Meta used its Connect 2026 keynote on September 24 to push its personal AI agent, Muse, well past chatbot territory. The company confirmed that Muse is getting real-time video conversations with customizable digital avatars, its own dedicated email address, and the ability to run apps directly on a Mac. Reported first by The Decoder, the announcement turns Muse from a task-taking assistant into something closer to a standing digital employee: one that can be looped into an email thread, join a video call wearing a face you picked, and click around a desktop the same way a person would.

For a security and privacy audience, the headline features are less interesting than what they imply about access. An AI agent with an email address can receive messages and act on them without a human relaying each step. An agent with Mac control can open apps, move files, and interact with software that was never designed with an autonomous caller in mind. Video avatars raise their own identity questions once a synthetic face starts showing up on calls. Meta’s framing at Connect was expansion and convenience. The more useful read is what each new permission actually opens up, and how it compares with what OpenAI, Google, and Anthropic have already shipped.

What Meta announced at Connect 2026

Muse launched on September 8, 2026 as Meta’s personal AI agent, available in the United States through a standalone app and through WhatsApp, according to Meta’s own rollout materials and reporting at the time. It is rolling out across iOS, Android, and a web version at muse.ai, with Meta saying support for its AI glasses is coming soon. The agent is built to handle everyday tasks: sending emails, booking travel, making purchases, and managing connected apps across categories that include email, calendar, payments, health, shopping, and smart-home systems. Users choose which apps Muse can touch and can revoke access at any time. Meta has set the product for adults, restricting it to people 18 and over.

Two weeks later, at Connect, Meta layered three capabilities on top of that base. The first is real-time video chat with a customizable avatar, powered by a model Meta calls Muse Realtime Avatar. The second is a dedicated email address for the agent itself, so a user can cc Muse on a thread or forward a message and have the agent act on it directly rather than being told about it secondhand. The third is expanded computer-use on Mac, letting Muse operate applications on a user’s own machine instead of staying confined to the apps it already had API-level access to. The Decoder, which broke the news, reported all three as part of the same Connect keynote, alongside other hardware announcements including a Tamagotchi-style companion device Meta calls Muse Charm and a new line of camera-free Ray-Ban Meta Audio Glasses.

What Meta has not confirmed is just as notable. There is no published rollout date for the video-avatar, email, or Mac-control features individually, no pricing tied specifically to them, no stated Mac system requirements, and no disclosed format for the new email address. Meta also has not named the shopping or technology partners involved in extending computer-use beyond the current app integrations. Readers should treat those specifics as pending until Meta publishes them, not as settled facts.

Why an AI agent needs its own email address

Giving an AI agent an inbox sounds like a small convenience. In practice it changes the trust model. Right now, most agentic assistants act as delegates: a user asks for something, the agent calls an API on the user’s behalf, and the interaction ends. An email address turns Muse into an addressable party that other people, and other systems, can contact directly. Forward a hotel confirmation to it and it can rebook. Cc it on a group thread and it can draft the reply. That is the pitch, and it is genuinely useful.

It is also a new inbound attack surface. Email is still the most common delivery mechanism for phishing and business email compromise, and security teams have spent two decades training humans to be suspicious of unexpected attachments and urgent-sounding requests. An AI agent reading that same mail has none of that trained skepticism unless Meta has built it in, and Meta has not published details on how Muse filters or flags suspicious inbound messages sent directly to its own address. Industry researchers tracking agentic AI risk, including contributors to the OWASP GenAI Security Project, have flagged prompt injection delivered through routine content (emails, documents, calendar invites) as one of the most practical ways to manipulate an autonomous agent, precisely because the content looks unremarkable to the system parsing it. An agent with its own email address is, by definition, exposed to more of that inbound content than one that only receives instructions from its owner inside an app.

Muse already runs each user’s agent and data inside a dedicated, secure virtual machine, which Meta has described as a way to isolate one user’s session from another’s. That isolation matters more, not less, once the agent has an open inbound channel. A compromised or manipulated instruction reaching Muse through email is now a risk that lives inside that VM boundary, and how well that boundary holds is something outside researchers have not yet had the chance to test publicly.

Mac control: from app permissions to desktop access

The jump to Mac computer-use is the bigger architectural shift of the three. Up to now, Muse’s abilities were bounded by whichever apps a user explicitly connected, each with its own scoped permissions that can be revoked individually. Desktop computer-use is different in kind: instead of calling a defined API, the agent operates the same interface a human would, clicking buttons, typing into fields, and moving between applications. That is a much broader grant of trust, because it is far harder to audit exactly what an agent did inside a GUI session than to log a discrete API call.

Meta is not the first to ship this. OpenAI’s Operator and Anthropic’s Claude computer-use both pioneered screen-level agent control before Meta expanded Muse to Mac, and both companies published safety documentation flagging the same core problem: an agent that can click anything on screen can also be tricked into clicking something it should not, whether through a manipulated webpage, a misleading dialog box, or a malicious file disguised as something routine. Meta has not yet published equivalent technical documentation specific to Muse’s Mac computer-use mode, which makes it hard to evaluate how its guardrails compare until that material becomes public.

For IT and security teams, the practical question is simpler than the architecture: does an employee’s personal AI agent, one designed for consumer tasks like travel booking and online shopping, belong anywhere near a work Mac. Amazon has already answered that question for its own staff. The company blocked Meta’s Muse agent internally over data-handling and access concerns, according to earlier reporting on the Amazon block of Meta’s Muse agent. Expanding Muse’s reach from phone apps to desktop control gives every enterprise security team a reason to revisit that same calculus, regardless of what Amazon specifically cited.

Video avatars and the identity problem

The Muse Realtime Avatar feature lets users pick a customizable digital face for real-time video conversations with the agent. On its face, this is a UX choice, aimed at making a text-based assistant feel more like a video call with a person. Meta has not detailed how avatar identities are generated, whether they are limited to stock options or can be customized to resemble specific individuals, or what safeguards exist against impersonation.

That ambiguity matters because synthetic video has become the fastest-growing category of fraud tooling over the past two years. Deepfake video calls have already been used in real corporate fraud incidents to impersonate executives and authorize wire transfers, and regulators in multiple jurisdictions have been pushing companies to adopt call-back verification specifically because a video feed is no longer sufficient proof of identity. Meta putting a mainstream, customizable AI avatar into a consumer product used by millions does not itself cause that problem, but it normalizes exactly the kind of video interaction that fraud investigators have been warning people to distrust. Meta has not said whether Muse avatars will carry any visible or embedded marker distinguishing them from a live human on a call.

The competitive landscape: how Muse compares

Muse is entering a field that already has three serious players, each of which built its agent around a different starting point. OpenAI’s ChatGPT has been steadily widening from a chat interface into a task-execution layer, most recently adding inbox, calendar, and Slack access, as covered in our report on ChatGPT Voice’s email, calendar, and Slack integration. Google’s Gemini has taken the platform route, landing as a fourth major OS integration on Windows itself, discussed in our coverage of Gemini reaching Windows and the data-risk questions that followed. Anthropic’s Claude has focused more narrowly on coding and enterprise use cases rather than consumer task automation, keeping its agent surface smaller by design.

Meta’s angle is breadth of personal-life integration paired with its own hardware. No other major agent is simultaneously targeting a phone app, a messaging platform (WhatsApp), a browser client, and AI glasses the way Muse is. That is a wider surface area than any competitor is running through a single agent identity, and it is also why the security questions around Muse carry more weight than they might for a narrower product. The table below lines up what has been publicly confirmed about each major consumer AI agent’s access scope as of this week.

AgentMakerEmail/Inbox AccessDesktop/Computer ControlVideo AvatarPlatform Reach
MuseMetaYes (dedicated agent email address)Yes (expanding to Mac)Yes (Muse Realtime Avatar)iOS, Android, muse.ai, WhatsApp, AI glasses (coming)
ChatGPTOpenAIYes (inbox, calendar, Slack)Yes (Operator, computer-use)No standalone avatar modeWeb, iOS, Android, desktop apps
GeminiGoogleYes (Gmail, Workspace)Limited, expanding via Windows integrationNoAndroid, iOS, web, Windows
ClaudeAnthropicLimited (enterprise-focused connectors)Yes (computer-use, coding-focused)NoWeb, desktop app, API

Note that the specifics of each competitor’s current permission model shift often, so this snapshot reflects publicly reported capabilities as of late September 2026, not a fixed spec sheet.

Historical context: how we got to agents with inboxes

The path from chatbot to email-holding, desktop-controlling agent happened faster than most product cycles in consumer software. Two years ago, the state of the art was a text box that answered questions. The shift began with tool-calling, where a model could trigger a narrow, predefined action like checking the weather or running a calculation. From there came connector-based access, where an assistant could read a calendar or send a single email through an API with a human approving each step. Muse’s current expansion, an agent with a standing email address and desktop control, is the next rung: persistent, addressable access that does not require a human to initiate every action.

Meta’s own timeline mirrors that arc closely. Muse launched September 8 as an app-and-WhatsApp assistant with scoped, revocable app connections. According to TechCrunch’s reporting on the original Muse launch, the debut came less than two weeks after Meta agreed to an $18 billion multistate settlement tied to a lawsuit over social media’s consumer harms, a timing detail that framed early coverage of the launch around how much trust Meta was now asking users to extend. Sixteen days later, Meta expanded that same product with video avatars, an email address, and Mac control, without publishing new documentation addressing the trust questions raised at launch. That compressed timeline is consistent with the broader industry pattern of agentic AI capabilities shipping ahead of the security tooling built to audit them.

Market impact: why this matters beyond Meta

Meta pushing Muse toward inbox and desktop access puts pressure on every other agent vendor to match the surface area, whether or not the security tooling has caught up. That dynamic has played out before in consumer tech: features ship because a competitor shipped them first, and the safety review happens in public, after launch, through user reports and independent research rather than before release through internal red-teaming alone.

Enterprise IT teams are the group most immediately affected. A personal AI agent asking for Mac-level access is a materially different request than a phone app asking for calendar permission, and it lands at a moment when many companies are still writing their first policies on agentic AI in the workplace. Amazon’s internal block of Muse is an early data point showing that at least one major employer views the current access model as too broad for a managed device, and other companies weighing bring-your-own-AI-agent policies now have a concrete precedent to point to either way.

There is also a consumer-trust dimension that outlasts any single feature. Meta’s $18 billion settlement over social media harms is still recent history, and asking the same user base to hand a Meta-built agent an email address and desktop access is a bigger ask of trust than a News Feed algorithm ever was. How that trust question resolves, through adoption numbers, opt-out rates, or a slower rollout than Meta’s Connect keynote suggested, will shape how aggressively OpenAI and Google push their own agents toward the same permission model.

What security teams should do now

Until Meta publishes technical documentation on how Muse’s new email intake and Mac computer-use are sandboxed, security teams evaluating the product have to work from what is confirmed rather than what is promised. A few concrete steps apply regardless of how the rollout timeline plays out.

  • Treat any AI agent’s dedicated email address as an untrusted inbound channel and apply the same phishing-resistant scrutiny expected of a human employee’s mailbox, including monitoring for anomalous forwarded content.
  • Restrict or block consumer AI agents with desktop computer-use from managed devices until vendor-published sandboxing documentation is available to review, following the model Amazon has already applied to Muse.
  • Audit which connected apps and data categories, email, calendar, payments, health, shopping, smart-home, are actually necessary for a given user, and revoke the rest rather than leaving default access enabled.
  • Watch for guidance from frameworks like the OWASP Top 10 for LLM Applications, which is actively tracking prompt injection and excessive agency as top risks for exactly this class of product.
  • Reassess video-call verification procedures for any workflow that could plausibly involve a synthetic avatar, since Muse’s video feature adds another mainstream source of AI-generated video to an already crowded deepfake landscape.

Predictions: where this goes next

Based on Meta’s Connect announcement and the pattern set by competitors, a few outcomes look likely over the next two to three quarters, though all remain unconfirmed until Meta or its rivals act.

  • OpenAI and Google will likely respond with their own expanded computer-use or avatar features within the next two quarters, continuing the pattern of feature parity racing ahead of safety documentation.
  • More employers will follow Amazon’s lead and restrict consumer AI agents on managed hardware, prompting Meta or a competitor to eventually ship an enterprise-specific, more auditable version of their agent.
  • Independent security researchers will likely publish the first public prompt-injection or account-takeover proof-of-concept against an agent’s email intake channel, whether Muse’s or a competitor’s, within the coming months, mirroring how researchers have tested earlier agent launches.
  • Regulatory attention on AI video avatars will increase, particularly around disclosure requirements, given existing momentum on deepfake legislation in the EU and several US states.
  • Meta will likely stagger the video-avatar, email, and Mac-control rollout rather than ship all three simultaneously, consistent with how it phased Muse’s original app-and-WhatsApp launch before expanding to additional platforms.

What Meta still hasn’t answered

A handful of open questions will determine whether these new Muse capabilities land as a convenience or a liability. Meta has not disclosed a firm rollout date for video avatars, the email feature, or Mac control individually, nor any pricing specific to them. It has not published the technical architecture behind the email intake pipeline, how messages sent to a Muse address are validated before the agent acts on them, or what Mac system requirements the computer-use mode needs. It also has not named which shopping or software partners are involved in the expanded computer-use rollout, or detailed how avatar identities are generated and safeguarded against impersonation.

Those gaps are worth tracking closely, because the difference between a well-sandboxed agent and a loosely governed one usually isn’t visible in a keynote. It shows up later, in how a product handles the first real attempt to abuse it.

Muse feature rollout at a glance

FeatureStatus as of Sept. 25, 2026Access ScopeConfirmed Rollout Date
Base Muse agent (app + WhatsApp)LiveConnected apps: email, calendar, payments, health, shopping, smart-homeSeptember 8, 2026
Real-time video avatar (Muse Realtime Avatar)AnnouncedVideo call interface with customizable digital faceNot disclosed
Dedicated agent email addressAnnouncedDirect inbound email to the agentNot disclosed
Mac computer-useAnnounced (expanding)Desktop app control on MacNot disclosed
AI glasses integrationPlannedVoice-triggered task execution on Meta smart glasses“Coming soon” per Meta

Frequently asked questions

What is Meta Muse?
Muse is Meta’s personal AI agent, launched September 8, 2026, that performs everyday tasks like sending emails, booking travel, and making purchases by connecting to apps a user chooses to link, including email, calendar, payments, health, shopping, and smart-home services.

What new features did Meta announce for Muse at Connect 2026?
At Meta Connect on September 24, 2026, Meta said Muse is getting real-time video conversations with customizable digital avatars (via a model called Muse Realtime Avatar), its own dedicated email address, and expanded computer-use that lets it control apps on a Mac.

When will Muse’s email, avatar, and Mac features roll out?
Meta has not published specific rollout dates for these three features individually. The base Muse agent is already live in the US via app and WhatsApp.

Is Muse safe to use on a work computer?
Amazon has already restricted Muse internally over access and data-handling concerns. Security teams generally recommend withholding managed-device access from consumer AI agents with desktop computer-use until a vendor publishes sandboxing documentation.

How does Muse compare to ChatGPT and Gemini?
ChatGPT has added inbox, calendar, and Slack access, and supports computer-use through Operator. Gemini has expanded onto Windows as a system-level integration. Muse is unique among the three in combining a dedicated agent email address, desktop control, and a video avatar within one consumer product tied to Meta’s own hardware, including AI glasses.

Does Muse keep user data isolated between accounts?
Meta has said each Muse agent and its associated user data run inside a dedicated, secure virtual machine, intended to separate one user’s session from another’s. Meta has not published independent third-party audits of that isolation.

Who can use Muse?
Muse is restricted to users 18 and older and is currently available in the United States.

What are the main security risks with an AI agent that has its own email address?
An agent-addressable inbox is a new inbound channel for phishing and prompt injection, since anyone who learns the address can send content directly to the system, not just to the human user. Security researchers, including contributors to the OWASP GenAI Security Project, flag prompt injection through routine content as one of the most practical ways to manipulate an autonomous agent.