ZDNET’s key takeaways
- Muse rivals leading AI tools for chat and deep research.
- Amazon blocked the Muse shopping agent.
- Meta’s privacy record makes broad permissions hard to trust.
It took me a few days to start writing this article. After my editor asked me to see what the Meta Muse agent could do, I pictured being handed a vial of Ebola and being told by my boss, “See if you can find any good in this.” I’ve been trying to figure out how to evaluate this service without letting it out of the safest quarantine I could find.
Also: The best and worst AI for your privacy, ranked – and how each handles your data
That restriction meant there’s no way in heck I’m putting this tool on my iPhone. There’s no way I’m going to stick this on an Android device with any of my accounts. It meant that I didn’t even want to run the agent in the same Chrome profile as the rest of my work.
I do have a Meta account, which I used with my Meta Quest 3, so that was my starting point. It’s really challenging to test something that’s supposed to help with all your daily and personal tasks when you don’t want it to know anything about your personal life.
Just because you’re paranoid…
Okay, let’s back up. What is Muse and why am I so skittish about it?
Muse is Meta’s new agentic AI tool, targeted at consumers and non-technical users. Think of it as OpenClaw, but it’s easy to understand and offered by Facebook’s parent company.
Also: Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’
By every indication, Muse is a nice product. My early (and purposely limited experience) has been quite positive. It’s a nicely designed tool. But it’s from Meta, where Zuckerberg has his secret lair.
This app wants access to your contacts, calendar, email messages, and even offers to store your logins and passwords. That’s right, Meta is asking for your logins and passwords.
This is the company that deceived users about privacy, shared friends list data with third-party apps, and was fined $5 billion for its approach. This is the company that manipulated users’ emotions secretly, in an attempt to engineer emotional contagion. This is the company that hid internal research that Facebook and Instagram harmed teens, while also working on new teen-focused products. This is the company that exposed 533 million users’ data, refused to notify affected users, and was fined €265 million due to the negligence.
This is the company that lied about privacy controls and shared private data with advertisers, resulting in FTC penalties. This is the company that discriminated in housing ads algorithmically based on users’ race, religion, sex, disability, familial status, and national origin, and was penalized for it by the Justice Department.
Also: Nearly 70% of workers use AI regularly now – but many get no time to upskill
There are more concerns, but this article is supposed to be a review, not a catalog of Meta’s sins. The thing is, if you’re going to consider an AI agent tool that wants access to all your private data, you have to consider which company is asking for that information.
There’s a lot to like in Muse. It’s just a shame that most of its capabilities probably shouldn’t be used, because of Meta’s unabashed affiliation with the dark side.
Bot around the clock
Let’s discuss the early setup process in Muse. Once you either connect to its website or install and open its app, you get a screen like this.
Hey, we often don’t even share money details with good friends. I’m not sure I want to share something this personal with the Zuckerbot before I even get to know it.
Also: Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Muse then tells you it’s all about running 24/7, monitoring and interceding on your behalf, like a personal assistant. This is where I started to pick up real OpenClaw vibes, especially because Meta says Muse runs in a private VM where it can do browser work for you.

Then Muse asks for full disk access, and connections to Mail, Messages, Notes, and WhatsApp ( but not Facebook Messenger).
As it turns out, Muse won’t talk to your Facebook personal profile at all. Only a Facebook page. It’s happy to dive deep into your email and contacts, but not your Facebook graph. Hmm…

Notice that ChatGPT, Claude, and Gemini don’t have full disk access, but here Muse asked for the Full Monty before we’d even gone on our first date.
Also: 7 AI coding techniques I use to ship real, reliable products – fast
Muse also wanted to store my passwords. If you go to a site that requests a password, Muse asks you for it and offers to store the combo in its own secure store. While you can certainly avoid doing so, and Muse does have a partnership with 1Password, the fact it even asks for your passwords seems a step too far. I don’t want Facebook to store my passwords, even with assurances that their storage database is fully secure.

Then, Muse asks for mic access. Keep in mind that I haven’t initiated any microphone activity with it yet. I didn’t hit the microphone icon to dictate prompts to the tool. And look, I know there was no evidence supporting the conspiracy theories that Facebook listened into your conversations, but asking for mic access before using the microphone seemed oddly sinister.

When I skipped that request during the setup process, Muse came back a few minutes later and asked again for access. If you’re not familiar with this screen (below), it pops up when a program asks MacOS for hardware access. Muse didn’t make this request. Instead, Muse asked the computer for access, and MacOS responded, “Yeah, well, I better check with the human first.”

Why would Muse ask the OS for mic access after I had already skipped that option? That question makes one muse.
Also: What workers are really using AI for in 2026 – and what they aren’t
While we’re at it, be aware that it appears Meta will use your interactions for AI model training unless you specifically opt out. You can do this by opening Setup, going down to Data Controls, and then toggling off “Help us improve our models.”

Overall, the Muse setup left me feeling creeped out, and that was before my first real interaction with the AI agent.
Muse Spark
According to Muse, the model it’s using is Muse Spark. I asked if there was a version number or a date, and it answered, “Not really.”
That being said, the chat experience is quite good. I engaged the AI in several interactions, and I found it helpful, lucid, and not overly annoying. Answers were complete, research was solid, and, on the whole, I found it (at least so far) to be every bit as good as the chat models from OpenAI, Google, and Anthropic.
The only real problem I had with the Muse app was that it seemed to log me out every couple of hours. I’m not sure if that’s intentional or just a launch-week bug, but it is annoying.
Then, there’s another issue.
Also: Could AI really destroy us all, or are humans still the bigger threat?
For some reason that escapes me, many of the AI companies are introducing little Clippy-like mascots that go along with their AI agents. OpenAI Codex has a little robot, Notion has a sketch of a face, and now Muse has a fabric plushy version of the Stay Puft Marshmallow Man from Ghostbusters (or at least that’s how I interpreted it).
Apparently, you can customize your avatar to your heart’s content. Because who doesn’t want another waste-of-time to-do list item?

In any case, the Verge wrote a whole piece about the lure of cute AI avatars. Perhaps it’s because my little dog provides us with a constant cuteness overload, but I’m completely unmoved by cartoon characters fronting for evil Skynet AIs.
Agentic performance
Meta seems to be promoting Muse as a personal helper, with a big focus on shopping. I immediately tried my agentic search prompt for vertical mice that I used to jump-start my vertical mouse research project.

That step did not go well. According to Gizmodo, Amazon has blocked Muse’s access. The article reported that Amazon didn’t agree to give the AI agent access.
Related to the privacy concerns I mentioned, Gizmodo stated: “The company also raised concerns about how Muse handles customer credentials and account data. Because Muse does not identify itself, Amazon says it is essentially an undisclosed third party accessing customer accounts without Amazon’s knowledge or authorization.”
I did have somewhat better results asking Muse to do some sentiment analysis on the first day after Claude’s Opus 5.5 was released. This was my prompt — I wanted to know, “Subjective reports about what people think of it. I don’t want benchmark results or marketing analysis or anything else. I want Twitter feed data, Facebook posts, blog posts, anything like that that says what their performance observations are for Opus 5.5 today. Write it up, summarize it, make it easy for me to digest.”
Also: Why replacing staff with AI backfires – and 5 ways smart leaders generate real value instead
The first response took about 20 seconds and was very light on information. I pushed back, telling the AI, “That was pretty quick. It doesn’t feel like you took the time to do any real research. Go back and take some serious time and really look into this. Don’t just grab the first two or three things you find.”
This time, Muse took a few minutes and gave me back a fairly comprehensive report from X, Threads, and Reddit. I found the response quite helpful.
I gave it one more agentic research assignment. My thinking was that, while I’m not willing to give Muse access to my private information, sending it out on the web to pull information together should be a fairly safe operation.
So, my final assignment was an assessment of the state of frontier models. I gave it a prompt, and it informed me that “research teams” were hard at work.

The results were interesting. Muse returned a fairly dense 12-page report that was mostly accurate. It did confuse Opus 5.5 and Fable 5.1, thinking that Fable was the less capable of the models. But it did point out something quite valid, and I was impressed with how it pinpointed this issue with benchmarks (see below) and raised it as a caution.

As a comparison test, I ran the same query with ChatGPT, Claude, and Gemini, and each got a few facts wrong. Muse was no worse than any of them, and its presentation was just as strong.
The Facebook paradox
Back in 2024, Meta surprised me with the quality and value of its Meta Quest 3 VR headset. The device was a solid, high-value, high-quality piece of engineering. Reconciling the excellent engineering with the idea that this product was from Facebook, of all places, was a bit of a cognitive challenge.
Since then, it’s become clear that Meta can make solid products. Muse is no different. I like it. The AI is competent, not too obsequious, fairly accurate, and generally helpful.
For projects that are air-gapped from my personal information, I will definitely use it again and add it to my AI toolkit. But even though Muse might be a great general AI assistant, I don’t trust Meta. The company has consistently demonstrated a lack of an ethical and moral center when it comes to user data.
That’s a shame, because Muse is pretty nice.
Have you tried Muse yet? If so, please share your impressions in the comments below.
You can follow my day-to-day project updates on social media. Be sure to subscribe to my weekly update newsletter, and follow me on Twitter/X at @DavidGewirtz, on Facebook at Facebook.com/DavidGewirtz, on Instagram at Instagram.com/DavidGewirtz, on Bluesky at @DavidGewirtz.com, and on YouTube at YouTube.com/DavidGewirtzTV.
