Muse will be able to act on what its wearer sees
The most visible Connect announcement is the move into Meta's AI glasses. Muse is scheduled to reach the glasses in the coming months with an integration that goes beyond forwarding a spoken question to a phone.
Users will be able to invoke their agent and ask it to act on something in view. Meta's examples include a product on a shelf, a flyer on a wall or a long school-supply list.
That is where the distinction between assistant and agent becomes practical. Identifying an object through a camera is already common. Identifying it, adding it to a larger task, finding a way to buy or organize it and continuing after the user looks away is a different workload.
Voice mode is supposed to keep working while the conversation continues
Meta is also adding a voice mode designed for extended conversations. Muse can continue doing background work while the user is still speaking with it.
The underlying product is built around persistent tasks rather than one prompt at a time. Web navigation, forms, research, reservations and longer-running goals can continue after the Muse app is closed.
Muse Spark powers the agent, while each user receives a persistent Muse Secure VM in the cloud with its own browser, storage and execution environment.
Meta is opening many more doors to the agent
Connect also substantially expands Muse's connector ecosystem. Meta says it launched with dozens of partners and access to the Shopify catalog.
The new shopping list includes Walmart, Best Buy, American Eagle Outfitters, DICK'S Sporting Goods, Fanatics, Gap, Michael Kors, Sephora, Ulta and Wayfair. Shop Pay and PayPal are being added for payments.
Expedia is coming for travel and Instacart for grocery shopping. Notion, Granola, GitHub and Box are among the work-oriented integrations Meta announced.
Not every one of those services should be treated as universally available today. Several are explicitly described as upcoming integrations.
Muse is even getting its own email address, giving the agent another way to receive information or communicate as it works through a task.
The security design assumes the agent will eventually make a mistake
Meta has published unusually detailed documentation on Muse's security architecture. Its most useful premise is not that the model is infallible, but the opposite: an agent will sometimes make mistakes or encounter hostile instructions in the data it reads.
Muse therefore operates inside an isolated execution environment. Credentials are stored separately, and the core agent is not supposed to see passwords or authentication tokens directly.
A separate system called Sentinel controls external actions. Depending on the operation and the user's settings, Muse can be forced to request approval before sending data, communicating with another service or completing a purchase.
Meta also says Muse conversations and VM data are not shared with its advertising systems.
Private does not yet mean technically inaccessible to Meta
Meta's own engineering documentation includes an important qualification. The current Muse architecture restricts employee access through operational policies, but it does not cryptographically prevent Meta from accessing VM data when necessary to operate, support or secure the service.
A stronger system called Muse Confidential VM is planned for later this year. Meta says the design is intended to make the user's VM inaccessible even to Meta through cryptographic enforcement.
That version is currently being tested with a small group of trusted users and is being opened to external auditing before wider release.
Users can also opt out of having their Muse interactions used to train future Meta models. That is separate from advertising: Meta says the conversations do not flow into its ad systems, while sanitized agent trajectories may be used for model training unless the user opts out.
Then there is the human on the phone
A Reuters report published shortly before Connect revealed a much less automated experiment inside Meta. The company has been testing a “human concierge” system in which contractors can handle some of the phone calls initiated through Muse.
This is not described as a public Muse feature currently available to ordinary users. Reuters reported that Meta has been testing it internally with employees while gathering feedback before any potential release.
According to internal posts reviewed by Reuters, some employees raised privacy concerns because information that a user expects to share with an AI system could instead be heard by a contractor working in a call center.
Meta says the experiment is being used to develop the required safety, privacy and disclosure mechanisms. Spokesperson Daniel Roberts told Reuters that the feature would only be released when ready and with appropriate disclosures.
The concierge experiment reveals the hard part of agentic AI
An agent can call a structured API with predictable fields. Calling an actual business is messier: automated phone menus, accents, background noise, interruptions, unexpected questions and social conventions all enter the task.
Experimenting with humans therefore does not automatically mean Muse has failed. It shows where digital workflows stop behaving like software.
The privacy problem is different, though. A model filling out a form creates the risk of an incorrect automated action. A contractor hearing or conducting a conversation that a user thought was AI-only raises the additional question of who has access to the information.
For a product being marketed as deeply personal, that boundary has to be explicit.
Muse is already expanding beyond its original US launch
When Meta introduced Muse on September 8, it said the agent was rolling out in the United States through iOS, Android, muse.ai and WhatsApp.
By Connect, Meta said Muse was available in the United States, Canada and Mexico, with more markets to come.
The iPhone app makes the intended scope unusually broad: email, reservations, calendars, spending, fitness, nutrition, shopping, travel and long-term personal goals are all presented as potential agent workloads.
Muse has a free tier with usage limits, with paid subscriptions available for users who need more capacity.
Meta is even building a dedicated Muse device
Connect also introduced Muse Charm, a pocket-size device specifically designed for talking to the agent through a real-time voice model.
Meta has not announced a price, detailed specification sheet or firm release date. The company says it will share more later this year.
Still, it is revealing that a software agent is already being given dedicated hardware only weeks after launch.
The product Meta is really selling is delegation
Muse is not primarily an attempt to build a better text box for asking questions. Meta wants enough access — browser, email, calendars, payments, shopping, work apps and soon cameras worn on the user's face — that one request can trigger a chain of real actions.
That also makes Muse harder to secure than a conventional chatbot. A wrong answer can be annoying. A wrong purchase, an email sent to the wrong person or personal information shared with the wrong party produces an external consequence.
Connect 2026 shows that Meta is moving aggressively anyway. Muse is gaining eyes through glasses, more services, persistent voice interaction, an email identity and potentially its own pocket device.
The human-concierge experiment is a useful reminder that between “the agent understood the request” and “the job is actually done,” a large part of the world still refuses to behave like an API.