Meta has spent years trying to convince the world that its next major platform will not necessarily be another social network.

Now the company has a much more ambitious candidate: an artificial-intelligence agent that can read emails, book travel, shop online, fill out forms, place calls and eventually handle increasingly large portions of a user's digital life.

That agent is Muse.

And the early numbers are impressive.

But popularity is only half the battle.

The harder challenge may be trust.

Muse overtook ChatGPT as the top free app on Apple's App Store and Google Play in the United States and Canada and recorded about 2.8 million downloads within its first two weeks, according to Sensor Tower data cited by Reuters.

For Meta CEO Mark Zuckerberg, that early adoption is important because Muse is central to his vision of "personal superintelligence" — an AI assistant that can do work on behalf of users rather than simply answer questions.

The commercial opportunity could be enormous.

The security and privacy challenge could be just as large.

Muse is not another chatbot

The key difference is what Muse is allowed to do.

Traditional chatbots mostly respond to prompts.

Muse is designed to act.

Meta says the agent can open a browser, fill out forms, send emails, book travel and work toward longer-term goals. It can continue working after a user closes the application and return when it needs approval for a sensitive action.

That creates a fundamentally different relationship between the user and the software.

A chatbot might tell you how to book a flight.

Muse can potentially book it.

A chatbot might explain how to sell a car.

Muse can potentially help carry out the transaction.

A chatbot can tell you how to negotiate a bill.

Muse can potentially make the call.

Those capabilities are exactly what make agentic AI so attractive.

They also create the trust problem.

The more powerful the agent becomes, the more information and access it needs.

Meta is asking users to hand over access

Meta has designed Muse around a system called Muse Secure VM — a dedicated virtual machine intended to isolate the agent and a user's data.

The company says users control which applications Muse can connect to, how much access it receives and whether interactions can be used to train Meta's AI models. Meta also says sensitive actions such as sending an email or making a purchase require user approval and that the system provides an audit trail showing what the agent has done and plans to do.

For payments, Meta says Muse can use Stripe's Link infrastructure, including one-time-use virtual card credentials designed to keep a user's actual card details hidden from the merchant or agent. The company also says a forthcoming Confidential VM will encrypt the entire environment with a key controlled by the user.

Those safeguards are important because the information an AI agent can access is dramatically more sensitive than the information typically provided to a search engine or chatbot.

Muse can potentially interact with email.

It can interact with calendars.

It can access shopping services.

It can make purchases.

And it can connect to other applications.

That makes security architecture a core product feature rather than something hidden behind the scenes.

The popularity is real

The early adoption figures give Meta a reason to be confident.

Reuters reported that Muse reached about 2.8 million downloads in its first two weeks and overtook ChatGPT in the U.S. and Canada app-store rankings.

The application has also become a major catalyst for Meta shares.

Reuters reported that Meta stock had risen more than 20% since Muse's September 8 launch, adding more than $200 billion in market value.

Investors have started considering Muse as a potential new revenue engine rather than merely another expensive AI project.

That expectation received additional fuel from Zuckerberg's announcement that Meta eventually plans to make money by taking a small fee from transactions Muse completes.

Meta has also been connecting the assistant to retailers, travel services and payments platforms. PayPal, Walmart, Best Buy, Gap, Sephora, Wayfair, American Eagle, Expedia and Instacart have all been cited as part of the growing ecosystem around Muse.

That means Meta's AI strategy is beginning to move beyond advertising.

The company generated almost all of its $60.8 billion in second-quarter 2026 revenue from advertising, with advertising contributing $59.36 billion, according to Yahoo Finance reporting.

Muse gives Meta a potential second economic model.

Instead of merely displaying advertisements around consumer activity, Meta wants its AI agent to participate directly in commerce.

That is a much bigger opportunity — but it requires enormous trust.

And trust is being tested

Meta's early success has coincided with several uncomfortable questions.

Amazon blocked Muse from making purchases on its site, arguing that the agent was operating without authorization and violating Amazon's conditions of use. Amazon said third-party applications making purchases on behalf of customers should operate openly and respect the decisions of service providers about whether to participate.

That dispute points to a much larger problem.

Who controls the internet when an AI agent becomes the customer?

For decades, websites have been designed for humans.

Users click buttons.

They enter passwords.

They compare products.

They accept terms.

They make purchases.

An AI agent changes that relationship.

The software becomes the intermediary.

The user may never even visit the website.

That threatens existing business models and raises difficult questions around authentication, advertising, data collection and platform control.

Amazon is not the only company thinking about these issues.

Retailers and platforms will have to decide whether they want AI agents interacting with their systems — and under what conditions.

Some may welcome the additional sales.

Others may fear losing control over customer relationships.

Meta has another privacy complication

Reuters recently reported that Meta has been testing a "human concierge" system for Muse's phone-calling feature.

Under the test, human contractors handled certain calls that Muse placed on behalf of users. The feature was tested internally as Meta worked to improve safety and privacy before broader deployment.

For an AI agent designed around personal information, that creates an obvious question.

If a user asks Muse to call a business, who is actually listening?

Meta says it has security and privacy measures in place, but the very existence of human involvement illustrates how difficult it can be to make AI agents fully autonomous.

Real-world tasks often contain edge cases that models do not handle perfectly.

A human may understand an unexpected situation immediately.

An AI system may not.

Companies therefore face a difficult choice.

Give the AI more autonomy and accept greater risk.

Or introduce human oversight and potentially undermine the privacy and scalability benefits of automation.

Muse sits directly in the middle of that tension.

Meta patched a security flaw too

Security concerns have also moved beyond theory.

The Verge reported that Meta patched a zero-day vulnerability in its macOS Muse application after researcher Patrick Wardle demonstrated that an attacker with local access could potentially redirect the application's transcription process and manipulate Muse into performing harmful actions. Meta said the exploit required malicious code already running on the user's machine, limiting its practical risk, but it nevertheless issued a hotfix.

The incident is important because AI agents introduce a new category of cybersecurity risk.

A traditional application being compromised is bad.

An AI agent being compromised can be much worse if it has permission to send emails, access accounts, make purchases or manipulate files.

The more autonomy an agent receives, the larger the potential consequences of a security failure become.

This is why trust may determine Muse's future

Meta's central challenge is no longer proving that Muse is interesting.

It clearly is.

Millions of people have downloaded it.

It has climbed the app charts.

It has performed tasks that traditional chatbots cannot easily perform.

Investors are increasingly looking at it as a potential source of revenue.

The question is whether users will continue using it once the novelty disappears.

And that depends on reliability and trust.

People may be willing to let an AI find a restaurant.

They may be considerably less comfortable allowing it to send sensitive emails, interact with financial accounts or make expensive purchases.

Every successful action builds confidence.

Every unexpected action can destroy it.

That makes the AI-agent market unusually sensitive to individual incidents.

A search engine can return a bad result.

An AI agent can make a bad decision.

That difference changes the stakes.

Meta is therefore trying to solve two problems simultaneously.

The first is technological: build an agent capable of completing increasingly complex tasks.

The second is social: persuade billions of people that they can safely delegate those tasks.

That second challenge may prove harder.

Meta wants Muse everywhere

The strategy becomes even more ambitious when Muse is combined with Meta's hardware.

The company says Muse is coming to its AI glasses, potentially allowing users to interact with an assistant without opening an app or touching a phone.

That could make the technology dramatically more convenient.

It could also make trust even more important.

An AI assistant operating from glasses is closer to the user's physical environment.

It may know where the user is going, what they are looking at, who they are communicating with and what they are trying to accomplish.

That is incredibly powerful.

It is also incredibly sensitive.

Meta's vision is therefore much bigger than another AI app.

It is building an ecosystem in which Muse becomes a persistent digital assistant across phones, messaging services, shopping platforms and wearable devices.

The company wants users to stop thinking about AI as something they open when they have a question.

Instead, Meta wants AI to become something that quietly works in the background.

That is the promise.

It is also the risk.

The AI race is entering its trust phase

The first generation of AI competition was about intelligence.

Which company had the strongest model?

The next phase is about agency.

Which AI can actually do the most?

The phase after that may be about trust.

Which AI will people allow to act on their behalf?

Meta appears to have made significant progress on the first two questions with Muse.

The third question remains open.

The early download numbers show that millions of users are curious.

The commercial integrations show that businesses are beginning to experiment.

But Amazon's resistance, privacy concerns, security incidents and Meta's own human-concierge testing demonstrate how unsettled the ecosystem remains.

That is why Muse could become one of the most consequential products Meta has ever released.

Not because it is another chatbot.

Not because it is another social-media feature.

But because it is an attempt to put an AI between people and the digital world.

Meta has already shown that people will download Muse.

Now it has to convince them that they can trust Muse.

And in the agentic-AI era, that may be the most valuable currency of all.

Keep Reading