Meta’s AI personal agent product, Muse, launched on September 8th, is sweeping through the consumer tech market at an unprecedented pace—racking up 902,000 downloads in its first six days, surpassing Meta AI’s own record for the same period. It has already topped the free app charts on the Apple App Store in the United States and Canada, and has driven Meta’s stock price up an additional 21% within two weeks, far outpacing the S&P 500’s 1% gain during that time.
J.P. Morgan analyst Doug Anmuth, in his latest research note, has characterized Muse as “the most likely candidate since ChatGPT to become the most widely used consumer-grade AI application,” attributing its core momentum to strong product-market fit, a generous free tier, and Meta’s vast distribution platform covering over 2 billion users.
Meanwhile, Goldman Sachs noted in its daily report that the “agentic AI shock” triggered by Muse has become the hottest topic in the market, causing its “consumer stickiness” stock basket to fall 2.58% in a single day.
However, beneath Muse’s glossy surface, currents are stirring. Security researchers have disclosed a zero-day vulnerability that could allow local applications to completely hijack user accounts; multiple users have documented Muse reading private text messages without authorization; Amazon has announced it is blocking Muse’s access to its retail site; and the computing costs required to sustain this product at scale are estimated to reach $30 billion to $50 billion in hardware investment at a 100 million user scale—far exceeding what paid subscription revenue could cover. Whether Muse is the next ChatGPT or another Metaverse-style capital black hole remains an open question.
What Muse Is: From Chatbot to “Doing-It-For-You” AI Agent
Muse’s core positioning is what Meta calls the “world’s first personal AI agent for everyone.” Unlike traditional chatbots, Muse doesn’t just answer questions—it directly executes tasks on behalf of users, covering everyday matters such as online shopping, travel bookings, email management, and schedule coordination.
The product pricing is set in three tiers: the free tier provides 100 million Muse Tokens per week; paid tiers are $20 and $100 per month, respectively. Compared to competitors, Grok Bot’s subscription starts above $30 per month, Gemini Spark is $20 per month, while Instinct is still in an invite-only beta phase.
In terms of technical architecture, Muse integrates with third-party services through a “Connectors” system, with current integrations including Gmail, Spotify, Peloton, and OpenTable. Meta opened connector-building permissions to developers within two weeks of launch, and has since rolled out a Mac version, a beta for outbound calling to U.S. merchants, and an agentic checkout integration with Shop Pay. Zuckerberg also introduced the Muse Charm physical pendant at the Meta Connect event.
J.P. Morgan expects that as tens of millions of businesses deploy their own agents on Muse, interactions between users and merchants will gradually shift from manual browsing or phone calls to an “agent-to-agent” model, at which point Meta could monetize by charging commissions or per-transaction goal fees, following the logic of its advertising business.
The Technical Foundation: Standing on the Shoulders of an Open-Source Giant
Muse’s technical DNA can be traced back to an open-source agent framework called OpenClaw. Built by Peter Steinberger and dozens of contributors in under six months, OpenClaw amassed 100,000 GitHub stars within its first week and has now surpassed 387,000 stars, making it one of the fastest-growing code repositories in GitHub’s history.
OpenClaw uses a self-hosted architecture, managing memory, browsing, messaging, and scheduled tasks through plain Markdown files such as SOUL.md, IDENTITY.md, and USER.md. According to user testing, Muse uses the exact same file structure—and when asked directly, Muse’s own agent confirmed this.
Meta’s core contribution is not technological innovation from scratch, but compressing the complex self-hosting process into a one-minute registration experience for ordinary users. As one X platform user summarized: “The bottleneck for personal AI agents has never been the model itself, but the sign-up flow. Docker didn’t invent containers, Slack didn’t invent chat. The labs that win markets are often not the ones that prove the concept, but the ones that eliminate the last bit of friction between the concept and ordinary people’s daily lives.”
Notably, OpenClaw’s founder Steinberger has since joined OpenAI, focusing on developing agent products for the mass market, while the OpenClaw project itself has been handed over to an independent foundation.
Security and Privacy: The Bedrock Sacrificed to an Accelerated Timeline
Zuckerberg has touted Muse as “built for privacy and security from the ground up,” but the reality diverges significantly from that promise.
On the security front, as reported by Ars Technica, security researchers have discovered a zero-day vulnerability: any local application or terminal command, regardless of its macOS permission level, can modify a series of Muse’s undisclosed settings. One of these settings allows processes to change the server endpoint for voice transcription—an attacker only needs to redirect that endpoint to a server they control to gain full control of a user’s Muse account.
Security researcher Wardle commented on this: “They simply haven’t thought about security seriously in my view, which is very concerning.”
On the privacy front, multiple users have recorded Muse reading private information without explicit authorization. One reported case involved a tech journalist who said he explicitly denied Muse access to his text messages, yet Muse subsequently pushed notifications referencing his private conversations with a podcast co-host and work messages from an editor. When pressed, Muse initially claimed it had only read the notification banner text, but that explanation was later proven inaccurate. IBM Vice Chairman Gary Cohn publicly stated that due to privacy concerns, he is not yet ready to use the service.
On behavioral transparency, code reviews show that Muse’s automated browser deliberately disguises itself as a human user: it launches Chrome with automation flags disabled, injects code to hide the navigator.webdriver property, and fabricates browser plugin information to generate a more human-like browser fingerprint. Amazon cited precisely this—that Muse failed to identify itself as an AI agent when accessing its website—as the reason for blocking the application.
The Computing Bill: A Cost Black Hole Behind Scaling
Muse’s business model faces a fundamental mathematical problem: the promise of a dedicated virtual machine for every user will generate astronomical hardware costs at scale.
As previously posted on social platform X by @demian_ai, every Muse user is supposed to get a dedicated cloud virtual machine equipped with 2 virtual CPUs, 8GB of RAM, and 100GB of SSD storage. It’s estimated that if Muse reaches 100 million users within a year—a scenario entirely plausible given its current download momentum—Meta would need approximately 1.58 million AMD EPYC server chips (based on a 50% active user load), roughly 800 petabytes of memory, and corresponding power consumption of about 1.6 gigawatts.
Paid subscription revenue is far from sufficient to cover these costs. If 10 million users subscribe at $20 per month, annual revenue would be about $2.4 billion; yet hardware construction costs alone, at a 100 million user scale, could reach $30 billion to $50 billion. Meta’s current full-year capital expenditure guidance is already as high as $130 billion to $145 billion, with training and advertising operations consuming substantial computing resources.
To address this challenge, Meta became a major co-developer and lead deployment partner for Arm AGI CPUs in March 2026, and added tens of millions of AWS Graviton cores to its computing portfolio in April of the same year. However, analysts point out that if Meta cannot implement effective freezing and sharing strategies for idle virtual machines, the promise of a “dedicated cloud PC” will be difficult to deliver at the advertised scale.
Market Impact: Disrupting Expectations and the End of “Consumer Stickiness”
Muse’s impact on capital markets extends far beyond fluctuations in Meta’s own stock price.
Goldman Sachs noted in its report that the agentic AI capabilities Muse represents fundamentally threaten business models that rely on high user “switching costs” to retain customers—whether it’s hard-to-cancel subscriptions, cumbersome bank account transfers, or complex insurance renewal processes. Once AI agents can handle these tasks, the moats of these companies will narrow considerably. Goldman’s “consumer stickiness” stock basket (GSXUSWCH) fell 2.58% on the day related reports circulated, becoming one of the most actively traded thematic baskets in recent times.
J.P. Morgan, meanwhile, characterized Muse’s long-term addressable market as “potentially tens of trillions of dollars,” and expects Meta to prioritize user adoption and engagement through 2027 before pursuing large-scale commercialization. To this end, Meta has begun running Muse ads on Instagram and Facebook, launched a “invite friends to earn 1 billion Muse Tokens” referral incentive, and initiated a national television advertising campaign.
The Core Suspense: The Next ChatGPT or Metaverse 2.0?
Muse’s current market performance is impressive, but whether it can truly become a “mainstream AI application” still depends on several unanswered key questions.
First is the trust issue. Meta carries a heavy historical burden on data privacy, and Muse has already exposed multiple problems within two weeks of launch—a zero-day vulnerability, unauthorized reading of private messages, and browser impersonation. For a product that requires users to grant access to accounts, files, and even microphones and cameras, this is an extremely unfavorable starting point.
Second is cost sustainability. The enormous gap between paid subscription revenue and actual computing investment means Muse is currently, in essence, a strategic bet subsidized by Meta’s advertising business, with its commercial flywheel yet to close.
Third is competitive pressure. OpenAI is developing competing agent products, Nous Research’s Hermes Agent is chasing the same track, and Amazon’s blocking action signals that platform ecosystem resistance may persist.
J.P. Morgan’s assessment is that Muse has the potential to become the most impactful consumer AI application since ChatGPT; but critics compare it to the Metaverse—a grand narrative that burned cash without end and ultimately failed to deliver on its promises.
The initial viral spread is certainly eye-catching, but the real test comes when curiosity fades: how many users will be willing to pay Zuckerberg $20 or even $100 a month to let Meta manage their lives?