Home RSS The Muse Is Loose: Inside Zuckerberg’s $100-A-Month Bet That You’ll Let Facebook...

The Muse Is Loose: Inside Zuckerberg’s $100-A-Month Bet That You’ll Let Facebook Run Your Life

0
25

The Muse Is Loose: Inside Zuckerberg’s $100-A-Month Bet That You’ll Let Facebook Run Your Life

Those lucky enough to be living under a rock in the past month, would be surprised to learn out that after trading near the year’s lows in mid-August, Facebook Meta stock just hit a 2026 high, and it is all thanks to the constant buzz over the release of its Muse AI agent two weeks ago, which has not only taken the tech world by storm, but sent Meta shares an additional 21% higher in that period vs just 1% for the S&P.

What is it?

Muse, which was launched on September 8, 2026, is what Meta calls “the world’s first personal AI agent built for everyone.” Instead of just chatting, it carries out everyday tasks such as purchasing, travel, email and organizing for you, with reported pricing of $20 and $100 monthly besides a generous free tier.

Two weeks after launch it’s growing fast, amid a broad range of reactions from euphoria, to skepticism, to outright revulsion. Gravitating toward the latter end of that spectrum, none other than Amazon earlier this week announced it would ban the use of Muse on its retail website. Ironically, that may have only helped Meta, whose downloads in the first two weeks since launch have surpassed none other than ChatGPT itself.

The market reaction has also been rapid and intense: not only has it helped push Meta stock into the stratosphere, it has once again prompted “disruption” fears, sending banking and various “consumer inertia” stocks sharply lower amid fears that Muse, running in the background, could make the drudgery of moving one’s bank account, canceling existing subscriptions and generally anything with “high switching costs”, a thing of the past. 

To that point, in its end of day wrap, Goldman yesterday said that “the most talked about theme on our desk today was the impact of Agentic AI post Meta Muse and the shorting of “Consumer Inertia” names. Our basket, GSXUSWCH (-2.58% today), which has been one of our most actively traded baskets in recent sessions, consists of stocks in industries where customer retention is supported by “behavioral, operational, contractual or financial switching costs.” …in other words, services that are hard to cancel (unless you have Agentic AI do it for you).” Goldman went on to point out some of the biggest losers from this basket, including PLNT, NYT, SCHW, ALL, and INTU.

Yet through it all, Muse has continued to climb in the App Store to currently the #1 most downloaded free app in the US, and at  increasing download volume compared to a week ago. The combination of virality and Meta’s strong distribution platform (the company reportedly reaches over 2 billion users) make the buzz around Muse quite palpable.

Following the accelerated model progression of Muse Spark with big gains in agentic and multimodel capabilities in recent months, Meta is also shipping quickly around Muse with a series of innovations within just two weeks from launch. Meta launched a beta for Muse outbound calls to US businesses (where it may have had some help from old-school call centers), opened access for developers to build Muse connectors, launched Muse for Mac, and added Shop Pay for agentic checkout, among other improvements. Earlier today, Zuckerberg even introduced a Muse Charm pendant during Meta Connect. 

In a note discussing the launch of Muse, JPMorgan’s Dough Anmuth (full note available to pro subs), wrote that Muse’s early traction reflects three key drivers:

  • Strong product-market fit, including leading agentic performance, ease of use, and an emphasis on privacy/safety (good luck with that).

  • a generous free tier that reduces friction for trial and repeat usage;
  • Meta’s scaled distribution advantage.

While it is still early, JPM believes that Muse has the potential to become the most widely used consumer AI application since ChatGPT. The bank also believes that Meta is currently focused on learning how people are using Muse and improving the product, while also increasing consumer adoption and engagement. Opening up access for developers to build Muse connectors last week was also significant as it is the first of likely many steps to bring businesses into Muse.

As tens of millions, and then potentially hundreds of millions of businesses, ultimately have their own agents on Muse, the bank expects Muse transactions to be handled less by browsing or calling, and more through agent-to-agent interactions. At that point, Meta will be able to monetize on a take-rate or commission model – or based on whatever the business’s goals are – similar to how it monetizes in advertising today.

Some more details

To justify its claims that Muse adoption is early and encouraging, JPMorgan writes that Muse has “shown strong early signs of virality and consumer adoption,” with Muse reaching the #1 most downloaded free app in the U.S. and Canada Apple App Stores…

… and daily downloads in the U.S. now exceeding all other Meta Family of Apps.

JPMorgan believes Meta’s near-term priority with Muse is to continue to drive adoption and engagement, with monetization beyond heavy-user subs likely not coming until at least 2027. As such, Meta is already starting to push Muse via ad inventory on Instagram and Facebook, and is offering 1 Billion Muse Tokens for inviting friends to Muse in addition to launching a national TV ad campaign.

Additionally, Muse’s generous 100M free weekly tokens will likely be a core driver of sustained engagement as it compares favorably to Grok Bot ($30+/mo) and Gemini Spark ($20/mo), while Instinct (free) is still invite-only given compute constraints.

At its Q2 earnings, Mark framed consumer personal agents as a potentially massive market, with billions of people likely to use agents that understand their goals and work 24/7 on their behalf across health, hobbies, finances, productivity, relationships, & more. Meta is positioning Muse as clearly differentiated from traditional chatbots by emphasizing its ability to take action rather than simply answer questions, supported by computer-use capabilities & connections to the apps people use daily.

In addition to the existing library of Connectors (incl. Gmail, Spotify, Peloton, Opentable, and more), Meta recently opened access for developers to build Muse Connectors for their apps and services, and Muse can also guide users through creating custom Connectors for unsupported services.

Early Muse use cases suggest the product broadly aligns with the vision Meta laid out, with users sharing examples across commerce, product research, restaurant bookings, travel planning, email/text drafting, and other multi-step workflows.

While JPM expects Meta to prioritize adoption and engagement over monetization near term (consistent with its historic playbook), especially since Meta – like XAi – has excess compute among its many data centers – many of these workflows also provide a clear line of sight to longer-term monetization via:

  1. a take-rate/ commission model based on transactions/objectives that Muse facilitates (e.g. shopping checkouts, reservations, flight/hotel bookings, lead generation)
  2. subscriptions for incremental usage. It will take time for small businesses and larger enterprises to launch agents on Muse, but agent-to-agent interactions will likely form the foundation for Meta’s monetization.

Also, while Muse and other agents will surely face pushback from online platforms and marketplaces early on, e.g. Amazon has blocked Muse access, JPMorgan still expects broader ecosystem participation over time as agents prove to be incremental sources of traffic and transactions.

Turning to the market, JPM’s Anmuth writes that “on a very tactical, short-term basis, we believe that some investors became more cautious heading into this week on the view that Muse had already launched, Watermelon would likely come after Meta Connect, & OpenAI would release its competing agent product this week, all of which may have contributed to Monday’s outsized move in Meta shares.” More broadly, he expects Muse adoption and engagement to continue to ramp, with Meta beginning to prove out AI returns—and leadership—beyond its core advertising platform, with a Total Addressable Market potentially in the tens of trillions of dollars. 

Of course, it’s not just unicorns and rainbows. 

A deeper dive reveals that at its core, Muse is merely an updated and modernized version of OpenClaw, the first real agent, and one which Meta’s highly overpaid AI chief Alexandr Wang “reverse engineered” and repurposed for Meta’s massive audience, using its vast distribution platform to capture agentic market share while taking advantage of Meta’s massive excess compute. 

An X user explains why this matters:

The bottleneck in personal AI agents was never the model. It was the signup flow.

Nat Friedman said something worth sitting with today: Meta built Muse from scratch, but it’s heavily inspired by OpenClaw, and after using OpenClaw in January he bought hundreds of Mac minis for his team because they fell in love with it.

Here’s the mechanism. OpenClaw is a self-hosted agent framework that Peter Steinberger and dozens of contributors built in under six months. It crossed 100,000 GitHub stars in its first week and has passed 387,000 stars, one of the fastest growing repos in GitHub’s history. You run it on your own server, point it at any model, and it manages memory, browsing, messaging and cron jobs through plain markdown files: SOUL.md, IDENTITY.md, USER.md.

Muse, which Meta shipped September 8, uses that same file structure. Its own agent confirmed it when asked directly: it runs on those exact files. Meta didn’t need to out-engineer the open source version. It needed to remove the server, the API keys and the config, and hand three billion people a one minute signup instead.

The result: Muse pulled 902,000 downloads in its first six days, ahead of Meta AI’s own 773,000 in the same window, and META stock jumped more than 12% on the numbers. Nous Research’s Hermes Agent is chasing the same self-hosted lane and can import OpenClaw’s settings directly. Steinberger is now joining OpenAI to work on agents for everyone, and OpenClaw is moving to a foundation to stay independent.

I’ve watched this movie before. Docker didn’t invent containers. Slack didn’t invent chat. The lab that wins is rarely the one that proves the concept. It’s the one that removes the last piece of friction between the concept and a normal person’s Tuesday.

The hidden bottleneck was distribution wearing a technical costume. My take for founders: if your product needs a server and an SSH session just to try it, you’re one onboarding flow away from a much bigger company doing it for you.

The problem with rushing out an optimized version of the original agent is that Meta appears to have steamrolled over some of the most basic tenets, such as security and privacy. Regarding the first, this is what ArsTechnica said

Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant, Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.

… For Muse to do [the things it does], users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources, like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures.

The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings. Most of them are fairly innocuous, such as controlling dark mode. One setting, however, is anything but innocuous. It allows processes to change the endpoint where transcription occurs. Normally, it’s a server address operated by Meta. Attackers can exploit this flaw by changing the location to their own endpoint. Once that happens, the attackers have the token that gives complete control over the Muse account.

…

“To me, the bar is infinitely higher in terms of the security of these apps. They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome,” Wardle said. “At the very least, they should be thinking about security from the very start, and they are just not.”

Which brings us to privacy, which at best was an afterthought for Muse. IBM Vice Chair Gary Cohn told Yahoo Finance that he is not ready to use the service because of privacy concerns. He has good reason for that, as this excerpt reveals: 

I installed Muse on my iPhone and then on a Mac mini I have basically for this very purpose. I asked it to write a bio of me from what it knew about me. After some back and forth where it told me it only knew my name, I suggested it use its browser to find some info. It did, and it came back with a reasonable bio. It isn’t one I would ever use, but that wasn’t the point. I just wanted it to do its first research on me.

I then asked it to suggest things it might do to help me, based on what it knows about me. It suggested researching topics for articles, helping book podcast guests, and creating a morning briefing each day on stories and events it thinks I might want to write about.

Then, yesterday, I was having a conversation with my Primary Technology podcast co-host, Stephen Robles, about the new iPhones. Moments later, I got a push notification from Muse suggesting that the conversation we were having would make for a good column and offered to put together research for me to write about. It even flagged a message from my editor about having a column ready for Monday.

Not only had I not asked it to do that sort of thing, I never gave it permission to read my messages. In fact, I remember explicitly choosing not to let it have access to my messages, calendar, and other personal information.

Stranger still was what happened when I asked Muse how it knew. It told me it didn’t have access to my message history at all. Instead, it said the Muse app on my Mac was simply passing along the text of incoming notification banners.

“When a notification pops up on your paired Mac, the text of that notification gets relayed to me—basically what you’d see in the banner itself,” Muse told me.

It went even further. “I can’t open your Messages app, scroll threads, or read history. It’s the incoming notification stream only, not access to your texts.” Except that wasn’t true.

And then, there are plain old glitches as this op-ed from Inc shows:

If you haven’t read my piece about Muse uploading all my private text messages and then hallucinating an explanation, you probably should. The short version, however, is that if you give it Full Disk Access on a Mac, it will do things way beyond what you’ve asked it to do. And I’m a pretty tech-savvy person, and I did not give Muse permission to access my messages, and I never once asked it to perform a task that would have required it to do that. Still, it started sending me push notifications about texts I was receiving from my editor as well as my podcast co-host.

When I asked Muse how it knew what I had been talking about, it told me it could see notification previews from my Mac. When I pushed further, it told me it couldn’t give me “the exact plumbing.” It turns out the robot just made that up. The real answer was much worse.

Adding insult to injury, there is a clear incentive to dissemble and prevaricate from day one, an immediate warning sign which got Muse blocked from Amazon.

Looking at the shipping version of the Muse app, I noticed that the code includes evidence that its automated browser goes out of its way to not look like an automated browser. Muse also launches Chrome in a way that disables automation indicators and injects code that hides navigator.webdriver—the standardized property that tells a website a browser is being controlled by automation. 

Muse also creates fake values in Chrome for things like browser plugins. That’s designed to create a browser fingerprint that appears more like one belonging to a human, not a robot. It even checks pages for signs that it has been detected or blocked, including CAPTCHAs, “verify you are human,” “access denied,” and Cloudflare’s “Ray ID.” This is especially notable given Amazon’s claim that Muse does not identify itself as an AI agent when visiting its store.

* * * 

To be clear, I’m not suggesting Muse is secretly reading everyone’s messages or routinely bypassing macOS security. I still haven’t gotten an answer as to how it was reading my messages with Full Disk Access turned off, but I’d be happy to dig into it with anyone from Meta that wants to help. I am, however, suggesting that trust is the single most important asset any company has, and Meta has a giant Muse-sized trust problem.

Assuming one is ok with all of this, the next question is how much will all this cost Meta?

As WCCFTech explained , to eliminate privacy concerns, Muse runs inside a dedicated and isolated cloud computer – a Virtual Machine or VM – that contains its own browser to securely house your data and credentials. A second guardrail, called a Sentinel, continuously monitors the environment, and ensures that the agent does not finalize transactions without both Sentinel’s approval and your explicit confirmation.

Referencing an X post, the outlet notes that Meta has promised each Muse user a dedicated VM, replete with 2 vCPUs, 8GB of RAM, and 100GB of SSD. Assuming the personal agent scales to 100 million users within 1 year – entirely plausible especially as it is already topping app download leaderboards – Meta would require at least 1.58 million AMD Ryzen EPYC CPUs, where each such CPU has 126 cores.

Of course, Meta can reduce this number by heavily sharing CPUs between active users. If 10 percent of Muse userbase is active and running tasks at any given time, the CPU load falls to 158,000 AMD Ryzen EPYC units. Of course, to maintain network scalability, Meta might have to target a 50 percent userload, which then translates to 0.79 million AMD Ryzen EPYC CPUs. As such, a lot rides on the overall compute architecture that Meta follows.

The memory and storage conundrum, however, is trickier still. Since your personal persistent Muse VM has to be available 24/7, 100 million users can entail 100 petabyte of RAM and 10,000 petabyte of SSD. Of course, not all users will consume this quantum of storage.

For obvious reasons, these compute requirements are quite strenuous, and can rapidly scale if Meta allows access to Muse via WhatsApp and Instagram. It is hardly a surprise, therefore, that Meta appears to be going all-in on compute in recent weeks and months, becoming the primary co-developer and lead deployment partner of Arm AGI CPU in March 2026. The tech giant also added tens of millions of AWS Graviton cores to its compute portfolio in April 2026.

Taking a closer look at the math reveals some truly startling numbers as laid out here:

Every Muse user is supposed to get their own cloud PC. 2 vCPUs, 8GB RAM, 100GB disk. 

If Meta actually leaves those boxes on, user growth turns into a chip and memory problem.  that’s what i’m trying to size

Muse is 13 days old and US only
App Store downloads are still under 1M on iOS; Add WhatsApp, web, android, mac and you might have 1-2.5M accounts. Most of those are not hot machines. Call live VMs closer to a million 

Ok, where does this go:
– stays messy and US-heavy: maybe 30M in a year
– whatsApp works: 25M in six months, 100M in a year
– they force it through whatsapp and insta: 250M

Let’s go with 100M, the middle scenario

Those EPYCs have 126 cores. Two vCPUs per user means about 60 VMs per chip if nobody is sharing. Share them and you fit more, and it is less of a private machine.

if you leave them 1:1 and always on:
today → tens of thousands of chips, 14 PB RAM  
25 million → 400k chips, 200 PB  
100 million → 1.6 million chips, 800 PB RAM, ~1.6 GW  
250 million → 4 million chips, 2 EB  
1 billion → 16 million chips, 8 EB

$AMD
Ships on the order of 10 million server chips this year. The whole industry about 39 million. 
100 million dedicated Muse users is a visible piece of AMD’s year, and they were already getting called sold out. Next die has more cores, which is how you stuff more VMs on the same chip.

CPU time can be shared. That RAM stays reserved if the files are supposed to live on the box. 2026 DRAM is already spoken for, HBM first. 100M users would lock up about 1% of a year’s DRAM bits. A billion users, 10%.

Meta’s own power plan is 7 GW this year, 14 next. Training and ads are already in that.

The paid tiers do not cover it. 
Ten million people on $20 is $2.4 billion a year. 
Last quarter Meta did $60.8 billion, almost all ads, and $31 billion of capex. 
Full year capex is $130-145 billion. 100 million 
VMs is $30-50 billion of hardware if you actually build them.

The conclusion: “either a lot of those VMs get frozen when idle, or this does not scale as advertised”

To summarize: judging by the initial reception, the Muse has been very successful, and as of this moment, it has enough momentum to become the most popular agent in the world. However, those using it should be aware of three things: they will have no privacy, and virtually no security (good luck getting customer services at the free tier when Muse goes rogue and deletes all your emails or spends all your money on pizza deliveries). Worse, the glitches of this rushed product will only emerge over time. And then the question is how much will all this cost Meta, which is already neck deep in capex, and its CDS is soaring to all time wides, outperforming just the debt basket cases that are SpaceX and Oracle. 

Which leads us to the last question: after the initial phase of curiosity fades, how many people will be willing to pay Zuck $20 (or $100) every month to run their lives?

The answer will determine if Zuckerberg’s latest toy will become what JPMorgan said could be the “most widely used consumer AI application since ChatGPT”, or if a better name for Muse would have simply been Metaverse 2.0… and its trademark bottomless money pit.

More in the full JPMorgan note available to pro subs.

Tyler Durden
Thu, 09/24/2026 – 00:55

This post was originally published on this site