Meta says its Muse agent can now operate apps on a Mac after the user grants permission. The company announced the computer-use update at Meta Connect on September 23, 2026, and offers a Muse for Mac download. This gives the agent a route into work on the computer itself, beyond the websites and connected services described at Muse's September launch.
The scope of that permission matters. Meta's Connect announcement says Muse can operate any Mac app with permission. Its download page gives narrower, concrete examples: organizing files, filling forms, and drawing from Messages, Calendar and Notes. Those are company descriptions of capability, not evidence that every Mac app and task works reliably.
The big change
- What changed: Meta is extending Muse from websites and connected services into Mac desktop apps. The new access depends on user permission.
- Why it matters: The download page names files, Messages, Calendar and Notes as sources Muse can draw on. For Mac users, granting access therefore means deciding which personal context and app actions to delegate to the agent.
- What to watch: That decision turns on the desktop controls Meta provides. Its published connected-service controls distinguish reading email from sending it; the checked Mac materials do not yet establish whether desktop access can be restricted to individual apps.
Permission covers more than one kind of access
Meta's Muse product page says users can choose whether an action is allowed once, always allowed, or denied, and manage default settings for each connection. The company's launch post gives email as an example of a service where a user may permit reading without permitting sending. It says users can change access or disconnect a service at any time and inspect an audit trail of completed and planned actions.
Those published controls describe Muse's connected services and sensitive actions. The Connect post does not explain how its new Mac computer-use permission is displayed, whether it can be limited to individual desktop apps, or how revoking it interacts with a task already in progress. The distinction is practical for anyone deciding what access to grant: permission to a connected email account and permission to operate an app on the Mac are described in different terms by Meta. The published record does not establish that they have identical boundaries.
Meta says Muse runs in a dedicated cloud virtual machine and that a separate Sentinel agent reviews internet-bound actions. According to the company, credentials are stored where Muse cannot read them, its conversations and virtual-machine data are not shared with Meta's advertising systems, and users can opt out of using interactions to train Meta's AI models. These are Meta's stated design and data-handling rules. The company has announced a further encrypted "Confidential VM" for later this year; it is not part of the current claim. The checked pages do not disclose a retention period for Mac data accessed through computer use.
Mac access is available; glasses access is planned
Meta says Muse is already accessible through its app, WhatsApp, the web and the recently released Mac desktop app. The September 8 launch post specified a US rollout for iOS, Android and the web. The Mac download page offers the installer, but the checked materials do not establish which countries can activate Mac computer use or identify its build number.
The Connect announcement lists additional commerce and work connectors, including Notion, GitHub and Box, without providing a per-connector availability table. It says Expedia is coming soon. Muse on AI glasses is also forthcoming, with Meta saying it will arrive in the coming months. Its proposed ability to respond to what a wearer sees should not be counted as a current Muse feature on glasses. Meta has only teased a pocket device called Muse Charm and says it will share more later this year.
For Mac users, the new decision is whether to let an agent operate desktop apps and use personal context, then monitor and adjust the access Meta makes available. Meta has published controls for connected services and certain consequential actions. It has not yet published enough detail to verify the precise scope of Mac computer-use permission or its performance across apps.



