Meta Muse Agent and Instinct AI Agent: Build Your Own AI Agent Privately
Muse and Instinct made personal agents the September fight. What each is, the privacy questions, and a private build.
Own the full flow: connect your sources, model your knowledge, and serve it to your agents in a controlled way with Swfte Cortex. See how it works.
Picture the finance lead at a mid-sized company. She is a composite, not a client. She has read that Meta's Muse agent will run errands for you from WhatsApp, and that a startup called Instinct, which you text or call, has just raised $1 billion. She wants exactly what they promise: something that reads the inbox, watches the calendar, chases the supplier and drafts the board pack from the shared drive.
She cannot give any of it to a consumer app. The inbox holds contracts and pay discussions. The drive holds numbers that are not public yet. Her security team has a rule, and she agrees with it: company data does not go into a product whose terms she cannot negotiate.
September 2026 turned the personal AI agent into the main consumer battleground. Meta launched Muse on 8 September. On 23 September it announced Muse Realtime Voice, Muse Realtime Avatar and a pendant called Muse Charm, with no availability for any of them. On 28 September Instinct, an invite-only agent startup, announced a $1 billion Series C at a $10 billion valuation.
This post pins down what each launch actually is, lists what to ask before you hand a consumer agent your inbox, and shows how a team builds its own Muse- or Instinct-style agent with the data, models and deployment under its control, including the parts we are not claiming to match.
The Muse agent is one of several things called Muse
"Muse" is at least five separate Meta things. Mixing them up is how people say a wearable is open source, or a chatbot has an API.
| Name | What it is | Status |
|---|---|---|
| Muse (the agent) | Consumer personal AI agent: iOS, Android, muse.ai, WhatsApp | Launched 8 Sep, US rollout |
| Muse Spark 1.3 | Closed language model, API only | Released 2 Sep |
| Muse Glimmer | Open-weights model, Apache 2.0, distilled from Muse Spark | Available; see our Glimmer deep dive |
| Muse Realtime Voice / Avatar | Voice model and expressive avatars built on it | Announced 23 Sep; no API, price or date |
| Muse Charm | Pocket or pendant device | Announced 23 Sep; no price |
The agent is what most people mean. Meta's launch post says Muse is powered by Muse Spark and runs on its own virtual machine, Muse Secure VM. It is rolling out in the US on iOS, Android and muse.ai, is usable in the app or in WhatsApp, and is "coming soon" to AI glasses. Meta calls it "free for most of what people need", with subscription plans for those who want to do more. The post gives no prices, and I could not verify the figures circulating, so I am not repeating them. TechCrunch says Muse has topped US app stores, and Sensor Tower, cited alongside it, counted over 730,000 US downloads.
Muse Spark 1.3 is the model behind the agent, and it is closed. It has a 1,048,576-token context and costs $1.25 per million input tokens and $4.25 per million output tokens, with cached input at $0.15, according to Meta's pricing page. You reach it through Meta's API and cannot put its weights inside your own perimeter. Muse Glimmer, distilled from Spark and released under Apache 2.0, is the Muse model you can.
The 23 September Connect announcement shows the agent's reach. Meta's post describes Muse for Mac computer use and new connectors: Walmart, Best Buy, Sephora, Shop Pay, PayPal, Instacart, Notion, GitHub and Box, with Expedia coming soon. That list spans shopping accounts, payment wallets and workplace files.
Not confirmed: Muse Charm has no price, and Meta says only that there is "more to share later this year". CNBC reported a December target; Meta's post does not. Meta gives no API, price or date for Realtime Voice or Avatar, so I quote no specifications.
Instinct is a company, not a model
Instinct is a consumer AI-agent startup. It is not a model, a chip or a device.
The product is a personal assistant you text or call. TechCrunch, reporting on 17 and 28 September, says it "uses its own phone number and computer", has no mobile app yet, and is invite-only. Its founder is Noah Shinn. The service launched in August 2026. In mid-September it added "Instinct Concierge", which makes phone calls and books services and was rolling out to a subset of users, per Shinn on X on 16 September.
The money moved fast. TechCrunch reported a $350 million round at a $2.5 billion valuation around 26 August, then on 28 September a $1 billion Series C at $10 billion, with Sequoia, Benchmark and Coatue. TechCrunch was relaying a company press release, which I have not seen. On those figures the valuation quadrupled in about a month.
What Instinct runs on is not public. Neither TechCrunch article names the underlying model, and instinct.com says only "core model". Any post telling you which LLM powers Instinct is guessing.
TechCrunch's 17 September piece was built around Instinct and Muse both adding calls. OpenAI's always-on "dots" agents, announced at DevDay on 29 September per secondary coverage, are a third entrant.
What handing over an inbox means
Strip away the branding and these products ask for four things.
Read access to your communication. Email, messages, calendar. The agent cannot triage what it cannot see.
Access to your files and accounts. Meta's connector list shows the pattern: documents in Notion and Box, code in GitHub, money through PayPal and Shop Pay.
The ability to act. Instinct's calls and email addresses, Muse's computer use on a Mac. An agent that only reads is a search box. One that acts is a delegate, and can be wrong at speed.
Persistence. Muse has its own VM. Instinct has its own phone number and computer. Both are long-lived, so the data does not vanish when the chat ends.
For holiday bookings, that bargain is easy. For the finance lead, each of the four needs an answer she can show her security team.
Questions to put to any consumer agent
Meta's launch post answers more of these questions than a quick read suggests.
Muse runs on Muse Secure VM, which Meta describes as a dedicated virtual machine that houses both the agent and a person's data, contained so no one else's agent can reach it. The data and credentials for any connected service are stored there. Meta says Muse does not share conversations or VM data with its ad systems. A separate Sentinel agent runs on the same machine, kept apart from Muse at the system level, and per Meta nothing Muse does reaches the internet unless the Sentinel approves it; it also asks the user's permission when necessary. People can opt out of their interactions being used to train Meta's models, which makes training use opt-out, not opt-in. And later this year Meta will introduce Muse Confidential VM, encrypted with a key only the person holds, "so not even Meta can access it". That last one is announced, not shipped.
Instinct has published nothing comparable in what we read: TechCrunch and its site describe features, not data handling.
Some questions stay open.
What happens after I delete? Retention after deletion, export and portability are not covered in what I read.
What does the opt-out cover? Meta's developer platform prices training rights explicitly: Muse Spark 1.3 has a "contributor" tier at $0.10 input and $0.20 output per million tokens, against $1.25 and $4.25 standard, about 92% and 95% off by my arithmetic. That is the Model API, not the agent. It is a reason to ask exactly which interactions an opt-out covers.
Which terms apply to a company account? Consumer terms are not negotiated.
How does it resist a hostile message? An agent that reads your inbox also reads mail from strangers. An approval gate on outbound traffic helps. Whether a crafted email can steer what the agent asks for is still a permissions-and-provenance question, the one we raised in the Glimmer post.
And Instinct? Which model reads the mail, where its "own computer" lives, and what happens on a change of control are unpublished.
The honest distinction for the finance lead is not that consumer agents are opaque. It is who holds the controls. Everything above is Meta's policy: set by Meta, described in a blog post, and changeable by Meta. That may be reasonable, but her security team wants controls the company sets and can evidence. In the build below, the company decides what the agent sees, which model reads it, and where it runs.
What an agent you own is made of
Take the Muse and Instinct experience apart and there are five components. Each has a place to keep it in your hands.
Memory and knowledge. What the agent knows about you and your company. In Swfte this is Cortex, "The Hive Mind of Your Business". Its promise is to let you "own the full flow: connect your sources, classify and model your knowledge, then serve it to your agents and people in a controlled way", with privacy at the heart, "from on-device AI to granular control over what every agent can see." It offers role-based access and a native desktop app with offline support on Mac, Windows and web. Cortex is where you decide the inbox is in and the payroll folder is out.
The agent. Instructions, tools and policies. Studio is "a complete platform to design agents, create chatflows, and automate workflows, deploy across every channel", with a visual drag-and-drop builder. You compose agents, tools and policies as reusable blocks, test them with golden sets and A/B comparisons, read traces and cost telemetry, and version them with rollbacks.
The model. Connect is one API to more than 50 LLM providers, with smart routing across cost, latency and availability. You can bring your own keys from any provider, or use Swfte's pooled access. Connect also carries the on-device path: the embedded SDK runs models locally, which is how the Glimmer post describes running an open-weights Muse.
The channels. Studio deploys chat, voice, email and social.
The environment. Dedicated Cloud deploys Swfte models, applications and data bridges "in your own dedicated cloud environment", in an isolated VPC or bare-metal on AWS, Azure, GCP or your own data centre. It runs proprietary and open-source models with full weight control, and bridges CRM, ERP and internal APIs with zero public internet exposure.
For the wider build, see our how to build an AI agent guide and the AI agent platform page. For the data side, including retrieval versus fine-tuning, read Build Your Own AI on Your Own Data. This post does not repeat it.
Three postures, by how sensitive the data is
You do not have to pick one deployment for everything. The useful decision is per task, by what the agent will see.
| Posture | Where data and inference go | Fits |
|---|---|---|
| Your keys, your policies | Studio agent and Cortex knowledge, models called through Connect with your own provider keys | Work that can go to a provider you have a contract with |
| On the device | Open weights such as Muse Glimmer through the Connect embedded SDK; weights and inference stay local | Drafts and triage over the most sensitive mail and files |
| Isolated deployment | The same agent inside Dedicated Cloud: isolated VPC, bare-metal, or your data centre | Regulated data, or a rule that nothing touches the public internet |
The first posture is the easiest and the one people misjudge. Bringing your own keys changes whose account and contract a request runs under. It does not change what the provider does with the request, which is set by the provider's terms, so read them. Connect's own statement is "TLS 1.3 in transit, AES-256 at rest. Your data is never stored without explicit consent". That covers Swfte's handling. It says nothing about a downstream provider's.
The second posture is why Glimmer belongs in this conversation. It is the one Muse model whose weights you can hold, released under Apache 2.0 and built to run locally with vLLM, SGLang, llama.cpp or ExecuTorch. If the input is mail you would never forward to a vendor, run the model on the machine. The cost is capability: it is a narrower model than the closed frontier, so for hard reasoning on non-sensitive work you may want a stronger one.
The third draws the boundary around the infrastructure itself. For the economics, see our on-prem guide; for local versus cloud, the deployment walkthrough.
Mixed use is normal: route sensitive triage to the local model and the rest to a hosted one, a routing rule in Connect rather than a rewrite. To price the hosted options, use the token cost calculator and the AI model leaderboard. As a reference, Artificial Analysis scores Muse Spark 1.3 at 48 at max effort on Intelligence Index v4.3.2, at $1.60 per Index task. That scores the model, not any agent built on it.
A build you could start this week
She needs three jobs done well: triage the inbox, prepare for meetings, draft the board pack. Start narrow.
1. Write the job description first. Three to five tasks, each with a definition of a good result. Vague delegates fail vaguely.
2. Draw the data boundary in Cortex. Connect the sources those jobs need, and only those. Set role-based access so the agent sees what its job requires. Leave payroll and legal correspondence out at first. Widening access is easy.
3. Build the agent in Studio, read-only first. Give it tools that read, summarise and draft. Withhold tools that send, pay or delete on day one. Put approval into the design: drafts go to a person, and the person sends.
4. Test on real examples. Assemble a golden set from tasks that already happened: fifty emails you would have wanted triaged a particular way, plus a few adversarial ones, including messages that try to give the agent instructions. If you would not trust a new hire with those results, do not trust the agent.
5. Pick models per sensitivity through Connect. Local open weights for the most sensitive slice, a hosted model on your own key for the rest. Swap assignments as better checkpoints arrive; the agent is untouched.
6. Deploy, watch, then widen. Read the traces weekly for the first month; roll back a bad change with versioning. When drafts have been right for weeks, let the agent send one narrow class of reply. Then the next. Each step is signed off.
For something closer to the consumer shape, see Swfte's personal assistant page: "a personal-assistant fleet on Swfte", multi-channel and multi-model, per-team budgets, on-prem optional.
What you give up, and who should do what
The trade is not free. You will not get Muse's polish or its distribution inside WhatsApp. You will not get Muse for Mac computer use, Realtime Voice, avatars or a pendant, and we are not claiming to replicate them. We make no claim here about text-message or outbound-calling support: the channels we have quoted are chat, voice, email and social. If your requirement is an agent with its own phone number, check the channel list before planning around it. And you take on the operating work a consumer app hides: access reviews, evaluation, and watching the traces.
That is the price of control, worth paying when the data is the reason for it.
If you want a personal agent for personal errands, a consumer product is a sensible choice. Read the terms, keep work accounts out of it, and ask the questions above.
If you are a professional with sensitive mail, the second posture fits: an open-weights model run locally through the embedded SDK, with a narrow agent.
If you lead a team, start with the three-job build in Studio, with knowledge scoped in Cortex and models chosen in Connect. The internal-assistant pattern is covered in our internal AI assistant post.
If you are in a regulated business, put the boundary around the infrastructure with Dedicated Cloud, and read the data sovereignty piece before you sign anything.
Consumer agents will keep improving. The difference is who decides what the agent can see.
Related: Meta Muse Glimmer deep dive, Build Your Own AI on Your Own Data, edge AI with the embedded SDK, current rankings on AI model leaderboard.
Sources: Meta, Introducing Muse, 8 September 2026 · Meta, Meta Connect 2026: everything we announced, 23 September · Meta Model API pricing and rate limits · Meta Model API overview · TechCrunch, 17 September 2026 · TechCrunch, 28 September 2026 · Instinct · Artificial Analysis
Details of the 8 September Muse launch are from Meta's launch post, re-read on 30 September, plus TechCrunch. Instinct's funding figures are TechCrunch's report of a company press release. Nothing here claims that Muse or Instinct mishandles data; where Meta has published controls, we quote them, and the remaining questions are questions, not findings.