More than 500,000 people tried Meta's personal AI agent, Muse (Japanese), in roughly the first week after its U.S. launch, according to The Information, which said it had seen internal Meta data. Around the same time, Nat Friedman, who leads the product, said Muse was strongly inspired, as a product, by the open-source project OpenClaw. Both the scale of early usage and the extent of the borrowed design are easy to misread from headlines alone. How far did Meta go in turning a system users run on their own machines into a different product?
500,000+ in week one is not a retention figure
According to The Information's report, more than 500,000 people tried Muse in about a week, daily users exceeded 250,000, and users entered more than 2 million prompts in total. None of these are statistics Meta has announced publicly. The full original report is behind a paywall, so this article is limited to the publicly visible portion and to articles that relay the same figures.
The three numbers measure different things. 500,000+ is people who tried it since launch, 250,000+ is people who used it on a particular day, and 2 million+ is the number of prompts. Dividing daily users by people who tried it, for example, does not give the share who came back the following week, because the counting day, the period covered, and individual user behavior are not aligned. Nor do app rankings or total prompt counts show how many times Muse completed a job through to booking travel or making a payment.
According to Meta's announcement, Muse launched on September 8, U.S. time. It works on iOS, Android, and the web, and users can also talk to it through WhatsApp. It handles tasks such as sending email, booking travel, and filling out web forms, and keeps working after the app is closed. It is free to start, with paid plans for people who want higher usage. Even so, the first-week reports do not reveal how many people used it through which entry point, or how many moved from free use to ongoing use. Meta's announcement also does not mention availability in Japan.
What did Muse take from OpenClaw?
The questions about Muse and OpenClaw arose from how similar the experience feels. In user posts that TechCrunch followed, people pointed to similarly named files in the two workspaces and to similar contents in "SOUL.md," which describes a persona and behavioral guidelines. Muse's internal file set has not been made public, so a match rate cannot be independently verified from the published comparisons.
Looking at OpenClaw's public template, SOUL.md covers the agent's tone, opinions, caution when acting on the outside world, and how memory is handled across sessions. According to the official guide, the file is loaded into ordinary conversations. It is not merely a name: it is a setting that determines how the AI interacts with the user. If the similarity is real, it would mean Meta borrowed from the way users tune their own agents, not just from the on-screen look.
In a post on X, Friedman, who handles product at Meta, said Muse was "strongly inspired" by OpenClaw as a product but was built in-house from the start, TechCrunch reported. He also recalled using OpenClaw in January and buying many Mac minis for an internal team. Meta's PR team offered no further explanation when the outlet asked. The executive's remarks acknowledge a product-design reference while asserting an original implementation. Similar configuration files and his own account are not enough to determine whether OpenClaw's program code was reused.
Similar config files, different places to run
According to OpenClaw's official FAQ, in the standard setup, conversation history, memory, settings, and the workspace are stored on the host where the user runs the Gateway. By contrast, Meta's technical explanation says Muse runs on a cloud virtual machine allocated to each user, where its working data is kept. Both share the idea that users can inspect and edit the files the agent uses. The party responsible for storage and operation, however, changes.
| Point of comparison | OpenClaw's public design | Muse's public design |
|---|---|---|
| Where the workspace lives | The host running the Gateway | A per-user cloud virtual machine |
| Handling of files | Users manage the workspace and edit files such as SOUL.md | Meta says users can view and edit memory and working files |
| External connections | Communication with the chosen model provider and messaging services occurs separately | Meta's protection mechanism evaluates outbound communication and connector operations |
OpenClaw's workspace sits on the Gateway host the user runs, while Muse's sits on a per-user cloud VM operated by Meta. This comparison concerns the standard configurations described in the two sets of public documents; it does not measure source-code identity or which is safer. OpenClaw, too, sends information beyond the user's own machine when it uses external AI models or communication services. Users can edit files in Muse as well, but Meta operates the underlying machine.
Approvals and secrets management built in by Meta
Meta says it divided permissions for operating external services into fine-grained parts so that a wide audience could use the product right away. According to the technical document, a component called "Sentinel," separate from Muse itself, evaluates outbound communication and operations. Where the connected service supports it, permission to read email is separated from permission to send it. For high-impact actions such as sending email or making purchases, the system asks the user for approval.
When a password must be entered, Meta describes a design in which the information is not shown to Muse itself but passed from an isolated vault to the browser. The aim is to reduce the risk of the AI following malicious instructions on a web page and reading out credentials. Meta also says it treats text arriving from outside as untrusted, layering detectors and human approval. This is, however, the defensive setup Meta has published, not an independent test proving that intrusions or misoperations cannot occur. Meta itself acknowledges that prompt injection remains an unsolved problem.
What would turn a trial into ongoing use
The explanation of dedicated VMs also draws a line between the present and the future. Meta states that for the current version of Muse, it restricts internal staff access through operational rules, but that this does not technically prevent Meta's own access where it is needed for purposes such as running the service. "Muse Confidential VM," which would make the data unreadable even to Meta, is planned for introduction within the year and cannot be treated as a feature of the current general release.
Meta says it does not share conversations or data inside the VM with its advertising systems. At the same time, it says that conversation and action histories, with personally identifiable information removed, are used for model training by default, and that users can opt out in settings. The company also notes that browsing history may be used for advertising by stores the agent visits, which could affect ads on Meta's services. This is why users should consider what information they hand over, and what history remains, before connecting email or payment methods.
Whether first-week interest turns into everyday use can be tested by whether the same users return the following week and month, and trust Muse to carry bookings and purchases through to the end. As for the Muse Confidential VM that Meta plans within the year, how much of the audit results are made public after launch will bear directly on decisions about entrusting personal information to it.
