
Meta has widened what its Muse AI agent can do on the Mac. It has moved from reading and organising files in native apps to operating any application on the machine, and continuing assigned work after the user has stopped watching. Chief AI officer Alexandr Wang described the change at Meta Connect as letting people “walk away from your computer” while Muse “keeps working for you on all the jobs you lined up.”
The expansion lands ten days after Muse’s first Mac release, in a market where consumer AI agents are competing on how much of a user’s digital environment they can act inside, not just answer questions about. An agent with standing permission to read mail, fill forms and operate software is a new kind of intermediary between a brand and the person it is trying to reach — one that did not exist in this form a month ago.
Muse’s Mac app launched on 17 September, giving the agent access to files, mail, calendar, notes and messages inside their native applications, according to Meta’s own description of the release and contemporaneous reporting from The Verge and TechCrunch. Meta said the app would always ask for approval before sensitive actions, and early coverage noted examples such as filling out forms.
The Meta Connect update, announced a week later, goes further: with permission, Muse can now control any application on the Mac and keep working through a queue of tasks while the user steps away. Wang framed the practical use case around small-business owners handing over administrative work, rather than enterprise deployment. Meta has not published a granular list of which applications or actions fall inside this expanded control, and the sources reviewed do not establish a wider rollout beyond the initial US launch.
Meta’s account of Muse’s guardrails centres on a permission model that the user sets, not one built into every action by default. According to Meta’s launch material, people choose which apps Muse can reach and how much access to grant, can read but not send mail unless they allow it, and can revoke access at any time. Meta says Muse checks with the user before sending an email or making a purchase, and keeps an audit trail of what it has done and plans to do next.
Meta also says conversations and data inside Muse’s dedicated virtual machine are kept separate from its advertising systems, that users can opt out of having their interactions used to train its AI models, and that a separate “Sentinel” agent must approve any action that reaches the internet. These are Meta’s own descriptions of its system, not the findings of an independent audit, and the company has not detailed every action it classes as sensitive or its data-retention practices beyond the ad-system separation. Reuters reported that the original launch came amid broader concern about how agentic systems handle access to sensitive personal data.
Muse’s download numbers, drawn from Sensor Tower estimates reported by CNBC, put the app at roughly 730,000 downloads in its first five days and past 2.5 million by 21 September, split by Sensor Tower’s estimate as roughly 1.5 million on iOS and 1.1 million on Android. CNBC reported Muse topped the US iOS free-app chart on 18 September; TechCrunch later reported it led Google Play downloads on 19 September. In the same 13-day comparison CNBC cited, ChatGPT recorded an estimated 3.1 million downloads to Muse’s 2.5 million, while Muse ran ahead of Claude and Grok. These are third-party estimates of mobile installs, not Meta-reported active users or Mac downloads, and they say nothing about how many people keep using the app.
Other companies are building comparable capability without matching Muse’s packaging as a single personal agent. Google offers a Mac app for Gemini and separate computer-use tools that let developers build agents to act across browser, mobile and desktop environments. Anthropic’s Claude has documented computer-use capability that can open applications and control the screen, though it is switched off by default and must be enabled. Neither Microsoft Copilot nor Apple Intelligence currently has a verified, directly comparable Mac agent with Muse’s described scope of native-app access.
Muse’s standing access to files, mail and calendar on a work machine raises questions that go beyond the individual user who installed it. Enterprises weighing Muse, or any comparable desktop agent, need to decide which permissions are acceptable and whether they can be centrally restricted, since outbound actions such as sending messages or submitting forms can carry real business consequences once an agent is doing the clicking. Meta’s claims about keeping Muse’s data separate from its advertising systems and letting users opt out of AI training do not, on their own, answer questions about data retention, processing location or how the tool fits existing confidentiality and records-management obligations. macOS device-management policy and software-approval processes are also untested against a tool built to operate other applications rather than sit inside one.
Meta has not published data on how many Mac downloads or active users Muse has, nor evidence of how agentic assistants are already affecting email engagement, product discovery or buying behaviour in a B2B context. Its next scheduled update to the Mac agent’s permitted scope has not been announced.