Meta Muse’s 2-Agent System: AI Can Spend Your Money

Meta’s Muse can email people, book travel and make purchases for you. For founders and operators, its 2-agent system is a warning: AI now needs rules, not applause.

Meta Muse’s 2-Agent System: AI Can Spend Your Money

Meta’s Muse can make purchases under your name. That is not a chatbot upgrade — it is a delegation risk most people are not ready to manage.

On September 8, Meta launched Muse in the United States: a personal AI agent that can work across email, calendars, shopping, payments, health apps, smart-home services and more. It can send emails, book travel, help sell a car and work through longer-term tasks on your behalf. That sounds useful because it is useful. It is also the point where AI stops being a novelty and starts becoming a delegation problem.

Most people will focus on whether Muse writes decent emails. Wrong question.

The question is whether you are prepared to let software act under your name when the downside is not an embarrassing typo but a missed payment, a bad purchase, leaked information or a relationship damaged by a message you never actually wrote.

Meta has moved from answers to action

For the last few years, most consumer AI has been a very capable intern trapped behind a text box. You ask a question. It gives you an answer. You still do the work.

Muse is designed to cross that line. Meta says the agent can operate through a dedicated app, via WhatsApp and eventually through AI glasses. It runs in what Meta calls a Muse Secure VM: effectively a separate cloud computer where the agent can keep working even when you are not staring at the screen.

That distinction matters more than the branding.

A chatbot is a search-and-draft tool. An agent is an operator. It needs access, context, memory and authority. Without those things, it cannot do much beyond produce polished waffle at impressive speed. With them, it can move money-adjacent tasks, speak to customers, arrange travel, manage a calendar and make decisions that used to sit with a human assistant.

Meta says users decide which apps Muse connects to and how much authority it receives. For email, for example, a user can decide whether it may only read messages or also send them. Meta also says Muse must seek approval before sensitive actions such as sending an email or making a purchase, and that users receive an audit trail of what it has done and intends to do.

Good. That is the bare minimum, not a medal-worthy achievement.

If you hired a real assistant and they sent money, emailed clients or booked travel without a review process, you would not call that innovation. You would call it an expensive mistake.

The 2-agent architecture is Meta’s real product

The clever bit is not that Muse can book a flight. Plenty of AI products can fumble their way through a browser.

The interesting part is Meta’s attempt to put a second agent between Muse and the internet.

Meta says Muse runs inside its own virtual machine, where connected-service credentials are held in secure storage. It says Muse cannot see users’ passwords or payment methods directly. A separate Sentinel agent is isolated at the system level and must approve actions before Muse reaches the internet.

That is a serious acknowledgement of the actual problem.

The risk with AI agents is not merely that they make mistakes. Humans make plenty of those. The risk is that a system which reads untrusted material — emails, websites, product listings, messages and documents — can be manipulated by what it reads. In plain English: if an agent sees instructions hidden inside a webpage or email, can it tell the difference between your instruction and somebody else trying to hijack it?

This is why “just give it access” is not a product strategy. It is a liability strategy with better graphics.

Meta’s design is trying to separate the worker from the gatekeeper. Muse proposes an action; Sentinel polices the route out; the user approves sensitive moves. That is directionally right. But it is also proof that mainstream AI has entered a far tougher phase. The hard part is no longer generating a passable answer. The hard part is building trust boundaries around a machine that is meant to act.

Every business owner understands this instinctively. You do not give a new hire unlimited bank access on day one because they gave a good interview. You start them with narrow permissions, clear spending limits and oversight. AI agents deserve exactly the same treatment.

Meta’s advantage is not the model. It is the distribution.

Plenty of founders will see Muse and conclude they need to build another personal-agent app. I reckon that is mostly a waste of time.

Meta’s advantage is not that it is first to the concept. It is that it already owns the front door to a huge chunk of people’s digital lives: WhatsApp, Facebook, Instagram and now a dedicated agent experience. It can put an assistant into a messaging habit people already understand, instead of begging them to learn a new workflow.

That is how platform businesses win. Not necessarily by inventing the best technology, but by making adoption feel like the path of least resistance.

An agent sitting in WhatsApp is more dangerous to incumbents than an agent sitting in a niche productivity app. People already coordinate family plans, suppliers, customers, social events and side hustles through messaging. Turn that inbox into a place where software can take actions, and Meta is not trying to own another app category. It is trying to become the operating layer between a person and the internet.

That should put pressure on anyone whose business relies on being the place where users initiate a transaction: travel sites, marketplaces, customer-service platforms, scheduling tools, comparison sites and basic software dashboards.

If an agent chooses the hotel, fills in the forms, negotiates the bill, finds the product and sends the enquiry, the consumer may not care which interface used to get the credit.

The overlooked angle: this could make lazy operators worse

Here is the part the AI evangelists will not put on the slide deck.

AI agents do not automatically make you more effective. They magnify the quality of the instructions, systems and judgement you already have.

A sharp operator with clear priorities can hand an agent a defined job: source three suppliers within a budget, draft a comparison, flag contract differences, prepare the emails and wait for approval. That person gets leverage.

A disorganised operator will say, “Sort this out,” grant broad access and then blame the software when it makes a perfectly predictable mess.

The same goes for businesses. If your customer records are rubbish, your product catalogue is inaccurate, your approval rules are buried in somebody’s head and your team cannot agree on what “good” looks like, an agent will not fix the business. It will simply automate confusion faster.

That is the contrarian truth: the winners from agents will not be the companies with the most AI subscriptions. They will be the companies with the cleanest processes and the discipline to constrain software before it touches customers or cash.

Meta’s Muse is a consumer product, but the lesson is commercial. The next competitive advantage is not prompting. It is permission design.

Who can the agent talk to? What can it read? What can it change? What dollar amount can it spend? What requires approval? What gets logged? Who reviews exceptions?

Boring questions. Very profitable questions.

Privacy is not a feature list. It is a bill coming due.

Meta says Muse does not share a person’s conversations or virtual-machine data with its advertising systems. It says users can opt out of having interactions used to train Meta’s AI models. Later this year, Meta says it plans to introduce a Confidential VM encrypted with a key held only by the user.

Those are important commitments. They are also necessary because Meta has an obvious trust problem: its business has been built on knowing a great deal about its users.

For an agent, privacy is not a nice-to-have setting at the bottom of a menu. The agent needs access to the stuff that reveals who you are: your inbox, diary, purchases, health information, household routines and relationships. The more useful it becomes, the more consequential that access becomes.

So do not judge Muse — or any agent — by the demo. Judge it by the failure mode.

What happens when it sees a dodgy instruction embedded in an email? What happens when it confuses two contacts? What happens when a merchant dispute arises after it made the purchase? What happens when an employee leaves and their agent still has access to company systems? What happens when the audit log says the machine acted correctly but the commercial outcome is a disaster?

The business model of the next decade will increasingly be built around these questions.

What this means for you

Do not hand an AI agent the keys to the kingdom because the demo looked slick. Use it like you would use a bright junior employee in their first week.

1. Start with reversible tasks. Let an agent research options, prepare a draft, compile a comparison, chase publicly available information or create a proposed itinerary. Do not begin with payments, contract commitments or customer-facing messages.

2. Use permission tiers. Separate read access, draft access and action access. Reading a calendar is not the same as rescheduling it. Preparing an email is not the same as sending it.

3. Set dollar and reputation limits. Any agent doing transactions should have a hard spending ceiling. Any agent communicating externally should need human approval until it has earned trust through repeated, logged performance.

4. Demand an audit trail. If you cannot see what the agent saw, what it did and why it did it, do not let it operate in a meaningful workflow. Convenience without accountability is how small mistakes become expensive ones.

5. Fix your process before automating it. Write down the outcome, inputs, rules, exceptions and approval point. If you cannot explain the workflow to a competent new hire, you are nowhere near ready to give it to an AI.

Muse matters because Meta has made the agent race tangible for ordinary people. The game is no longer about who has the friendliest chatbot. It is about who can safely turn software into a trusted operator.

That will create enormous value. It will also punish anyone who confuses automation with judgement.

Software can now do more of the work. Brilliant. Just make sure it is doing your work — not quietly creating more of it.

Sources