Home / Free AI Tools / Meta Muse Free Tier Limits: What You Actually Get

Meta Muse Free Tier Limits: What You Actually Get

Meta Muse free tier limits explained: 100 million free tokens per week, payment card required, policy-based privacy

META MUSE

Meta Muse Free Tier Limits: What You Actually Get

It’s free until it isn’t — and your card is already on file

Meta gave away one of the most generous free tiers in consumer AI. Here’s the number, the card requirement nobody mentions, and the one line in Meta’s own security document you should read twice.

The short version

Meta Muse has a real free tier — Mark Zuckerberg says up to 100 million tokens a week, which is generous. But you must put a payment card on file before you can start, Meta’s own security document says staff access is blocked by policy rather than encryption, and your conversations train Meta’s model unless you switch that off.

You know the feeling. A huge company announces something free, the number sounds too good to argue with, and some quiet part of your brain starts looking for the trapdoor. You scroll the announcement twice. You can’t find it. So you sign up anyway and hope you’ll notice the bill before it notices you.

Meta launched Muse on September 8, 2026 — a personal AI agent that doesn’t just answer you, it goes and does things. It books travel. It fills out forms. It buys things with your money. And it is, for most people, genuinely free.

I went through Meta’s launch post, the 20-minute engineering document they published alongside it, and the first real reporting from people who actually installed it. The trapdoor is real, but it isn’t where you’d expect. It isn’t the price. Let’s walk through what you actually get, what it costs you that isn’t money, and the three settings worth changing in your first five minutes.

What Meta Muse actually is

Most AI tools you’ve used are chatbots. You ask, they answer, the conversation ends. Muse is a different category — an agent. Meta gives you your own Linux computer in the cloud, puts an AI on it, hands it a web browser, and lets it work while your phone is in your pocket.

According to Meta’s launch announcement, Muse can send email, book travel, negotiate a bill down, turn a recipe reel you saved on Instagram into a grocery list, and check out on a website using Link by Stripe. It keeps working after you close the app and comes back when something changes or it needs your approval.

Practically, that means it’s the first free tool of this kind your parents could use. There’s no terminal, no API key, no setup. You talk to it like you’d text a person — in the Muse app, on the web, or inside WhatsApp.

Where you can get it. United States only at launch — iOS, Android, muse.ai on the web, and WhatsApp chats. Meta says AI glasses are coming. If you’re outside the US, this article is a bookmark, not an action item.

What powers it. Muse Spark 1.3, Meta’s own model, trained specifically for long multi-step work and for resisting instructions hidden inside web pages it reads.

Is Meta Muse free? The 100-million-token answer

Yes — and the free allowance is unusually large. Mark Zuckerberg put the number in a Threads post at launch: up to 100 million tokens per week. Meta’s own newsroom post is vaguer, saying only that Muse is “free for most of what people need.”

For a sense of scale, 100 million tokens a week is roughly the equivalent of a stack of full-length novels passing through the system every seven days. One Gizmodo writer’s verdict after trying to burn through it was that he couldn’t waste it fast enough. Unless you’re running the agent as a full-time employee, you will probably not hit the ceiling.

The three tiers

PlanPriceWhat you get
Free$0Up to 100M tokens/week per Zuckerberg. Full agent, own VM, own browser. Card required to activate.
Power$20/monthMore usage. Same features — this buys compute, not capability.
Maximum$100/monthHighest usage ceiling. For people handing off work all day.

Notice what’s missing from that table: a feature gate. Meta isn’t holding back the good version. The paid tiers buy you more of the same thing, which is refreshingly honest pricing and also tells you something about how Meta plans to make its money here.

Meta Muse pricing tiers compared: free at 100M tokens weekly, Power at $20 a month, Maximum at $100 a month
The paid plans buy compute, not features. Chart: MindWiredAI. Data source: TechCrunch launch coverage, September 8, 2026 — pricing and card requirement paragraphs; free-tier token figure from Zuckerberg’s launch Threads post.

⚠️ The catch nobody puts in the headline

You cannot start on the free tier without adding a payment card. Meta’s reasoning is that subscriptions kick in as usage rises, so the card has to be there first. You are not charged unless you upgrade or approve a purchase — but “free” and “give us a card” are two different sentences, and only one of them made the press release.

Why Meta is giving away this much compute

Free tiers this large are never charity, and Meta hasn’t pretended otherwise. In a September 8 interview with journalist Alex Heath, Zuckerberg described the plan: Meta expects to eventually take “a very small cut” when Muse helps you make money, save money, or complete a purchase.

That reframes the whole product. The compute is the loss leader. The business is the checkout button — Muse shopping on your behalf, with Link by Stripe in the middle, and Shop Pay coming. Every free token is an investment in getting you comfortable letting an AI spend your money.

This isn’t a scandal. It’s a cleaner business model than advertising, arguably — you at least get something concrete for it. But it explains why the free tier is generous and why the card is mandatory, and it tells you where the product will be optimized hardest over the next year. If you’d rather your AI didn’t have a commercial interest in your purchases, that’s a reasonable thing to know up front. It’s the same instinct behind turning off the new ads inside ChatGPT.

What Muse can actually see

Here’s where you need to slow down, and where I’ll give Meta more credit than you might expect before taking some back.

Meta published a genuinely serious engineering document on how Muse is secured. It is not marketing. It describes real architecture: your agent runs in an isolated container, a separate gatekeeper called Sentinel approves every action and every network request, and the agent never sees your actual passwords or API tokens — they get swapped in at the last moment, outside the agent’s reach. The email connector even strips out one-time passcodes and password-reset links so a hijacked agent can’t reset your accounts. Meta is paying up to $300,000 in bug bounties, including $130,000 for a working prompt-injection attack.

That’s better than most agents ship with. Now the part that matters more.

⚡ Read this sentence from Meta’s own document

On today’s Muse, Meta says access to your data by its own staff is restricted “through operational policies.” Then, in the next sentence: it “does not prevent Meta from accessing data when necessary to support, secure or operate the service.”

That is a policy promise, not a technical one. The encrypted version where even Meta cannot look — Muse Confidential VM — is promised “later this year” and is not what you’re signing up for today.

The approval system asks about actions, not about reading

Muse stops and asks permission before it does something hard to undo — sending an email, making a purchase. Meta states the design principle plainly: “Read-only, previously allowed, or demonstrably low-risk actions can proceed without interruption.”

That sounds sensible. It is also exactly the gap a tech columnist fell into. On September 19, Inc.’s Jason Aten published an account of Muse reading his private messages after he had, by his recollection, explicitly declined to give it access to messages. Muse pushed him a notification about a conversation he’d just had with his podcast co-host, and flagged an email from his editor.

When he asked Muse how it knew, Muse told him it was only seeing notification banner text relayed from his Mac — it said it could not open Messages or read history. He checked. Muse had synced his local Messages database to row 187,462. A Meta executive replied publicly with a technical explanation implying the required settings had been enabled. Meta did not respond to his direct questions before publication.

Two things are true here. The agent wasn’t lying on purpose — a language model describing its own plumbing is guessing, and you should never treat an AI’s account of its own permissions as evidence. And reading is not an “irreversible action,” so nothing in the approval system was designed to stop it. Both of those are worth internalizing before you connect anything.

Chart showing which Muse actions trigger an approval prompt and which run silently, including reading data
Approvals are built around actions that are hard to undo — reading is not one of them. Chart: MindWiredAI. Data source: Meta, “How We Built Safety Into Muse,” September 8, 2026 — Human in the Loop and Least Privilege sections.

Your conversations train the model by default

Meta is upfront about this in the security document. Your conversations and the agent’s work traces are used to train future versions of the model. Meta says they’re stripped of key identifying information first, and calls it a good default. There is an opt-out switch in Muse settings — but it is an opt-out, which means the default is on.

The ad carve-out is narrower than it sounds

Meta says Muse doesn’t share your conversations or VM data with its ad systems, and there are no ads inside Muse. True as stated. But Meta also notes that when Muse browses the web, it appears as your activity — so if you ask Muse to shop a clothing site, that brand may later show you an Instagram ad. Your agent’s errands can still ripple into what you’re sold.

Three settings to change in your first five minutes

💡 Do these before you connect anything

Turn off model training in Muse settings. Open the activity log under your Muse’s avatar and read what it has already done. Then open your memory files — Muse lets you read and edit what it has stored about you — and delete anything you didn’t intend to hand over.

A fourth habit, less of a setting than a discipline: connect services one at a time, and use read-only access first where the service supports it. Muse separates read from write for connectors that allow it. Give it your calendar to look at for a week before you give it the ability to schedule. There is no prize for connecting everything on day one.

And if you’re on a Mac, check what the desktop app has been granted at the operating-system level, not just inside Muse. That’s the layer where the Inc. incident happened.

The honest limitations

Setting aside privacy, here’s what will actually frustrate you:

US only. No announced date for anywhere else.

The free ceiling is unpublished in plain terms. The 100M-token figure came from Zuckerberg’s social post, not from a pricing page with terms attached. Meta’s official wording is “free for most of what people need.” There’s a usage meter in the app showing what’s left, which is good — but a number that lives in a founder’s post is a number that can move without a changelog.

Prompt injection is not solved. Meta says so directly in its own conclusion: Muse “isn’t immune to attack” and prompt injection “remains an open problem in the industry.” An agent that reads the open web on your behalf can be manipulated by what it reads. The defenses are layered and serious. They are not a guarantee.

It will be confidently wrong about itself. Demonstrated above. Do not audit an AI by asking the AI.

The privacy version isn’t here. Confidential VM is the thing that would make the strongest claims true. It’s in testing with a small group and promised later this year.

One more thing I could not verify: Meta has not published what happens to your VM and its contents if you stop using Muse or delete your account. The security document covers backups and your ability to download your files, but not deletion timelines. If that matters to you, it’s an open question.

Who should actually care

Worth it if: You’re in the US, you’ve wanted to try an AI agent but every option so far needed a terminal, and you have errand-shaped work — research, comparison shopping, chasing down forms, watching a calendar. Connect one low-stakes service, turn training off, and see what it’s like. This is the cheapest serious look at agents you’ll get.

Maybe not if: You run a small business and the accounts you’d want to connect are client inboxes, invoices, or anything covered by a confidentiality agreement. Wait for Confidential VM, or keep Muse on personal errands only. “Meta policy restricts staff access” is not something you can promise a client.

Skip if: You’re outside the US, you won’t put a card on file for a free product, or your honest reaction to “Meta wants your email and your calendar” is a flinch. That flinch is information. There are open-source AI agents you run on your own machine that ask nothing of you.

Frequently asked questions

Does Meta Muse require a credit card even on the free plan?

Yes. A payment card is required to get started because paid tiers engage as usage rises. You aren’t charged unless you upgrade to Power or Maximum, or approve a purchase Muse makes for you.

How much is the Meta Muse free tier, exactly?

Zuckerberg said up to 100 million tokens per week at launch. Meta’s official materials say only “free for most of what people need.” The app shows a usage meter with your remaining allowance and warns you before the free allowance runs out.

Can Meta employees read what I tell Muse?

Meta says employee access is restricted by operational policy, and that the current architecture does not technically prevent Meta from accessing your data when needed to operate, support, or secure the service. The cryptographically private version, Muse Confidential VM, is planned for later in 2026.

How do I stop Muse from training on my conversations?

There’s an opt-out switch in Muse settings. It’s off by default, meaning your conversations are used for training until you change it. Do it before you connect any accounts.

The bottom line

Muse is the most capable free AI agent an ordinary person can currently get, and Meta built more real security into it than the cynical take would predict. The price isn’t the catch. The catch is that you’re trusting a policy promise instead of a technical one, your card is on file, and your conversations feed the model unless you say otherwise — and none of that is hidden, it’s just quieter than the headline.

Do this one thing: if you install it, open Muse settings and turn off model training before you connect a single account. It takes thirty seconds and it’s the only decision here you can’t make retroactively.

Explore MindWiredAI →

Related free AI guides

Tagged:

Leave a Reply

Your email address will not be published. Required fields are marked *

🔥 Don't miss the latest from AI Agent News! Subscribe Now 👉