Updated 2 hours ago
Meta Muse is coming to AI glasses. Its new connectors carry the bigger tradeoff

AI News

Meta Muse is coming to AI glasses. Its new connectors carry the bigger tradeoff

Meta announced Muse for AI glasses and expanded its connector roadmap at Connect 2026. The practical distinction is what is live, what is still coming and what account access can persist.

The Connect announcement mixes current features with a roadmap

Meta used Connect 2026 to give its personal AI agent a much larger surface area. The company said Muse will come to its AI glasses, gain a voice mode and its own email address, and connect with more shopping, payment, travel and work services. The stage presentation made those changes look like one launch. They are not all available on the same schedule. The most visible feature—asking Muse to act on something a wearer is looking at—is still a roadmap item. [Meta says Muse will reach its AI glasses “in the coming months”](https://about.fb.com/news/2026/09/the‑biggest‑news‑from‑connect‑2026/), without naming supported models, a release date or the data controls that will govern visual requests. [Muse itself began rolling out in the United States on September 8](https://about.fb.com/news/2026/09/introducing‑muse‑personal‑ai‑agent/) for iOS, Android and the web, and [TechCrunch reported the Mac app arriving ten days later](https://techcrunch.com/2026/09/18/metas‑muse‑hits‑mac‑letting‑the‑ai‑take‑actions‑on‑your‑computer/). For someone deciding whether to use Muse now, the more consequential change is its growing connector system. A shopping or calendar connector can turn a chat into an action across another account. That makes the useful questions less cinematic: which integrations are actually live, what can each one read or change, when will Muse ask for approval, and what remains after a connector is removed? Muse is the consumer product: a personal agent that can browse, work in the background and use connected services. Muse Spark is the model family underneath it. Meta also uses “Muse” in the names of separate image and video generation models. Treating those as the same thing makes both availability and security claims unreliable. At Connect, Meta said it was bringing Muse to AI glasses in the coming months. The company demonstrated a future flow in which a wearer can ask about something in view and have Muse take action on it, but it did not publish an eligible‑device list or a firm launch date. Meta also previewed Muse Charm, a pocket device for voice conversations, and said it would share more later in 2026. Neither announcement is evidence that those products are available today. The connector news is closer to the current product, but Meta’s wording still combines several states. Its September 24 post says Muse launched with dozens of partners and access to Shopify’s catalog, then says the company is “adding” Walmart, Best Buy, American Eagle, DICK’S Sporting Goods, Fanatics, Gap, Michael Kors, Sephora, Ulta and Wayfair, plus Shop Pay and PayPal. It calls Expedia “coming soon,” while listing Instacart, Notion, Granola, GitHub and Box without a service‑by‑service launch date. That distinction matters because a conference partner list is not a live connector directory. Readers who want to check an integration before granting access can use OpenTools’ [source‑backed Meta Muse connector directory and setup guides](https://opentools.ai/muse‑connectors), which records availability and setup evidence instead of treating every announcement as installed software. A connector should be described as live only when its current directory entry or the service itself supports that claim.

A connector can create three different kinds of account relationship

Meta’s documentation reveals three materially different ways Muse can reach another service. The first is automatic linkage inside Meta’s own account system. According to [Meta’s connector help page](https://www.meta.com/help/artificial‑intelligence/1687253048996149/), Facebook, Instagram and Threads connect automatically when the accounts share the same Accounts Center. That is different from choosing a third‑party connector in Muse, and it is easy to miss if someone assumes every connection begins with a separate install screen. The second is a built‑in connector. Meta says a connector should exchange only the information needed for the requested task: asking about one email should not download an entire inbox, for example, while a calendar connector may continue checking for changes if the user asks for proactive updates. Muse’s security design can separate read access from write access when the underlying service supports it. A user can therefore test whether Muse summarizes the right calendar before allowing it to create or move events. Built‑in connectors also pass through a partner process. [Muse’s connector platform page](https://muse.ai/platform) says submitted integrations receive functional, security and legal review plus end‑to‑end testing before approval for the directory. That review is evidence of Meta’s admission process, not proof that every connector is risk‑free or that OpenTools independently tested it. The third path is a custom connector for a service that is absent from Muse’s list. Muse may retrieve API information and place credentials in its Secure Credentials Store, but Meta explicitly says it does not review custom connectors or how they use a person’s information. A custom connector therefore has a different trust boundary from a listed integration even when both appear inside the same agent conversation.

Approval controls are specific, but disconnection is not deletion

Meta says Muse runs inside a dedicated cloud virtual machine and places a separate Sentinel system between the agent and the internet. In the company’s [technical account of Muse security](https://research.meta.ai/blog/security‑and‑safety‑for‑ai‑agents‑our‑approach‑with‑muse), Sentinel holds the authoritative permission state and can issue one‑time, session, task, time‑bounded or continuing grants. The runtime doing the work sees surrogate tokens rather than the underlying credentials, while Sentinel inserts the real credential only after authorizing a network request. Those controls are useful, but their scope needs precise language. Meta says many important connector actions default to asking for approval. Users can change those settings, and a prior continuing grant may allow a later matching action without another prompt. Approval is therefore neither universal nor merely a reassuring dialog; it is a permission attached to a particular connector, destination and use case. The safest review is the exact action Muse proposes, not a generic “allow Muse” label. Disconnecting a connector stops future data exchange. It does not necessarily remove information already used. Meta’s help page says earlier connector information may remain in Muse’s memories and the user’s conversation history. Someone ending access may also need to ask Muse to forget retained information and review or delete the relevant conversations rather than assuming the disconnect button reverses everything. Meta also says sanitized conversations, tool calls and subagent handoffs can be used to train later model checkpoints by default, with an opt‑out in Muse settings. The same technical post calls prompt injection an open industry problem and says Muse can still make mistakes. A more isolated “Confidential VM” is described as coming later in 2026, so it should not be confused with the Secure VM architecture running today.

AI glasses raise unanswered questions that connectors do not settle

Moving Muse into glasses changes what can become task context. Meta’s demonstration suggests a wearer could point the agent at a real‑world object and ask it to buy, research or act on what it sees. The connector model explains how Muse might reach a retailer or payment service after the request, but Meta’s Connect post does not specify which visual data is sent, how long it is retained, whether bystanders can be included, or which approval settings will apply to glasses‑triggered actions. Those are not reasons to claim the product is unsafe before it ships. They are the missing details needed to evaluate the announced experience. Device eligibility, visual‑data handling, action history, bystander controls and the handoff from a glasses request to a connected account all need product documentation before “Muse on AI glasses” can be treated as a usable feature rather than a conference demonstration. The same restraint applies to Muse’s own email address. Meta says the address will let the agent receive work or serve as another way to communicate with it, but the announcement does not yet explain sender controls, spam handling, authentication, retention or how an inbound message can trigger a task. An email address is a meaningful new input channel only once those operating rules are published.

The safest first Muse test is deliberately narrow

A sensible first test begins with a task whose result is easy to inspect and reverse. Reading a calendar to identify conflicts is safer than immediately granting the ability to reschedule meetings. Comparing products is easier to audit than allowing an autonomous purchase. Where Muse separates read and write privileges, the initial connection should use read access and one‑time approvals, then expand only after the activity matches the request. Before connecting anything, check whether the integration is live rather than announced, identify the account it will reach and inspect the requested scope. After the task, review Muse’s activity and memory settings, not just the service’s own authorization page. When access is no longer useful, disconnect the connector and separately address any retained memory or conversation history. Meta’s Connect announcement makes Muse broader, but breadth is not the same as readiness. The glasses feature and Charm remain future products; Expedia is explicitly coming soon; and the connector list contains integrations with different review and permission paths. What is available today can still be useful, provided the user treats each connection as an account‑access decision rather than another app icon. *Mark Zuckerberg speaks at Meta Connect 2026, where Meta announced Muse’s planned move to AI glasses and new connector integrations. Image: Meta. Source: [Meta Newsroom](https://about.fb.com/news/2026/09/the‑biggest‑news‑from‑connect‑2026/). Resized and cropped for display.*

Share this article

PostShare

Related News