Meta's free personal AI agent is live on WhatsApp. The data it asks for is the real story.
Meta shipped a free personal AI agent called Muse last week, and it is already in roughly 900,000 pockets. WIRED reports the app was downloaded more than 900,000 times in its first seven days, according to Sensor Tower estimates. It is not a beta tucked behind a waitlist. It is a Meta product, cross-promoted on Instagram and reachable through WhatsApp, the chat app that carries the daily traffic of much of the world.
The product works. That is the part worth examining.
Muse asks for access to a user's email and bank account at install. The hands-on review describes a personal agent that runs in the background, clicks through the web on a virtual machine, and completes concrete tasks. In one test, the reviewer asked Muse to order breakfast from Kahnfections, a San Francisco bakery, and Muse added a biscuit sandwich to the cart and pushed payment through Stripe. Compared with the now-defunct ChatGPT Agent, the reviewer wrote, the web-browsing ability is genuinely impressive.
What changes at the install screen is the resolution of the data. A chatbot answers questions and forgets. A personal agent with inbox and bank access sees the receipts, the transaction merchants, the recurring senders, and the calendar context that pass through a normal day. For a company that already sells targeted advertising against inferred intent, the data flow is the underlying asset, even if the consumer-facing pitch is convenience. The trade is documented at the install screen, not in the ad copy.
Meta has answered the framing directly. Spokesperson Emil Vazquez, on the record in the same WIRED piece, said: "Muse is the first personal AI agent built for everyone, with built-in protections and user controls that put people absolutely in charge of how they use it—any suggestion we didn't build with that in mind from the beginning is ludicrous." Meta's research division also published a dedicated post on its safety approach for Muse, walking through how the agent is constrained, monitored, and limited to authorized actions. The defense is real; it is also the response of a company whose installed-base business model depends on the install being worth granting.
The independent academic context for the human-oversight question is now published too. A recent arXiv preprint, "AI Agents Push Humans Out of the Loop," surveys the structural problem that personal-agent products create: the more capable the agent, the less the human is in the decision path for any given action, and the harder it is to audit what the agent saw or decided. The paper is not a verdict on Muse specifically. It is the field's current description of the design tension every personal-agent product ships into.
Meta has not said what it will or will not do with inbox and bank-transaction data once Muse has access. The next milestone worth watching is the first time that question is answered in detail, in a privacy policy or a security disclosure, rather than in a product launch.