Short answer

Meta Muse and Instinct are personal AI agents: they act for one person across that person's own email, calendar, browser, messages and payments. For a business the decision is about data, not features. Write a rule on connecting work accounts, keep client and financial data out, use them for public low-risk tasks, and use a work agent with admin controls for team work.

What is a personal AI agent, and how is it different from a work agent or a chatbot?

A personal agent is an AI agent that one person sets up on their own accounts, and it acts on their behalf across those accounts. A work agent is set up by a business, on business accounts, under an administrator. A chatbot answers questions and does not act.

The practical difference is who holds the keys. A personal agent answers to the individual who connected it. A work agent answers to the organization that pays for it, which can see usage, restrict connectors and switch features off.

ChatbotPersonal agent (Muse, Instinct)Work agent (Claude, ChatGPT workspace agents, Copilot Cowork)
Works forWhoever is typingOne personA team, under the business
Can touchWhat you paste inThe person's own email, calendar, browser, messages and payment methodsBusiness apps and files the admin allows
Who controls accessThe userThe user, app by appAn admin, then the user within those limits
Takes actionsNoYes: sends, books, buys, postsYes, inside approved tools
Business visibilityNoneNoneAdmin settings, usage and audit tools, depending on plan
Best forQuestions and draftsPersonal errands and the owner's own public postingClient work, shared files, repeatable team processes

On the work side, as of September 2026: Anthropic began merging Claude Cowork into the main Claude app on September 16, OpenAI offers workspace agents, in research preview, to ChatGPT Business and Enterprise teams, and Microsoft sells Copilot Cowork to Microsoft 365 Copilot customers. Claude vs ChatGPT for business compares the first two.

What is Meta Muse and how does it work?

Muse is Meta's personal agent, launched on September 8, 2026 and rolling out in the US. It is available in the Muse app on iOS and Android, on the web at muse.ai and inside WhatsApp, with Meta's AI glasses announced as coming.

  • How it runs. Each person gets a Muse Secure VM, a dedicated cloud computer with its own browser that holds both the agent and the person's data. Meta says a separate Sentinel agent runs on the same machine, kept apart from Muse, as a safety check.
  • What it connects to. Meta's help center names Gmail, Google Workspace, Apple Health and Android SMS among its connectors. Facebook, Instagram and Threads connect automatically when they sit in the same Meta Accounts Center. Where no connector exists, it can use its browser.
  • Payments and logins. Meta says Muse cannot see passwords or payment methods, which sit in a separate credential store. Purchases run through Link by Stripe at launch.
  • Approvals. By default Muse asks before sensitive actions such as sending an email or making a purchase. Each connector can be set to "Always ask" or "Ask for some actions", and many can be limited to reading only.
  • Data use. Meta says Muse conversations and VM data are not shared with its ad systems. Interactions can be used to train Meta's models unless the person turns that setting off.
  • Price. Meta calls it free for most use, with subscriptions for heavier use. TechCrunch reported paid plans at $20 and $100 a month at launch.

At its Connect event later in September, Meta also announced a Mac app that can operate desktop apps and a dedicated Muse email address, both described as coming rather than available.

What is Instinct, and why has it drawn scrutiny?

Instinct is a personal assistant from Spear Street Technology that you text or call. It asks for access to email, messaging, calendar, screen, audio and location, then handles follow-ups, bookings and errands. As of September 2026 it is in private beta.

It raised a $250 million Series B co-led by Index Ventures and Benchmark, announced August 26, 2026, at a reported $2.5 billion valuation. Two days earlier TechCrunch reported problems testers had described in public:

  • An email sent on a user's behalf without asking first.
  • An email summary arriving hours after the user had disconnected Google, and emails stored in plain text for search.
  • A demonstration that it could be manipulated by instructions planted in an email.
  • Terms of service granting a "perpetual and irrevocable" license to user materials and allowing it to enter "agreements, commitments, or transactions" on the user's behalf.

The company told The Wall Street Journal it takes the concerns seriously. For a business, the lesson applies to every agent in this category: read the terms and the permission list before anyone connects an account that holds other people's information.

What should a business owner decide about personal agents?

Decide three things and write them down: which accounts may be connected, which data may never go in, and what needs a person's approval. One page is enough. AI governance lite has the fuller template.

  1. Work accounts. The default for most small businesses: employees may not connect a work inbox, work calendar, shared drive or company card to a personal agent. The business cannot see, audit or revoke that access, and when the employee leaves, the agent's copy of the data leaves too.
  2. Data that never goes in. Client personal information, contracts and closing documents, financial accounts, passwords and codes, health information, and anything under an NDA. If a regulator or a client would ask where it went, it does not go to a consumer agent.
  3. Approval on anything outbound. Where a personal agent is allowed, set it to ask before sending, posting, paying or signing up. Turn off model training where the setting exists.
  4. Offboarding. Add a line to the exit checklist: disconnect any agent from business accounts, and change passwords the agent could have used.

Where is a personal agent genuinely useful for a small business or real estate agent?

It earns its place on the owner's own public-facing work, where the data is already public and a mistake is embarrassing rather than a breach. Social posting and local community groups are the clearest case.

One pattern we have worked through with a residential real estate agent: the content is drafted in Claude, where the agent already keeps listing notes and a consistent voice, and Muse handles the Meta side, publishing to the agent's own Facebook and Instagram and keeping up with the neighborhood Facebook groups where many homeowners in a farm area follow local news. Muse is built around Meta's apps, which connect to it through Accounts Center, so it is the natural hand for that half of the job. The same split suits a restaurant, a salon or a contractor with a local following.

Keep it within limits:

  • Only public content goes to Muse. Client names, addresses of people's homes and deal terms stay out.
  • Leave approval on for posts and messages until you have read a few weeks of output.
  • Read each group's rules. Repeated automated posts or messages read as spam and can get an account restricted.
  • Licensed professionals still own their advertising rules. A real estate post still needs whatever your brokerage and state require.

When is a work agent with admin controls the right tool instead?

Whenever the work involves other people's data, a shared process, or an account the business owns. That covers most of what a team does all day.

  • Client and deal work. Contracts, rent rolls, underwriting and client correspondence belong in a business plan where an admin controls connectors and data settings.
  • Shared processes. A work agent can be built once and used by the team. Claude Cowork works in approved files and folders, and ChatGPT workspace agents can be shared across a workspace.
  • Browsing with limits. Claude in Chrome became generally available on paid plans on August 26, 2026, and Enterprise admins can restrict it to approved domains. A personal agent has no equivalent a business can set.
  • Leaving staff. Removing a seat removes access. A personal agent stays with the person.
Working rule

If the account belongs to the business or the data belongs to a client, use a work agent the business administers. If the account is the owner's own and the content is already public, a personal agent is fine with approvals on.

Common questions

What is Meta Muse?

Muse is Meta's personal AI agent, launched in the US on September 8, 2026. It runs on a dedicated cloud computer with its own browser, connects to apps such as email, calendar and payments, and takes actions like sending email, booking travel and buying things. It is available in its own app, on the web and inside WhatsApp.

What is Instinct AI?

Instinct is a personal AI assistant from Spear Street Technology that people reach by text or phone call. It connects to email, messaging, calendar and a computer to handle tasks such as replies, travel and bookings. As of September 2026 it is in private beta, and testers have raised privacy and security concerns about its permissions and terms.

Can employees connect work email to a personal AI agent?

Only if the business has said yes in writing. A personal agent connected to a work inbox can read client and vendor mail and act on it, outside any admin control the business has. Most small businesses should forbid it for work accounts and offer an approved work agent instead.

Does Meta use Muse conversations for ads or training?

Meta says Muse does not share conversations or the data in a person's Muse computer with its ad systems. Its help center also says interactions can be used to improve Meta's AI models, that the setting is on by default and that it can be turned off in settings.

Is a personal agent useful for a real estate agent or small business?

Yes, for public-facing, low-risk work on the owner's own accounts, such as posting content the owner already wrote to their own social pages and local groups, or keeping a personal calendar in order. It is the wrong tool for client files, contracts, transaction data or anything a team shares.

Related reading