Meta's AI assistant, Muse, is now available as a Mac app. Until this week, Muse lived on your phone or in a browser tab and mostly answered questions or drafted text. On the Mac, it can go further: open your Mail, Messages, Calendar, Notes, and files, and take action inside them, like sorting a folder, pulling details out of an email, or filling in a form using a document you already have saved.
That is the real shift here. Muse is not a smarter chatbot. It is software that does the clicking and typing for you, inside apps you already use, once you give it permission. Meta says it will always ask before doing anything sensitive, such as sending a message or making a purchase, and that users choose which apps and accounts it can touch.
Muse launched two weeks ago on phones and the web and quickly climbed to the top of app store charts in the US. Bringing it to the Mac is Meta trying to turn a popular download into a daily habit, the kind of app people open before every other app.
It is not competing in a quiet corner of the market. A rival called Instinct, which handles tasks through text messages, is reportedly close to raising money at a value near $10 billion, roughly four times what it was worth a month earlier. Another texting assistant, Poke, was bought outright by the AI company Cognition in July after racking up heavy use in just a few months. Meta, Instinct, and others all shipped voice calling features within days of each other. Nobody wants to be second.
Here is the part worth sitting with: every one of these products asks you to hand over your email, your calendar, your files, and sometimes your payment details, to software that then acts on its own. That is a much bigger ask than typing a question into a chat box. Trust, not raw intelligence, is the actual product being sold, and Meta is not starting from a position of trust. The company recently agreed to a settlement of nearly 17 billion dollars over claims it misrepresented harm on its other apps, and it is asking the same users to now hand it their inbox.
There is also a real safety gap nobody has closed yet. When an AI reads your documents and emails and then acts on what it finds, a hidden instruction buried in a file or message can trick it into doing something you never asked for. This is already a known weakness in similar tools from other companies, and none of them have fully fixed it.
For business owners, none of this needs an urgent decision today. But if staff start connecting personal AI agents to work email or files on a company laptop, that is a data policy question, and most companies do not have an answer yet. Worth writing one before an employee does it first.