Meta’s Muse AI agent surged to 2.5 million downloads in its first 13 days of availability. Operating on a freemium model, the agent handles everyday tasks like sending emails, booking travel, lowering bills, filling out forms, creating plans, and making purchases using Link by Stripe for checkout.
Muse Reaches 2.5 Million Downloads and Offers Paid Tiers
The agentic service attracted 750,000 downloads within its first five days before reaching the 2.5-million milestone. Users can connect Muse to apps and services part of everyday workflows, including email, calendars, payments, health and fitness, smart home, dining, shopping, music, and events. Meta notes that Muse can score tickets, pay and file old bills, triage inboxes, and check state databases for old unclaimed money. Analysts point out that Muse represents a true way to generate non-advertising revenue for Meta through its paid subscription tiers, which include Power at $20 per month and Maximum at $100 per month.

Meta Trains AI on User Data from Connected Services
Despite the rapid adoption and excitement that has carried Meta’s stock forward, the agent requires direct access to connected services like email accounts, offering a deep view into users’ worlds. By default, Meta trains its AI on user data. When a conversation or interaction is deleted, Muse may still retain info related to it, with Meta describing this as Muse may still remember information it learned from what you deleted.
Meta states in its privacy policy that training data is anonymized, disconnected from original users, and scrubbed of personally identifiable details like names, Social Security numbers, email addresses, and phone numbers. Users can ask Muse what it recalls or inspect various Muse files.
Security Vulnerabilities and Questions of Verification
Security concerns have emerged following the discovery of a zero-day exploit just a couple of weeks after launch that briefly allowed macOS apps and terminal commands to commandeer the AI agent and access connected services. Additional configuration settings in macOS allegedly allowed Muse to gain access to private messages in other apps. Beyond hacking risks, industry observers note that while enterprises have scaffolding, verification, and redundancies, everyday consumers lack those built-in protections when an agent makes a mistake.