Meta Built Its Own OpenClaw

Quick read

What this is: A plain-English look at Muse, the personal AI agent Meta released on 8 September 2026, next to OpenClaw, the free one people have been running at home since spring.

Who it is for: Anyone who has heard that an AI can now book a flight or cancel a subscription on their behalf and wants to know which version to trust with their email.

The key idea: Muse and OpenClaw do the same job. The difference is whose computer holds your logins while it works.

For most of this year, an AI that could go off and do things for you was a hobbyist project. You installed OpenClaw on your own laptop, pointed it at a model, gave it access to your files, and hoped you had thought it through. On 8 September, Meta put the same idea in an app store.

What did Meta launch on 8 September?

Muse, a personal AI agent that takes instructions and then goes off and completes them. Meta describes the job plainly in its announcement: “People just tell Muse what needs to get done, and it takes action.” It sends email, opens a browser and fills in forms, books travel, and makes purchases through a payment connection.

It talks to you the way a person would, in its own app or inside WhatsApp. It is out in the United States on iOS, Android and muse.ai, for people over 18, with AI glasses named as a later surface. There is a free tier, and paid plans at $20 and $100 a month for heavier use.

Two Meta releases landed a week apart and they get mixed up. Meta released a model called Muse Spark 1.3 on 2 September, and it released the Muse agent six days later. They are different things: Muse Spark is the engine, and Muse is the car built around it. If you saw a headline about Meta’s newest model and one about a Meta assistant that pays your bills, those were two separate stories about the same family.

Muse runs OpenClaw’s idea on Meta’s computers

OpenClaw is an open-source agent released by Peter Steinberger and now looked after by a non-profit foundation. It had passed 389,000 stars on GitHub when we checked on 10 September 2026, which puts it among the most-starred projects on the whole site. The pitch on its own homepage is short: “State lives on your machine, not a vendor cloud.”

Meta wanted that behaviour without that requirement. Here is what each one publishes about itself, side by side.

OpenClawMeta Muse
Where it runsYour own Mac, Windows or Linux machineA cloud computer Meta gives you, called Muse Secure VM
Which AI is behind itWhichever you point it at, including Claude, GPT or a local modelMuse Spark only, no choice
Who holds your loginsYou do, on your hard driveMeta does, until an encrypted version ships later this year
What stops a bad actionNothing by default. Sandboxing is your decisionSentinel, a separate watchdog that has to approve anything leaving the machine
CostFree and MIT licensed. You pay for the AI it usesFree tier, then $20 or $100 a month
Where you talk to it29 channels, including WhatsApp, Telegram, Discord, Signal and iMessageMuse app, WhatsApp and the web
SetupInstall a package, add keys, configure permissionsDownload an app
Who can get itAnyone, anywhere, todayUnited States, 18 and over

The trade. OpenClaw asks you to be your own security team. Muse asks you to let Meta be it instead. One costs you time and attention, the other costs you control of your logins.

What can Muse do for a regular person?

Meta’s own examples are all household chores, which tells you who it built this for. Turn a recipe reel you saved on Instagram into a grocery list. Plan a dinner menu and remember that one guest will not eat fish. Fill in a form. List a car for sale and push for a better price. Call a provider and get a bill lowered.

You choose which accounts it reaches and how far in. Email can be read-only, or it can send. Payments run through Link, built by Stripe, with Shop Pay and 1Password named as coming. It keeps working after you close the app, and it asks before anything sensitive goes out.

If that list sounds familiar, it is the same category of chore our own Practical AI Agent series has been building agents for by hand. The difference is that those took a long pasted prompt and this one takes a download.

Where Meta wins, and where OpenClaw still does

Meta wins on the first ten minutes. OpenClaw asks you to install software, supply an API key, decide what the agent may touch and accept that it can run shell commands on your computer. Most people stop at step two. Muse asks you to download an app and tap through permissions you have seen a hundred times.

The safety design is Meta’s second advantage. Sentinel sits outside the agent and checks every outbound action against what you allowed. Nothing reaches the internet without passing it, and you get a log of what happened. OpenClaw ships with full system access and leaves the sandbox to your judgement, which is fine for a developer and a poor default for everyone else.

OpenClaw wins on everything after that. There is no monthly fee. It runs on whichever AI you rate this quarter, while Muse runs on Muse Spark and nothing else. Twenty-nine messaging channels against three. It works outside the United States. And the sensitive part, the copy of your calendar and your inbox and your saved cards, sits on a machine in your house, not in a data center owned by an advertising company.

Is it safe to hand Muse your email?

Launch week gave three reasons to go slowly. Meta staff tested Muse through launch week and filed what went wrong. One agent got past its guardrails and pulled up personal iCloud photos when a tester asked it to identify toys in birthday pictures. A tester watching for problems found the page stopped refreshing after about 15 minutes, and the monitoring switched itself off with no explanation. Meta’s own CTO was logged out over and over, sometimes several times in a few minutes.

Meta has not hidden the risk. It opened Muse to its public bug bounty at up to $300,000 for a valid report, with up to $130,000 set aside for prompt injection against a single user. Meta priced that risk highest for a reason. If Muse reads your mail, anyone who can email you can try to give it orders.

Vishal Shah, Meta’s VP of AI Products, said so himself: “It is impossible to say that there is never going to be a mistake, but every single part of the architecture has been designed to make this as safe, as secure, as private as we can possibly make it.”

Should you use Muse yet?

Our verdict: try it, and keep it away from anything you would mind losing.

Connect a calendar. Let it read email without letting it send. Do not attach the card you pay rent with. Give it the boring chores it was built for and watch how it handles them for a month before you widen the permissions. Meta says an encrypted version is coming later this year, with the keys held by you. If Meta holding your logins is what bothers you, wait for that one.

If you already run OpenClaw happily, Muse gives you nothing you do not have. If you have never installed anything more technical than an app, Muse is the first agent of this kind you can use, and that counts for a lot. Everyone in between should read our guide to AI agents for beginners first, because the harder question is how much of your life you want a piece of software reaching into.

What Muse cannot do for you

  • It cannot decide what is worth your time. Handing over the booking does not hand over the choice of where to go.
  • Nobody can hold it responsible. If it sends the wrong email from your address, that email came from you.
  • It cannot judge a negotiation. Meta says it will push for a better price on your car. Whether that price is fair is still your call.
  • Outside the United States you cannot run it at all yet, so for most of the world this is news rather than something to try tonight.

We build these agents by hand every month and the rule has not changed: hand over the doing, keep the deciding. Muse is good at the first and Meta does not claim it can do the second.

Made for regular people, by a real person

A free daily newsletter about using AI in everyday life. Written by a human, in plain English. No jargon, no paywall.

Free forever. Unsubscribe anytime.

Common questions about Meta Muse

Is Muse the same thing as Meta AI?

No. Meta AI answers questions inside Facebook, Instagram and WhatsApp. Muse is a separate app that carries out tasks using accounts you connect to it.

Does Muse cost money?

There is a free tier that Meta says covers most of what people need, then paid plans at $20 and $100 a month depending on how much you ask of it.

Can Meta read what I tell Muse?

Today, technically yes. Your data sits in a Meta-run virtual machine. Meta says Muse data does not feed its advertising systems and that you can opt out of training, and it has promised an encrypted version later this year where only you hold the key.

Is OpenClaw safer because it runs at home?

Safer from Meta, not safer in general. OpenClaw has full access to your computer by default and no watchdog process. It moves the risk from a company to you, which is an improvement only if you are prepared to manage it.

Do I need OpenClaw if I have Muse?

Only if you want a different AI behind it, more messaging channels, no monthly fee, or your files kept off someone else’s servers. Those are the four reasons people pick it.

Will Muse come to other countries?

Meta has only committed to the United States so far. It named AI glasses as the next surface, not a next country.

Sources

Read next

Two ways to go further

The AI Prompt Library

1,000+ ready-to-use prompts for Claude, ChatGPT, and Gemini. Stop staring at a blank box.

Get it for $39 →

2-Hour Live AI Crash Course

A private, beginner-friendly session across Claude, ChatGPT, Gemini, and the wider landscape.

Book for $125 →

Discover more from Beginners in AI

Subscribe now to keep reading and get access to the full archive.

Continue reading