Meta has moved the AI-agent liability question from crypto accounts and trading subaccounts into ordinary consumer payments.
The company announced Muse on September 8 and is rolling it out in the United States on iOS, Android, the web and WhatsApp for users aged 18 and older. Support for Meta’s AI glasses is due later. Muse has a free tier alongside subscriptions priced at $20 and $100 a month for heavier use.
What separates Muse from another AI subscription is what Meta is allowing the agent to do. It can connect to email and other services, book travel, fill out forms, negotiate on a user’s behalf and make purchases. For longer tasks, it can continue working after the user closes the app.
Meta Has Put a Card Behind the Agent
That makes Muse a payments product as much as an AI launch.
Meta says Muse can check out using Stripe’s Link wallet. The agent itself does not see the user’s card details. For purchases where payment credentials need to be supplied, Link generates a single-use card tied to a particular merchant, dollar amount and limited period. Meta says every payment requires human approval before it goes through.
The same control applies when a website already has the user’s payment credentials on file. Meta says Muse detects that it has reached checkout and shows the exact transaction details for approval.
That arrangement reduces one obvious risk: giving an autonomous model an unrestricted reusable card number.
It does not remove the harder liability question. By the time a user approves the payment, Muse may already have selected a merchant, negotiated terms, filled out forms and interpreted what the user wanted. A dispute caused by an agent making the wrong decision earlier in that chain is different from a conventional unauthorized-card transaction.
Stripe Link provides purchase protections for eligible Muse transactions, including protections involving damaged or lost goods, price drops and returns. But those protections do not by themselves answer who ultimately bears the cost when the problem is not the payment execution, but the agent’s decision that led to it.
Muse Runs Inside Its Own Cloud Computer
Meta has built a dedicated architecture around those risks.
Each Muse runs inside what Meta calls Muse Secure VM, a dedicated virtual machine in Meta’s cloud containing the agent and the user’s connected data. The agent is powered by Muse Spark, Meta’s model built for agentic work.
A separate Sentinel agent evaluates actions and internet access. Users decide which services Muse can connect to and what permissions it receives, including whether it can only read email or also send messages. Meta says users can revoke those permissions, and Muse asks for confirmation before sensitive actions such as sending an email or making a purchase.
The architecture matters because financial firms are arriving at the same problem from another direction.
FinanceFeeds reported on September 1 that MoonPay’s PayBox reaches Grok through a custom connector that users must add and authorize before the assistant can prepare supported crypto and payment actions. MoonPay Brings PayBox to Grok Through a Custom Connector
Two days later, Binance’s Agent OS extended the model to trading by allowing AI agents to operate through dedicated subaccounts with controlled permissions rather than giving them unrestricted access to a user’s main account. Binance Agent OS Lets AI Trade Through Dedicated Subaccounts
Muse brings the same question to a much larger consumer surface.
The agent can now sit between a person’s inbox, browser, travel plans and payment card. Meta has put explicit approvals and single-use payment credentials around the final transaction. The more difficult question begins one step earlier: who owns the mistake when the human approves a payment but the AI made most of the decisions that produced it?




