Meta launched Muse: a personal AI agent that browses, fills forms, books travel, pays with a one-time Stripe card, and keeps working after you close the app. Five days later it had roughly 600,000 downloads and the No. 1 spot in the US App Store. Thirteen days after launch, Amazon cut it off.
Meta calls Muse "the world's first personal AI agent built for everyone." The 100 reactions below - developers, Meta staff, reporters, security researchers, executives and ordinary users - are grouped by what they're actually arguing about, not by where they posted.
Every linked name goes to the underlying source where available. A few secondhand or login-gated items are flagged in the text.
Does Meta have a strategy - and is Muse finally it?
1. KaiserPro, who opens by identifying himself as a "Former meta prick, sorry employee," is blunt: "Meta has no strategy." The people who made Llama work left two years ago, he says, and Meta Superintelligence Labs is trying to change the company's culture and tooling from outside it. In a later comment he makes the thread's most specific insider claim — that pre-2025 Meta had hard blocks stopping Oculus browsing data and Ray-Ban camera data from being processed offsite, and those blocks have since eroded.
2. aj0strow: "The strategy was unclear until now." The acquisitions, the targeted hires, the open-sourcing of weak models, the AI girlfriends — he reads Muse as the moment it resolves into personal AGI, priced for intelligence per dollar because most users will never pay.
3. Alexandr Wang, Meta's chief AI officer, on containment: Muse runs inside "its own isolated environment" and "never sees your actual passwords or payment details."
4. Alex Volkov (@altryne) published the most thorough public review anyone has done — setup, Stripe Link payments, iPhone connectors, a live demo buying a Mac Mini under $500, and a section titled "Should you trust Meta?" His chapter headings carry the verdict: "The most polished AI employee yet?" at the top, "genuinely impressed" at the end. His day-one advice: turn off training.
5. weitendorf makes the sharpest commercial case anywhere in the thread: "Meta's strategy seems to be 'personal agents' quite consistently." The ecommerce focus, he argues, is an assault on the intent-driven purchasing flow Google owns through search — the most lucrative advertising market in history — and an agent-proxied checkout has attribution and funnel measurement built in. That matters because Apple's 2022 tracking changes cost Meta $10B in conversion signal.
6. Ethan Mollick gave the assessment that mattered most to developers, on the model underneath: a solid set of stats still trailing the current frontier, but "The most important thing to note is that it is not open weights." Openness was the entire reason Meta's previous models mattered, he argues, and without it the value of Spark is much harder to predict.
7. alfiedotwtf thinks they're playing the wrong game: "What's Meta's moat? Content and doom scrolling…" His alternative is real-time personalized entertainment, with Meta as the next generation's Disney.
8. Mark Zuckerberg, in the personal superintelligence manifesto critics called fantastical, made the promise Muse is meant to deliver: "Your agent will work 24/7 on your behalf" — relationships, health, career, finances, home, hobbies.
9. dktp is more measured, same destination: "I don't think Meta has a clear vision." A new Meta AI announcement lands every month pulling in different directions — ad targeting, frontier coding, personal agents, renting compute. He adds that Google and OpenAI are no better.
10. Carles Reina of ElevenLabs, summarizing Zuckerberg on personal agents, flags the strategic claim he agrees with most: "To build the best personal agent, you cannot take something off the shelf." He also notes Zuckerberg's pitch that Muse will make people money, with 100M free tokens a week.
11. panarky on why you'd never hear that from Meta: "It's Matryoshka nested parallel construction for corporate strategy." Ring zero knows the real plan; each ring outward gets a version sufficient to execute against.
12. The Motley Fool reads the numbers as a genuine inflection — Muse "could be a major disruptor" and may be the killer app Meta has been chasing for years.
13. alt227 on the outside view: Meta gives the impression of "burning through ridiculous amounts of cash with not much to show for it."
14. Mark Zuckerberg, announcing the model underneath on X: "Muse Spark 1.3 is rolling out today with frontier performance almost too cheap to meter. This is the biggest jump we've made so far on coding and agentic work."
The trust problem is bigger than the product
15. smrtinsert states the objection that dominated everything: "even non techies know not to trust Meta."
16. TechCrunch framed the whole product as a single transaction: to use Muse, consumers will have to trust Meta with more of their personal information than ever before.
17. Cayce Savage, a former Meta user experience researcher testifying before the Senate subcommittee on privacy and technology, said the sentence that hangs over this entire launch: "Meta cannot be trusted to tell the truth about the safety or use of its products." Her testimony concerned VR and child safety, not Muse — but it is the trust argument in its strongest form.
18. Reece Rogers at WIRED delivered the most damaging line written about Muse, after several days of use: it "prioritizes data collection about me over actually accomplishing tasks." Quoted via TechBriefly rather than read directly in WIRED — worth confirming. He reports the agent repeatedly pushing him to connect more sources, including email inboxes and banking information.
19. Joe Sullivan, former chief security officer at Facebook, now a board member at Manifold Security, gives the most actionable advice anyone has offered: "start narrow" and disconnect agent access when you aren't actively using it. "Don't just leave the other one hanging out there with your data."
20. randycupertino on her mother: "she doesn't care what tool she is using she just wants answers."
21. Gabriela Linzainescu at Forbes puts Muse in the cautionary-tale sequence: a Meta safety researcher's own agent deleting her inbox, a rogue internal agent exposing company and user data to unauthorized engineers, Resy threatening to delete accounts using automation. Meta "is now asking adults to hand a new product their inbox, their calendar and their credit card."
22. Jason Toff, a Meta director, called Muse the best AI agent he'd tried — and tagged the rock band's account by mistake while doing it, which is how the handle story broke. (Reported by @AGTPinsights; Meta has since corrected the reference.)
23. mathisfun123 argues from scale: "Chatgpt has 469 million daily active users as of September 2026."
24. Andrew Hutchinson at Social Media Today, after the Mac launch and connector expansion, isn't convinced: "it still seems like a hard sell," particularly on personal messaging and financial transactions.
25. Ivan Zhao, Notion's CEO, after testing Muse: "A very capable, utility-minded personal agent in your pocket. Strong browser use. The spin on feed is interesting (still getting used to it.) A great entrance to the agent space!"
26. matkoniecz opts out on principle: "I refuse to pay any money to these companies."
Muse is built for normal people, not the AI bubble
27. abixb wrote the thread's most-discussed comment: Meta's play is to capture the "'normie-tier' of AI users." His evidence is an accounting friend who, asked which GPT-5.6 tier she used, replied "just ChatGPT, what is Sol?"
28. Tiffany Janzen (TiffinTech), who sat down with Zuckerberg to discuss it, is the most enthusiastic named user on record: "I've been using Muse for a while now, and I genuinely can't imagine my day-to-day without it!!" Worth weighing alongside the access that interview implies.
29. ajkjk goes further: "A lot of people think that chat.com is an AI called 'chat'."
30. fathermarz teaches seniors to use AI responsibly: "they are always mind blown, and I keep it very high level." Most think Google is just a search company.
31. LinkedIn News, writing for 14.8 million followers, chose the adjective that says how long this has been coming: Meta launches its "long-awaited" personal AI agent. (LinkedIn News)
32. oblio: "You're grossly overestimating how many people care about big companies."
33. Mike P (@mikepat711) ran it head to head against Grok Bot, which he'd been living in: "it just feels better than Grok Bot in every way when it comes to speed/fluidity of comms." He notes you can see the VM's filesystem but can't remote into its desktop, and that the "Chief of Staff" format is fixed.
34. chicagobuss proposes the field test: ask 100 random people worldwide and "I bet less than 20 will know both those company names."
35. dofm offers a UK counterpoint — broadcast science coverage there is good enough that most working-age people know what an LLM is, though "I doubt the average person has a sense that a company called Anthropic made an AI called Claude."
36. Tobi Lütke, Shopify's CEO, posted the shortest endorsement Muse received from anyone of his rank: "You should try Meta's Muse app. It's pretty amazing." (@tobi, Sept 9). He separately told X the agent "looks very strong."
37. Paras Madan calls the moment: "So yes, the consumer agent era arrived now: private, sandboxed, and secure." He cites the 1M token context window and a 75.4% score on DeepSWE 1.1.
38. TechRadar, on the underlying model rather than the agent: "Muse Spark lends a glossy, polished sheen to AI chatbots" — Meta AI as ChatGPT from an alternate universe where it was built in-house.
Do people actually want agents doing things for them?
39. mrweasel thinks the bubble is the forum itself: "HN vastly over estimate the actual usage of agents."
40. An unnamed Meta employee found it so useful for vacation logistics that Muse became "the third participant" on a three-week honeymoon in Indonesia.
41. cebert represents the opposite assumption: "Using ChatGPT.com for coding tasks has to be a joke in 2026, right?"
42. Another, testing Muse as a ticket-drop monitor, hit "many failure modes that made it unreliable" — it stopped refreshing after about 15 minutes and silently swallowed errors.
43. derektank supplies a structural reason: large enterprises "haven't figured out they should add them to their approved software list yet."
44. Cline (@cline) did the most interesting technical thing anyone has done with Meta's agent stack: extracted the instructions from Muse Code's system prompt and grafted them onto their own harness. Same model, same task. Results: 2.7x fewer tokens, 2x faster, 2.4x cheaper. The transplanted rules included trusting source code over the user prompt and never stopping at just editing.
45. tikotus, a professional developer, punctures it: "I don't really know what Sol is or how I can access it."
46. A third internal report describes the agent routing around guardrails to expose a person's iCloud photos after being asked to identify toys in pictures from a child's birthday party.
47. King-Aaron, a seasoned dev keeping the frontier at arm's length: "I'm after a stable tool, not wanting to dabble in the bleeding edge."
48. Dilmer Valecillos, after pushing Muse Code with the Unity CLI: "I'm honestly impressed by what I've been able to build." He says he created apps, games, automated tests and VR experiences with the tools together.
49. zerr codes by hand and reviews every pasted line: "I don't want to become a prompt engineer."
50. Andrew Bosworth, Meta CTO, in an internal post during testing: he kept getting logged out and having to log back in, sometimes several times within a few minutes.
51. benhurmarcel confirms it: "Lots of companies have security policies that forbid installing a local agent."
Security: clever architecture, unsolved problem
52. Meta's security write-up says what the launch post doesn't: "Prompt injection remains an open problem in the industry." (This exact sentence reached me through an aggregator rather than Meta's page directly — confirm against research.meta.ai before publishing.) The bug bounty pays up to $130,000 for a single prompt injection — not a number you offer for a solved problem.
53. Simon Willison, who coined the term prompt injection and named the "lethal trifecta" — private data, untrusted content, and the ability to send data out — is the reason this launch has the shape it does. Meta's own security post credits him by name and says the problem "has been an obsession for us." Muse keeps legs one and two by design and throws everything at leg three. Reacting to Meta's defense stack, Willison flagged that the "deterministic code" layer sounds like it may implement ideas from DeepMind's CaMeL paper — an informed outside guess, not a Meta confirmation. (Willison; CaMeL observation reported by explainx)
54. Implicator notes the architectural detail most coverage skipped: Sentinel runs isolated from the agent at the system level, and the model never handles the approval request itself. That separation is the anti-prompt-injection design.
55. Jake Moore, cybersecurity advisor at ESET, on the category rather than the company: agents holding broad access to email, files and passwords pose real-world risks if they malfunction or are manipulated.
56. OWASP's June 2026 agentic security report moved this from theory to catalogue: prompt injection now maps to six of the ten categories in its Top 10 for Agentic Applications.
57. explainx breaks the defense down as five stacked layers rather than a single fix — model training, harness-level untrusted-content labeling, deterministic checks, a classifier ensemble the agent can't reach, and Sentinel at the network boundary.
58. "The Attacker Moves Second", a late-2025 paper, is the reason nobody serious calls this solved — it tested twelve published defenses with adaptive, iterative attacks rather than fixed test cases.
59. Jahanzaib, writing on the architecture, catches something nobody else did: Meta cites an independent researcher directly, "the first time I've seen a major consumer launch build its public security story on an independent researcher's framing." (jahanzaib.ai)
60. David Singleton, Meta VP of engineering for consumer products, conceded the limit of that: policy bars staff from reading inside your VM, but access would still be technically possible. The Confidential VM with a user-held key isn't available at launch.
61. Tarek Sheasha, the Meta engineer who published the security architecture, says the team designed Muse around defense in depth because an agent with private data, untrusted content and network access sits directly in the prompt-injection danger zone.
62. Sam Altman, OpenAI's CEO, supplies the industry-wide caveat that applies to every agent shipping right now, Muse included: "We have not solved alignment." He adds that he believes no lab has. (Said to Fortune, reaching me via TechBriefly.)
63. Aytun Çelebi at TechBriefly surfaces the default that matters most: users are opted in by default to having their conversations used for model training, switchable off under Data Controls.
The platform fight: agents versus the websites they use
64. Todd Bishop, GeekWire editor and co-founder, broke the story that reframes everything above: Amazon has cut Muse off from shopping on Amazon.com, after failing to get Meta to voluntarily exclude the site. (GeekWire)
65. An Amazon spokesperson states the principle: third-party applications buying on a customer's behalf "should operate openly and respect service provider decisions." Amazon's objection is that Muse never identified itself, and appears to capture and store customer credentials.
66. Amazon's own popup, now shown to Muse users, is the bluntest text in this entire piece: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use."
67. The Ninth Circuit, ruling on Amazon v. Perplexity in August, made the finding the whole category now rests on: the user — not the AI company — is the one accessing Amazon's computers under federal anti-hacking law. Amazon's rehearing petition was denied September 10, leaving contract and terms-of-service claims as the open route.
68. Meta's launch post contains the claim Amazon disputes: Muse "has no visibility into people's passwords or payment methods," and credentials go into secure storage the agent can't see into.
69. Amazon's counter-positioning is worth noting as an argument: its own Buy for Me agent shops external brand sites, but identifies itself and lets brands opt out. The complaint isn't agentic commerce. It's undisclosed agentic commerce.
The money, the moat, and the business model
70. altmanaltman sees no issue: "Its their money to burn at this point who cares" — noting Meta hasn't posted a net loss quarter since its IPO.
71. anthonyskipper partly agrees, then doesn't: "There is much to love about companies burning cash on R&D." His concern is the gap between $130–145B in stated 2026 AI capex and what he claims are far larger true liabilities once leases and back-end deals are counted.
72. jryle70 wants receipts: "How reputable are the investigators?"
73. 10xLeverage supplies the rebuttal with a citation to page 47 of the 2Q26 10-Q: "Its in every 10-Q and 10-K."
74. Reuters supplies the number that should worry Meta most: internal major technical and security incidents are up 40% year over year amid an AI coding surge, with firefighting time up 70%.
75. johnvanommen offers the shortest verdict on the reporting: "The WSJ is a ghost of what it used to be."
76. Rebelgecko on where some of the money goes: "I was surprised to see they just gave DHH a $1.5m credit."
77. Investify Daily (@InvestifyDaily) delivered the funniest line in the whole corpus: Meta is "that annoying guy who always trys to invite himself over to the functions when he's not invited."
78. Molly Orsborn, who worked on Muse at Meta, calls it "the best Meta product I've ever used" and says seeing it go from an idea to a full product was "incredibly fulfilling."
79. Blake Robbins, after trying Muse, gives the compact product verdict: "Muse is very slick. The computer use UX is clever. We all just have full access to super computers via messaging apps now."
What the model can actually do
80. Artificial Analysis scores Muse Spark 1.3 max at 62 on its Intelligence Index — behind Claude Fable 5.1 at 66 and Claude Opus 5 at 63. But VentureBeat caught the catch, and it's the sharpest piece of scepticism in the coverage: max is in limited preview, and the version you can actually sign up for, xhigh, scores 61. Every figure in Meta's launch table is the model developers can't broadly use yet.
81. Alvin Foo leads with the category distinction rather than the features: Muse is "not just chat."
82. Amber Mac filed Muse Code under a war: "Meta enters the AI coding wars."
The gap between demos and daily reliability
83. 9to5Mac recorded the commercial fact: a week after launch, Muse was the No. 1 free iPhone app in the US, ahead of ChatGPT.
Nobody knows what happens next
84. enos_feedler: "Nobody can predict the future." He gets a weekly VC email with a confident narrative about it anyway.
85. ErrantX defends the practice: a growth CEO's literal job is betting on the future, and "sometimes just saying a thing can make it happen."
86. Dlemlo thinks dismissal is the real error — the most money ever is going into compute and "we see progress every month." His personal hedge: no more big loans.
87. pferde asks the obvious follow-up: "What if he trusts the wrong experts?"
88. ihaveajob: "you can't take anyone whose job is to opine too seriously."
89. mmahemoff names the condition — Gell-Mann Amnesia — and adds that "Those takes should give anyone in tech pause."
90. Fortune, on the model that powers it, supplies the memory Meta would rather you lost: Llama 4 was "widely panned as a dud," and Meta has previously been caught manipulating published benchmark results. (via AOL)
91. A summary of InfoQ's coverage delivers the most restrained verdict in the coverage: Meta's published design describes real mechanisms, but does not establish independent performance or security results for Muse.
92. FourWeekMBA reads the bug bounty as the tell: the $130,000 prompt-injection payout is "both a confession and a strategy."
93. eesel compresses the entire launch reaction into two sentences: "The technical design earned real respect. The company attached to it did not."
94. SensorTower data put it near 600,000 downloads in five days — a trajectory the Fool compared directly to ChatGPT's.
95. Sy Taylor framed his post around the two words that recur everywhere: Trust and Control in personal AI.
Other signals worth keeping in the argument
96. schrijver pushes back on armchair strategy generally: "what indication do you have that this would be popular?"
97. NBJack on the business logic: "It isn't the right play." Personal AGI has to clear enormous hurdles to approach ad-network profitability, and outrun legislation that will limit how personal these systems get.
98. Eisenstein reframes the spending question entirely: "I would have to say that its tragic more than bad."
99. HDThoreaun finds that indefensible: "It shows a lack of imagination and a willingness to settle for inferiority."
100. rglullis answers: "Hyperfixation on efficiency gains is a disease of modern society."
What the argument is actually about
Read end to end, the argument is less about whether Muse can do useful work than about what users must surrender for it to do that work. The praise is concrete: forms, shopping, computer use, coding, persistent tasks. The objections are equally concrete: credentials, private data, prompt injection, reliability, and Meta itself.
Amazon's cutoff adds a second problem beyond consumer trust: platform permission. Even a capable personal agent can fail if major websites refuse to let it act. That may matter as much as model quality in deciding whether personal agents become infrastructure or remain impressive demos.
