Meta launched Muse on Monday. By Tuesday I had four people ask me some version of the same question: is this the one I should finally be using?

Fair question. Wrong shape.

There are now five companies selling you an agent that takes actions instead of giving answers, and they are not competing for the same job. Two of them will produce work you can bill for. Three of them will book your dinner reservation. Owners keep buying the reservation one, waiting for it to save them ten hours a week, and concluding that agents are overhyped.

Here is what actually shipped, what each one is for, and how I would pick.

What Meta actually put in the box

Start with the facts, because most of the coverage this week was about Meta's privacy record rather than the product.

Muse is Meta's personal AI agent, live September 8 in the US on iOS, Android, and muse.ai, with AI glasses support coming. It sends email, books travel, fills out forms, turns a saved Instagram recipe into a grocery list, and buys things. It keeps working after you close the app and comes back when something changes or when it needs your approval.

The architecture is the interesting part. Every user gets a dedicated virtual machine with its own browser, and a second program called Sentinel sits between that machine and the internet. Meta's words: "Nothing Muse does reaches the internet unless the Sentinel approves it, and it asks the person for permission when needed." Credentials are stored so that Muse can use them without seeing them. Purchases run through Stripe's Link with damage, loss, and price-drop coverage attached. A confidential version, encrypted with a key only the user holds, is promised later.

Pricing, per TechCrunch: free with a usage meter, $20 a month for Power, $100 a month for Maximum. Meta expects most people to stay free.

That free tier is not a small detail. It is the most capable agent anyone can use this week without a credit card, and it is going to set the average person's expectation of what an agent is.

The split nobody is naming

Line all five up and they sort into two columns immediately.

Agents built for your life. Muse, Google's Gemini Spark, and Instinct. They hold your logins, act as you, and their best demos are errands: book it, cancel it, reschedule it, negotiate the bill down, buy it.

Agents built for your work. Claude Cowork and ChatGPT Work. They sit on your files and your business tools and hand back a finished thing: the reconciled spreadsheet, the contract summary, the deck, the weekly report.

That distinction decides almost everything, including how much risk you are taking. A life agent needs your credentials to be useful at all. A work agent mostly needs your folders. One of those is a much smaller thing to hand over.

AgentBuilt forWhere it livesPriceThe catch
Meta Muse Personal errands, travel, shopping, bills iOS, Android, muse.ai. Glasses coming Free tier, $20 Power, $100 Maximum Strongest security architecture on paper, weakest trust record in the group
Gemini Spark Running your Google life across Gmail, Calendar, Drive Inside Google's apps $100 or $200 AI Ultra only No cheap way in, and US rollout is still staged
Claude Cowork Finished documents, spreadsheets, decks, recurring reports Mac, Windows, Linux desktop. Web and mobile in beta From about $20 Pro, $100 to $200 Max, $20 per seat Team You point it at folders and tools, so setup is on you
ChatGPT Work Multi-step work across email, Slack, Teams, Drive, GitHub Inside ChatGPT, web and apps Included on paid plans from $20 Plus Broadest reach, so scope its permissions deliberately
Instinct Text-message concierge, calls and bookings on your behalf iMessage, WhatsApp, phone calls Free during private beta Invite only, and its terms and early incidents are the real story

Prices and availability as of September 9, 2026. All five are moving fast; check the vendor before you buy.

The short version on each

Gemini Spark is the one to watch if your company runs on Google Workspace. Google describes it as a 24/7 agent that connects the dots across Google products and takes complex tasks off your plate. Being native to Gmail and Calendar is a real advantage: no integration to configure, no permission to grant, it is already inside the thing. The problem is the price of entry. Spark is gated to the AI Ultra tiers at $100 and $200 a month, US only, still rolling out. There is no $20 door.

Claude Cowork is the least exciting product in this group and the one most likely to give a business owner hours back. It works on files in folders you specify, connects to Drive, Microsoft 365 and Slack, runs recurring tasks on a schedule without you there, and shows you every step it took. That last part matters more than it sounds. When an agent produces a number you are going to put in front of a client, being able to see how it got there is the difference between a draft and a liability.

ChatGPT Work is the broadest. Launched in July, it pulls context from connected apps and hands back finished documents, spreadsheets, presentations and reports, and it reaches Gmail, Calendar, Slack, Teams, GitHub and Drive. If your work is spread across five tools that do not talk to each other, this is the one that spans them. Breadth is also the risk. An agent with read and write access to your inbox and your team chat is a large surface, and the right instinct is to connect one tool, prove it, then connect the next.

Instinct is the one I would keep out of a business for now. The product is genuinely impressive and the market agrees; it raised at a $2.5 billion valuation within weeks. But TechCrunch reported that its terms grant a perpetual and irrevocable license to access, store, reproduce and modify user materials including for training, that one tester had it send an email without checking first, and that another found it still summarizing an inbox after access was disconnected. Any one of those is a bad week. Together they are a pattern, and they are exactly the pattern you cannot have touching client data.

Every agent in this category asks for the same thing: your logins. The only real question is what happens on the day it does something you did not ask for.

Which brings us back to Muse

Meta built the most conservative architecture of the five. A sealed machine per user, a separate gatekeeper approving every outbound request, credentials the agent can use but not read, an audit trail, and a promise of a version Meta itself cannot see into. Compare that to a startup whose terms of service claim a perpetual license to your material and it is not close.

Meta also has the group's worst track record on exactly this, and the coverage this week reflected that. TechCrunch went straight to the FTC settlements and Cambridge Analytica. Those are fair to raise, and the security claims deserve outside verification rather than a press release.

My read: Muse is the best free personal agent available right now, and the free tier is the point. Let it plan a trip, chase a refund, keep a grocery list. Do not connect it to the account your business runs on. Not because Meta is uniquely dangerous, but because a consumer errand agent is not built to be your operations layer, and none of the three in that column are.

How I would pick, if you run a business

Start from the job, not the brand. Write down the task that eats your week. If it produces a document, a report, a reconciliation, or a summary, you want a work agent. If it is booking and buying, you want a life agent, and you probably want the free one.

Sort by whether a mistake is reversible. A bad draft costs you five minutes. A sent email, a purchase, a permission change, a deleted record: those do not come back. Agents earn their keep on the reversible, high-volume, low-stakes work first. Everything else keeps a human in the loop until you have watched the thing work for a month.

Follow where your work already lives. Deep in Google Workspace and willing to pay for Ultra, look at Spark. Spread across Slack, Teams and Drive, look at ChatGPT Work. Living in documents and spreadsheets that need to come out client-ready, look at Cowork. That is usually the whole decision, and it takes about ninety seconds.

Give it its own identity. Whichever you choose, connect it with an account scoped to the job, not your primary login. Read-only where read-only will do. This is the single highest-leverage thing most businesses skip, and it is the thing that turns a bad agent day into an inconvenience instead of an incident.

The part worth noticing

A year ago the interesting question about AI was which model was smartest. That question is basically settled at the level a business cares about: they are all good enough to do the work.

The interesting question now is what you are willing to let one touch. That is not a technology question, it is an operations question, and it is the same question you would ask about a new hire in their first week. Give them the reversible work, watch what they do with it, expand the scope when they earn it.

Muse is a real product and the free tier will put an agent in a lot of hands that have never used one. That is good for everybody selling this. But if you are an owner looking at your calendar and wondering which of these five buys back your Thursday, the honest answer is the boring one that reads your folders and hands you a finished spreadsheet.

I write more about how this stuff actually lands in a business over at Highland Private Office, and about the operator side of building with it at evanrossfl.com.