Meta puts its agent on the Mac: Muse desktop app launches with approval gates on deleting files and sending messages

2026-09-20·8 min read

On September 17, 2026, Meta released the Mac version of Muse. It is the first version of Muse that can actually act on a user's computer, working inside native apps across files, mail, messages, calendar and notes rather than waiting for the user to paste content into a chat box. The product itself is not new: Muse launched in the US on September 8 across iOS, Android, the web and WhatsApp. What is new is the desktop layer, and desktop means permissions. The most interesting part of the product description is not what it can do but where it has to stop.

Start with what it is allowed to do. Meta's chief AI officer Alexandr Wang and Mark Zuckerberg both announced the launch on September 17, with Zuckerberg saying on X that Muse for Mac was out that day, that it works across apps, files, calendar, notes and messages on your computer, that you control what it can access, and that the team is shipping fast. The concrete abilities cluster around everyday tasks that span several apps: organising folders, finishing a form using information already stored in files, and building an end-of-day summary out of emails, messages and notes. The real shift is in how context is gathered. A normal chatbot needs you to move material into the prompt; Muse can potentially collate information scattered across applications itself, so one task might touch a calendar event, a mail thread, a document in a folder and a message conversation. It also runs asynchronously: Meta says the agent keeps working in the background even when the desktop window is closed, so you can start something on your phone, check in from a laptop, or nudge it through WhatsApp, with the same task thread carried across devices.

The permission design is the most concrete part of the description. Access to your computer is opt-in and Full Disk Access is optional; you decide what permissions Muse gets and can change them at any time in Settings. More important is the gate on destructive or outbound actions: Meta says sensitive actions such as deleting files or sending messages require approval. Concretely, Muse can sort a folder freely but has to stop before deleting anything, and it can draft a summary but has to ask before sending it. That boundary answers a practical question. Once an agent has its hands inside the local file system, the way things go wrong is usually not that it reasoned incorrectly but that it quietly did something irreversible, and picking out deletion and sending as the two actions that need a lock addresses exactly that class of action.

The stack behind the capability was disclosed as well. Muse is powered by Muse Spark, which Meta's launch post describes as its most capable model to date, built for real-world agentic work; the same model powers Muse Code, a coding agent for macOS and Windows. On the cloud side it runs on what Meta calls a Muse Secure VM: Muse runs on its own dedicated computer in the cloud, contained so that no other user's agent can reach it. A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level, and its job is to watch the network egress, so nothing Muse does reaches the internet unless Sentinel approves it. The design turns every outbound connection into an action a second party has to clear, instead of leaving the primary agent to decide for itself whether it may go online.

There is one qualifier that has to be read carefully, and Meta wrote it into the description itself: Secure VM isolates your data from other users, but it does not prevent Meta from accessing your data when necessary to operate the service. The company plans a Muse Confidential VM later in 2026, which will encrypt the entire virtual machine with a key only the user holds, and it runs a public bug bounty for Muse. Those statements belong together: in the current version the privacy boundary keeps other users out, not the service provider, and the genuinely end-to-end encrypted version is still to come. Two product facts are also worth noting. Muse for Mac is currently available only in the US, as a free download, and it is a hosted consumer agent rather than an open model you can self-host. On adoption, Muse climbed the US App Store quickly after its September 8 launch: according to Sensor Tower data cited by TechCrunch, it moved from No. 4 to No. 2 on Apple's US free-apps chart by September 10 on more than 83,000 iOS downloads, and Wang said on September 18 that Muse had become the number one app in the App Store.

🤔 Frequently Asked Questions

What can Muse for Mac do?

It works inside native apps across files, mail, messages, calendar and notes. Meta's examples include organising folders, finishing a form using information already stored in files, and building an end-of-day summary from emails, messages and notes. It runs asynchronously, continuing in the background after the desktop window is closed, with the task thread carried across phone, laptop and WhatsApp.

How are permissions controlled?

Access to your computer is opt-in, Full Disk Access is optional, and permissions can be changed any time in Settings. Sensitive actions such as deleting files or sending messages require approval first: it can sort a folder freely but must stop before deleting anything, and it can draft a summary but must ask before sending it.

What model does Muse use, and where does it run?

It is powered by Muse Spark, which Meta describes as its most capable model to date; the same model powers Muse Code, a coding agent for macOS and Windows. It runs in the cloud on a dedicated Muse Secure VM, contained from other users. A separate Sentinel agent on the same machine is kept apart from Muse at the system level and watches network egress, so Muse cannot reach the internet without Sentinel's approval.

Can I download it now, and how private is it?

It is currently available only in the US as a free download, and it is a hosted consumer agent rather than an open model you can self-host. On privacy, Meta states plainly that Secure VM isolates a user's data from other users but does not prevent Meta from accessing it when necessary to operate the service; a Muse Confidential VM that encrypts the whole machine with a key only the user holds is planned for later in 2026, and there is a public bug bounty.

🛠️ Recommended Tools

  • AI Meeting SummarizerOne of the scenarios demonstrated for Muse is turning emails, messages and notes into an end-of-day summary. Doing the same thing yourself is not hard: drop the scattered records in, get structured points out, then check them against the original, which is faster than waiting on an agent that is not yet available outside the US.
  • Markdown EditorWorking across apps creates a new problem: records of the same matter end up split between mail, messages and documents, each holding a different version. Keeping key decisions and dates in one plain-text place means the source of record stays in your hands whatever agent you use.
  • Text SummarizerWhether a privacy boundary is acceptable depends on what is being processed. Compressing long emails and documents into key points first lets you decide which material never needed to leave your machine and which genuinely did, and that makes the permissions conversation much clearer.

Summary

On September 17, 2026, Meta released the Mac version of Muse, the first version of the agent that acts directly on a user's computer; Muse had launched in the US on September 8 across iOS, Android, the web and WhatsApp. The desktop version works inside native apps across files, mail, messages, calendar and notes, handling folder organisation, form completion from existing files, and end-of-day summaries built from emails, messages and notes. It runs asynchronously, continuing in the background after the window is closed, with the thread carried across devices. On permissions, computer access is opt-in, Full Disk Access is optional, and sensitive actions such as deleting files or sending messages require prior approval. It is powered by the Muse Spark model, which also powers the Muse Code coding agent for macOS and Windows, and runs in the cloud on a dedicated Muse Secure VM watched by a separate Sentinel agent kept apart from it at the system level. Meta states plainly that Secure VM isolates other users rather than the provider, and that it may still access data when necessary to operate the service; a Muse Confidential VM encrypting the whole machine with a user-held key is planned for later in 2026, alongside a public bug bounty. It is currently a free, US-only hosted consumer agent rather than a self-hostable open model. Every fact here comes from descriptions of Meta's launch post and from MarkTechPost, 9to5Mac, Unite.AI, Business Insider, and TechCrunch citing Sensor Tower, with no speculation added.

Sources: MarkTechPost: Meta Launches Muse for Mac - A Personal AI Agent That Works Across Your Files, Mail, Messages, Calendar and Notes
9to5Mac: Meta AI launches Muse personal agent, including apps for iPhone and Mac
Unite.AI: Meta Launches Muse Mac App With File, Messages, and Calendar Access
Business Insider: Meta's Personal AI Agent Muse Soars to Top of App Store