfortable supervising an agent. Try it on low-risk tasks first: comparing options, drafting emails you review before sending, researching travel, or organizing personal scheduling. Keep approvals on for anything involving money or outbound messages.
It is a poor fit as business infrastructure. There is no shared inbox, no call answering, no lead qualification, no booking flow tied to your capacity, and no reporting an owner can audit. Customer-facing work needs tooling built for that job, such as an AI receptionist for calls or a lead follow-up workflow for new inquiries.
It is also a poor fit for anyone handling sensitive client, patient, or legal data inside the same accounts the agent can see. Regulated work needs access controls, audit trails, and data boundaries that a consumer personal agent does not promise.
If you decide to try Muse, keep the first week narrow.
| Step | What to do |
|---|---|
| Day 1 to 2 | Connect one low-risk account, such as a personal email or calendar, and leave payments disconnected |
| Day 3 to 4 | Assign two or three contained tasks, such as researching options or drafting messages you approve |
| Day 5 | Review the history: what it touched, what it asked about, what it did without asking |
| Week 2 | Add one more connection only if week one behaved, and turn on approvals for purchases and outbound messages |
If anything surprises you in the review, shrink the permissions before expanding the tasks. An agent earns broader access by behaving well on narrow jobs, not by starting with the keys to everything.
What is Meta Muse?
Muse is Meta's personal AI agent, launched September 8, 2026 in the US and described as the first personal AI agent built for everyone. It handles everyday tasks such as sending emails, shopping, booking travel, selling a car, opening browsers, and filling out forms. You reach it through a dedicated app, the web, WhatsApp, and since September 17, a Mac app.
How does the Muse Secure VM work?
Muse runs on what Meta calls a Muse Secure VM, a dedicated virtual machine that houses both the agent and your personal data. Meta says a more secure confidential encrypted version is planned later in 2026. In plain terms, the agent works in its own locked workspace rather than directly on your phone or laptop.
What did Reuters report about Muse before launch?
Reuters reported that Meta launched Muse even though internal tests showed the product stalling and exposing sensitive data without authorization. Meta proceeded with the September 8 launch. That history does not settle how the product behaves today, but it is a reason to limit permissions and require approvals.
Is Meta Muse free?
Meta says Muse is free for most of what people need, with paid subscription plans for heavier use. Full details of those plans were not specified at launch. Expect the free tier to cover normal personal errands, with power users paying once pricing is published.
Should a business run on Meta Muse?
No, not as its operating system. Muse is a consumer agent with no CRM, pipeline, dispatch, or reporting features. It can help an owner with personal admin, but customer-facing work such as answering calls and booking jobs belongs on business tooling with logging and approvals.
Personal agents will keep showing up in your customers' and employees' lives, so Muse is worth understanding. Try it personally with narrow permissions, but keep business workflows on systems built for supervision. To map which tasks are ready for an agent, start with our free six-step plan: start your AI automation plan. For a second pair of eyes, book a call.
ChatGPT Dots are always-on agents with their own cloud computers. Learn how they work across apps, approvals, availability, and what is still unproven.
Can Meta Muse help your company? See which owner tasks fit, where the consumer agent stops, and what business-grade setup to pair it with instead.
Personal agents like Meta Muse and work agents like ChatGPT Dots handle your data very differently. Learn the boundary, the risks, and a simple SMB policy.
More articles: browse the full Praktivo blog.