Industry story
Update: Meta expands Muse AI agent with avatar, Mac control, and shopping integrations
agent-framework agents cloud-costs safety tool-use
Amazon already said no. That tells you everything about where this goes. Meta unveiled Muse at Connect 2026 with Mac control, email access, and agentic shopping across Shopify, Walmart, and Sephora, with Zuckerberg pitching it as "the personal superintelligence that billions of people are going to use." Amazon looked at an AI buying on behalf of users and barred it from the site before the keynote was cold. The retailers with the most to lose will do the arithmetic on being charged twice for the same customer, and the technical risks around prompt injection through email and unsanctioned computer-use will give them all the cover they need.
Full analysis
What's new since we last covered this: Muse expands to Mac control, email, and retail integrations with trust-model shift.
Meta wants its AI agent, Muse, to run your Mac, answer your email, and buy things for you on Shopify, Walmart, and Sephora. Zuckerberg says it becomes "the personal superintelligence that billions of people are going to use." The business model is free usage now, a small transaction fee later. And one detail buried in the coverage tells you more than the keynote did: Amazon already barred Muse from doing agentic shopping on its site.
This is hard to undo for Meta in one direction only. Shipping the features is easy to reverse. Convincing people to hand an AI their email login, their desktop, and their credit card is a trust decision that, once broken by a single ugly incident, does not come back. Nothing sets a hard deadline here except Meta's own capex clock and the fact that OpenAI and Anthropic are shipping the same computer-use story right now.
The Skeptic
Zuckerberg has stood on this stage before. Portal. Spark AR. The metaverse rebrand of the entire company. "Billions of users, personal superintelligence" is the same framing that preceded each, and each underdelivered against it.
The money question nobody answered: why does the transaction fee work? Merchants already pay Meta to reach users through ads. Now Meta wants a cut when the same user buys. That is charging twice for one customer, and merchants can do arithmetic.
Amazon barring Muse from agentic shopping is the whole thesis in one move. The retailer with the most to lose looked at an agent buying on behalf of users and said no. Expect Walmart and the rest to reread their contracts the moment Muse actually drives volume. The 1,500 connector applications are a press-release number until someone shows retention and dollars.
The Safety Lens
An agent with your email, your desktop, and your credit card is a new kind of target, and the attack is already documented. Prompt injection through email means a stranger sends a message crafted to hijack what Muse does next. That problem is unsolved. Not "hard." Unsolved.
Computer-use that operates "any desktop app autonomously" walks straight past the permission model every app relies on. The app thinks a human clicked. It was the agent, following instructions it read in a phishing thread.
Meta published no system card for Muse Spark and showed no red-teaming at Connect. For a product that can spend your money and impersonate you over email, that silence is the story. The EU AI Act's high-risk rules for agents making consequential decisions on your behalf are about to get their first real test, and Meta walked in without showing its work.
The Compute Pragmatist
The Muse Realtime Avatar claim is the one to price. A photorealistic talking avatar at conversation speed, running alongside a multimodal agent model and desktop vision, requires serious server spend. That cost scales with how much people use Muse, not how many install it.
So Meta's cost rises with the exact engagement they are bragging about. Free tiers plus "transaction fee later" is spend now, hope to monetize later. Meta's $14 billion-plus quarterly data center spend buys the runway. The unit economics only close if agent sessions turn into purchases at a rate nobody has shown at scale.
The smart glasses wake word implies an always-on small model at the edge, with the heavy work in the cloud. Keeping context in sync between the two without wrecking latency is the real engineering, and it is unglamorous.
The Builder
Two features break first. The email address and Mac computer-use.
Giving an agent an email address makes it an authenticated actor in your identity graph. One replied-to phishing thread, one hallucinated commitment ("yes, ship it, I approve"), and you own the consequences. Computer-use on Mac hits the same wall Anthropic's did: apps that don't expose accessibility hooks, a UI update that breaks the click sequence, and the agent losing its place mid-task with no clean recovery.
The commerce layer is the opposite. Shopify, Stripe, and Walmart are structured APIs. Clean inputs, clean outputs, reliable. That part ships and works.
Anyone building on the connector platform should plan for tighter rate limits and narrower permission scopes around the 90-day mark, right after the first incident forces Meta to lock things down.
Where they disagree
The real split is between the Builder and the Skeptic on where value actually lands. The Builder says the commerce integrations are the clean, reliable part that ships. The Skeptic says the commerce part is exactly where the business model dies, because merchants won't pay Meta twice and Amazon just proved retailers can slam the door. Both are right, which is the problem: the feature that works technically is the feature with no economic foundation.
The second tension is Compute versus everyone selling the demo. The avatar and computer-use are the flashy moments, and they are also the most expensive to run and the most likely to fail with real users. The cheap, boring, reliable thing is structured commerce, which is the thing merchants may not let Meta monetize.
What this hinges on
Three beliefs decide it. Will users grant email, desktop, and payment authority to a Meta agent. Will merchants tolerate a transaction fee on top of ad spend. Will computer-use survive contact with real desktops and adversarial email. Right now the council leans skeptical on all three, and Amazon's bar is the first hard data point pointing the same way.
Before betting anything on Muse commerce, watch what the retail partners do, not what they announced. A launch logo on a slide is a pilot, not a commitment.
Prediction: By Meta's Q2 2027 earnings call in late July 2027, at least two of the retail or platform partners named at Connect 2026 (Shopify, Stripe, Best Buy, Walmart, Gap, Sephora) will have publicly restricted, paused, or declined to expand Muse's agentic shopping access, following Amazon's lead.
Confidence: Medium. Amazon already did it, and the incentive for other large retailers to follow is concrete.
Why: Amazon barred Muse from agentic shopping the same week Meta announced it, and Amazon is the retailer with the clearest read on what an intermediary agent does to margin and customer ownership. The mechanism is simple: an agent that buys on the user's behalf inserts Meta between the merchant and the shopper, threatens a transaction fee on top of the ad dollars merchants already pay Meta, and hands Meta the purchase data. Large retailers with their own checkout and their own ad ambitions have every reason to limit that, and once one major player (Amazon) has set the precedent, the cost of following drops. The opposite outcome, all partners deepening access, requires merchants to accept being disintermediated and double-charged during the exact window when Muse has no proven purchase conversion to justify it.
Revisit by 2027-07-31: We're right if two or more of the named partners have restricted, paused, or declined to expand Muse's agentic shopping by Meta's Q2 2027 earnings call. We're wrong if all named partners have kept or expanded Muse's agentic shopping access with no public restriction.
Comments