Meta Muse: The Fight to Own Everything You Buy

An episode of Dan's AI Intel

Meta's new AI agent is a bid to become the front gate of commerce — and the war over who owns your purchases reveals what the agentic era is really worth.

Published · By Dan Walter

Executive summary

Meta did not ship a shopping app on September 8, 2026. It shipped a tollbooth. Muse looks like a friendly errand-runner — it books your tennis lesson, turns an Instagram recipe reel into a grocery order, remembers your friends' dietary restrictions before you send the invites — but the thing Meta is actually building is the layer that sits between a billion people and everything they buy. Whoever becomes that layer inherits the most valuable position on the consumer internet: the front gate through which demand flows before a single retailer gets a say. That is why the launch was less a product debut than the opening move in a land grab, and why the most telling event of Muse's first month was not a feature but a locked door — Amazon cut Muse off from its store less than two weeks after launch, and, by one industry scan, roughly a third of the largest U.S. retailers quietly did the same without ever announcing it.

The deepest thing Muse reveals is what the prize of the agentic era actually is. It is not subscription revenue. The $20 and $100 monthly tiers are rounding errors against the pool Meta is really eyeing: retail media, the ad-and-placement business that already runs to roughly $69 billion a year in the U.S. alone, of which Amazon takes about 80%. An assistant that decides which three products you see, and buys one for you, is the ultimate placement engine — and the most plausible long-run business model is not a subscription at all but a hybrid, a small fee on top of retailers and brands paying to be the answer. The fault line running through the whole field — Meta, Google, OpenAI, Visa, Mastercard, and a defensive Amazon — is a single question: at what scale can a player afford to own the customer relationship and slam the gate shut, versus needing to open it for reach?

And that same logic is what makes Meta's privacy pitch so hard to swallow, even where it is technically real. Meta has gone further than any rival to insulate Muse — a secure virtual machine, a promised user-key-encrypted "Confidential VM" co-designed with Signal's Moxie Marlinspike, conversations walled off from ad targeting. The cryptography is credible. The company making the promise updated its policy on December 16, 2026 to feed data from its other AI interactions into ad targeting, and lost a New Mexico jury verdict the same month for misleading users about exactly this. Both things are true at once, and holding them together is the whole story.

Why an errand-runner is a turning point

For thirty years the digital economy ran on one geometry: attention and traffic funnelled through a browser window and a search box, where the winner sold the right to be seen. Agentic AI moves the window. When an assistant does the searching, comparing, and buying, the moment of decision leaves the retailer's storefront and moves inside the agent. The retail analysts have a name for it — the front door has moved — and Microsoft, Kantar, and McKinsey have all published some version of the warning that a business which is not "agent-ready" loses its direct relationship with the customer to whoever owns the agent. McKinsey's own estimate is that AI systems could mediate somewhere between $3 trillion and $5 trillion of global consumer commerce by 2030, with as much as $1 trillion of orchestrated U.S. retail revenue flowing through agents.

That is the stakes frame for everything below. Muse matters not because Meta built a good assistant — the jury on that is still out — but because it is Meta's attempt to own the new front door, using the two billion-person distribution it already has. This report walks the product, the business model beneath it, the field fighting over the same ground, and the privacy bargain at the centre — and asks, at each step, who actually wins.

What Muse actually is

Strip the marketing and Muse is a personal AI agent that acts in your name. It is powered by Muse Spark, the multimodal model out of Meta's Superintelligence Labs under Alexandr Wang, and it does three kinds of work: it remembers (your goals, your calendar, your saved reels), it plans, and — the part that matters commercially — it executes, shopping and booking and checking out with your approval. Zuckerberg's framing at launch was characteristically grand: "In the coming years, I expect that Muse is going to grow into the personal superintelligence that billions of people around the world are going to use to accomplish their goals and improve their lives."

The mechanical novelty is where it runs. Each Muse agent gets its own cloud virtual machine — a "Muse Secure VM" — driving a real, visible browser that the agent operates on your behalf, and that keeps working when your phone is in your pocket. That visible cloud browser is the difference between a chatbot that gives you a link and an agent that completes the purchase. It launched in the U.S. on iOS, Android, and muse.ai, with a free tier and two paid plans metered by tokens: Power at $20 a month (about 500 million tokens a week) and Maximum at $100 a month (about 3 billion). The free tier is not a demo — it includes the full agent, its own cloud computer, and the ability to shop and check out.

The market reaction was immediate. Muse shot to number one on the U.S. free-app chart, reportedly crossing 3.4 million downloads in short order, and Meta's shares jumped sharply on the debut. JPMorgan called it potentially the broadest consumer-AI adoption since ChatGPT and lifted its price target from $820 to $920; KeyBanc moved to $900 from $780. This is not a science project. It is a distribution weapon aimed at the most profitable choke point in retail.

The war for the front gate

We mapped the underlying logic a month ago, in our agentic-commerce episode (number 50, from late August) — own the customer relationship or become invisible. Muse is that thesis made flesh, and the clearest way to read the strategy is to watch who opened the door and who bolted it. Meta lined up the plumbing — Stripe, Shopify, and PayPal on payments — and a row of brand-name retailers: Best Buy, Gap, Sephora, Wayfair, and, notably, Walmart, plus Expedia for travel and Instacart coming for groceries. The single sharpest move was Shopify's: on launch day it added Meta to its Agentic Storefronts program with merchant catalogues shared to Muse by default, so a seller who wants out has to opt out. Amazon did the opposite. It cut Muse off within about two weeks, greeting agent traffic with a pop-up — "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed" — and its stated reasons were pointed: Meta never told Amazon that Muse would shop there, the agent does not identify itself as it browses, and it appears to capture and store customer credentials.

Exhibit — Who opened the gate for Muse — and who slammed it shut. The opt-in/opt-out choice is a proxy for market power — reach for the challengers, control for the incumbent. Source: Company announcements; GeekWire; majormatters retailer scan. Compiled by Dan's AI Intel.

That divide is the whole thesis in miniature. A Best Buy or a Gap needs demand more than it needs to own the checkout, so it takes the reach an agent offers. Amazon does not — its store is the customer relationship, and letting an outside agent buy on its shelves would hand a rival the decision moment while stripping out the sponsored listings that fund the business. As one framing of the standoff put it bluntly, Amazon blocked Muse because the page earns more than the sale. The uncomfortable truth underneath is that Amazon is not alone; it is simply the only one that said so out loud. A scan of the 92 largest U.S. retailers reportedly found roughly a third quietly blocking Muse — a single-source figure worth treating as a reported estimate, not a hard count, but directionally damning either way.

The real question beneath the opt-in list is scale. A retailer's decision is a bet on its own market power: open the gate and you rent reach from the agent at the cost of your customer relationship; shut it and you keep the relationship but forfeit the reach. Only a handful of players are big enough to make the second bet stick — which is what makes Walmart's opt-in the surprise of the launch, and Amazon's block the natural move. Neil Saunders, managing director at GlobalData Retail, kept the temperature honest: the buzz around Muse marks "the acceleration of agentic shopping," he said, but "I wouldn't say it's a tipping point — it's certainly an important part of the journey for AI and consumers." An agent is only as useful as the shelves it can reach, and right now Muse can reach the challengers who need it more than the incumbents who don't.

Follow the money: the subscription is a decoy

Here is where the insider read diverges from the press-release read. The $20 and $100 tiers are real, but they are not the plan. The prize is the toll underneath. Retail media — the fees retailers and brands pay to influence what a shopper sees — is already a roughly $69 billion business in the U.S. and north of $200 billion globally, and an agent that narrows a thousand products to three is the most powerful placement surface ever built. The likely long-run model is an all-in hybrid: a modest subscription for capability, plus retailers and products paying for better standing in the agent's answer — and, on the transaction itself, the chance to clip the ticket, taking a cut of the sale the way a marketplace or a card network does. That is not a new business for Meta. It is the ad business Meta already dominates, wearing a new interface. The venture investor Rory O'Driscoll captured why the market cared enough to add roughly $100 billion to Meta's value in a week: the phone app is the sideshow, and "the real fight is agentic commerce." A pure subscription, by contrast, is a rounding error — even a wildly optimistic paid base at $100 a month raises a fraction of what a single point of take on the trillions McKinsey expects agents to mediate would throw off. That asymmetry is the tell. No serious player is building an agent to sell subscriptions; they are building it to sit at the toll gate.

Exhibit — Amazon owns ~80% of U.S. retail media — which is exactly why it won't let an agent in. The incumbent with the biggest ad toll to protect has the most reason to keep rival agents out. Source: eMarketer (US retail media ≈ $69B; Amazon ≈ 80% share), 2026. Compiled by Dan's AI Intel.

The counter-case is real and worth stating, because it cuts against the doom narrative. eMarketer's early data suggests agents might enhance retail media rather than kill it, by sending higher-intent traffic that converts better. But the structural worry has teeth: Walmart's own data reportedly showed that when agents buy items directly, the basket shrinks — the agent grabs the one thing you asked for and skips the impulse aisle that fattens every cart. And the take-rate math is what keeps analysts cautious. Truist's Youssef Squali estimated Muse could add about $28.5 billion in annual revenue by 2030, then cautioned in the same breath that Meta's early lead may not last. Every dollar of that projection depends on a toll that does not yet formally exist and a base of retailers that is, right now, shrinking as fast as it is growing.

Everyone is building the same tollbooth

Meta is not inventing this land; it is late to a field that has been quietly wiring itself for a year. The striking thing is how similar the blueprints are — an agent, a payment rail, and a protocol to move money with a cryptographic audit trail — and how the real division is between open standards and walled gardens.

Exhibit — Six players, one tollbooth — the split is open standard vs walled garden. The plumbing is converging on a standard; the strategy is diverging into open reach vs closed control. Source: Google Cloud; Stripe; Visa; Mastercard; Amazon. Compiled by Dan's AI Intel.

The details matter. Google is furthest along on infrastructure: its Agent Payments Protocol (AP2), first announced in September 2025 with more than 60 partners including PayPal, Mastercard, and American Express, shipped a v0.2.0 in April 2026 that added "Human Not Present" payments — an agent buying limited-release tickets the instant they drop — and Google donated AP2 to the FIDO Alliance to make it an industry standard rather than a proprietary lock. Its Universal Cart, unveiled at I/O in May 2026, follows a shopper across Search, Gemini, YouTube, and Gmail. OpenAI, with Stripe, published the open Agentic Commerce Protocol whose Shared Payment Tokens keep the retailer as merchant-of-record, and Visa tied its Intelligent Commerce effort directly to OpenAI in June 2026; Mastercard's Agent Pay, announced back in April 2025, moves money through "Agentic Tokens." And Amazon, having renamed Rufus to Alexa for Shopping in May 2026 and built its own "Buy for Me" agentic checkout, is running the opposite strategy entirely — deploy your own agent, block everyone else's. The convergence on shared plumbing is real; so is the divergence on who is allowed through the gate.

The privacy paradox

Meta knows its own reputation, which is why Muse arrived wrapped in the most elaborate privacy architecture the company has ever shipped. The concrete claims: Muse does not share your conversations or the data inside your VM with Meta's ad systems, even when your account is linked to other Meta products. The forthcoming Muse Confidential VM goes further — it encrypts the entire virtual machine with a key held only by the user, inside a trusted execution environment, so that no one, Meta included, can enter your agent's world. Meta recruited Moxie Marlinspike — Signal's founder and the architect of WhatsApp's end-to-end encryption — to design it, promised to publish the VM binaries and a transparency log, and is giving outside security firms source access for ongoing audits. Analysts have started calling it a genuine third model of AI trust, alongside Apple's stateless Private Cloud Compute and Google's approach: not "trust us," but "we made it mathematically impossible for us to betray you." Taken on its own terms, it is the strongest privacy engineering any agent maker has put forward.

Now the other side of the ledger, which the record earns. This is the company of the Cambridge Analytica scandal, and in September 2026 — the very month Muse launched — a New Mexico jury found that Meta had made users believe they controlled their information while it was selling access to third parties. More pointedly, Meta confirmed that from December 16, 2026 it would begin using data from interactions with its AI products to target ads across its platforms. The needle Meta is threading is narrow and worth stating precisely: the Muse VM and its conversations are walled off from ads, but Meta AI more broadly is being pointed straight at the ad engine. So the honest verdict is neither "trust it" nor "it's a con." It is that the cryptography, if it ships as described and the audits hold, could be real and verifiable — and that a user is still right to ask why the company that needs your commerce data most is the one promising hardest not to look at it. The Confidential VM is in limited testing, not general release; until the binaries and audits are public, the promise is a promise.

Bottom line

Muse's arc is easy to trace and the near-term is already visible. The Muse Spark model surfaced in spring 2026; Muse itself launched on September 8; Amazon blocked it within about two weeks; at Connect on September 23 Meta gave it voice and real-time video, opened it in Canada, and unveiled a keychain device called Charm (shipping in December) to talk to it hands-free; on September 29 it launched Muse for Small Business. The next couple of months are set: Charm ships and the December 16 ad-data policy takes effect in the same window, Muse rolls onto Meta's AI glasses, Instacart comes online, and the user-key Confidential VM is due to widen from trusted testers.

Exhibit — Muse's first 100 days — and the two months that decide it. The same December window ships the strongest privacy promise and the policy that undercuts it. Source: Meta Connect; TechCrunch; CNBC. Compiled by Dan's AI Intel.

The three hinges to watch are simple. First, does the toll materialise — will retailers and brands actually pay for placement inside an agent, turning Muse into the retail-media engine the valuation assumes, or does the basket-shrink problem starve it? Second, does the gate stay shut — if Amazon and a third of big retailers hold the line, Muse's reach is capped at the challengers who need it, and an assistant that can't buy where you actually shop is a demo, not a habit. Third, does the trust hold — the Confidential VM either ships verifiable and resets what a user can expect from Meta, or it stays a testers-only promise while the ad machine quietly eats the rest. Meta has the distribution to win the front gate. Whether it deserves to stand there is the question the next two months answer.

Sources

Provenance note: outbound fetches to news domains were blocked in this environment, so this report is built from search-result summaries triangulated across multiple independent outlets rather than primary pages; single-sourced figures (e.g. the "~1 in 3 retailers" scan and the 3.4M download count) are flagged in-text as reported estimates.

Transcript

Sam: Meta just shipped an app that books your tennis lesson and turns an Instagram recipe reel into a grocery order. A cute little errand-runner, right?

Alex: Except it's not an app. It's a tollbooth — the layer that sits between a billion people and everything they buy.

Sam: And less than two weeks after launch, Amazon slammed the gate shut on it. That reaction alone tells you exactly what's at stake here.

Alex: Welcome back to Dan's AI Intel, the show where we take the one question that actually matters this week and dig past the hype and the fear to what's really going on underneath.

Sam: I'm Sam, and the calm, unreasonably well-read voice on the other mic is Alex. And today we are getting into Meta Muse — the personal AI agent Meta launched on September the eighth.

Alex: On the surface it's the friendliest thing Meta has ever built. It remembers your friends' dietary restrictions before you send the dinner invite. Underneath, it's the opening move in a land grab.

Sam: Because here's the deeper question we couldn't put down. When an AI does your shopping for you, who actually owns that moment — you, the store, or the company that owns the agent? That's a trillion-dollar question, and we mean that almost literally.

Alex: We're going to walk the product, then the business model hiding underneath it, then the six giants all fighting over the same patch of ground — Meta, Google, OpenAI, the card networks, and a very defensive Amazon.

Sam: And then the part that made my head hurt in the best way: Meta making the strongest privacy promise anyone in AI has ever made, in the same month it lost a jury verdict for misleading people about their data. Both true. At the same time.

Alex: There's a turn in this one that flips the whole thing on its head, and I don't want to give it away — but the villain and the hero might be the same move.

Sam: If you've been enjoying the show, do hit follow on Spotify or Apple Podcasts while we get into it — it's free, one tap, and it means the next one just shows up. Okay. Let's open the gate.

Alex: So let me set the table, because the framing is everything here. For thirty years the digital economy ran on one shape: attention and traffic funnelled through a browser window and a search box, and the winner was whoever sold the right to be seen.

Sam: Right — the whole game was "get in front of the customer." Search ads, the storefront, the shelf. That's the world I grew up shopping in.

Alex: Now watch what an agent does to that. When the assistant does the searching, the comparing, and the actual buying, the moment you decide leaves the store's website and moves inside the agent. The retail analysts have a phrase for it — the front door has moved.

Sam: Okay, unpack "the front door moved," because that sounds like a slogan until you feel it.

Alex: Think of a shopping mall. For decades the mall owned the front door — everyone walked in through it, and the stores paid rent to be near it. Now imagine a concierge meets every shopper in the car park, takes their list, walks in alone, and comes back with the bags. The shops never see the customer. The concierge is the new front door, and the mall is just a warehouse.

Sam: Oof. And whoever hires out the concierge sets all the rules.

Alex: Exactly. Microsoft, Kantar, McKinsey — they've all published some version of the same warning: a business that isn't "agent-ready" loses its direct relationship with the customer to whoever owns the agent. And McKinsey's own number for the size of this shift is genuinely startling.

Sam: Hit me.

Alex: They estimate AI systems could mediate somewhere between three and five trillion dollars of global consumer commerce by 2030. And as much as a trillion dollars of U.S. retail revenue flowing through agents.

Sam: A trillion dollars of buying just... routed through a piece of software. That's the prize sitting on the table.

Alex: That's the prize. So Muse matters not because Meta built a good assistant — the jury's honestly still out on that — but because it's Meta's attempt to own the new front door, using the two-billion-person distribution it already has.

Sam: So before we get to the war, what is the thing? If I download Muse tomorrow, what am I actually holding?

Alex: Strip the marketing and it's a personal AI agent that acts in your name. It runs on a model called Muse Spark, out of Meta's Superintelligence Labs, and it does three things: it remembers — your goals, your calendar, your saved reels — it plans, and, the part that matters commercially, it executes. It shops, it books, it checks out, with your approval.

Sam: Superintelligence Labs — that's the shop run by Wang, right? Remind me where he fits.

Alex: Alexandr Wang. He runs Meta's Superintelligence Labs — the group Meta stood up to chase frontier AI — and Muse Spark, the model powering Muse, is the first big consumer thing to come out of that lab. So this is Meta's superintelligence bet, pointed straight at your shopping cart.

Sam: Got it. And the mechanical trick — you said there's something genuinely new about how it runs.

Alex: This is the part I love. Every Muse agent gets its own cloud computer — Meta calls it a Muse Secure VM — and it drives a real, visible web browser on your behalf. Not a chatbot handing you a link. An actual browser, clicking through checkout, that keeps working while your phone's in your pocket.

Sam: So it's less "here's a recommendation" and more "I've already bought it, it's arriving Thursday."

Alex: That's the whole difference. A chatbot gives you a link; an agent completes the purchase. That leap — from suggesting to doing — is what turns a novelty into a chokepoint.

Sam: Okay, and the money side for a normal person — is this the usual twenty-bucks-a-month thing?

Alex: There's a free tier, and it's not a crippled demo — it includes the full agent, its own cloud computer, and the ability to shop and check out. Then two paid plans metered by tokens: Power at twenty dollars a month, roughly five hundred million tokens a week, and Maximum at a hundred a month, about three billion.

Sam: Hold that thought on the pricing, because I have a feeling those numbers are a magic trick and we're going to come back to them.

Alex: You have very good instincts. Park it. But the reaction tells you people took it seriously: Muse shot to number one on the U.S. free-app chart, reportedly crossing three-point-four million downloads fast — and I'd flag that download figure as a single reported estimate, not gospel. Meta's stock jumped hard. JPMorgan called it maybe the broadest consumer-AI adoption since ChatGPT and raised its price target from eight-twenty to nine-twenty. KeyBanc went to nine hundred.

Sam: So Wall Street didn't see a shopping app. They saw the tollbooth too.

Alex: They absolutely did. Which is the perfect place to talk about the door Amazon shut. So we mapped the underlying logic of all this about a month ago — our agentic-commerce episode, number 50, "Own the Customer or Become Invisible." If that one grabbed you, this is that thesis made flesh.

Sam: And the way to read the strategy, you said, is almost embarrassingly simple: watch who opened the door for Muse and who bolted it.

Alex: Right. Meta lined up the plumbing — Stripe, Shopify, and PayPal on payments — and a row of brand-name retailers: Best Buy, Gap, Sephora, Wayfair, and, notably, Walmart. Plus Expedia for travel and Instacart coming for groceries. But the single sharpest move was Shopify's.

Sam: What did Shopify do?

Alex: On launch day it added Meta to its Agentic Storefronts program, with merchant catalogues shared to Muse by default. So a seller who wants to stay out of Muse has to actively opt out.

Sam: Opt-out by default. That's how you flood a system overnight — same trick every platform uses when it wants scale fast. Nobody reads the setting, so everybody's in.

Alex: Exactly the pattern. And then Amazon did the precise opposite. About twelve days after launch, it cut Muse off — greeted the agent with a pop-up that basically said, continued access by an unauthorized AI agent violates our conditions of use.

Sam: A velvet rope with a bouncer. What were Amazon's actual reasons, or was it just turf?

Alex: The reasons were pointed, and honestly not unreasonable. One: Meta never told Amazon that Muse would be shopping there. Two: the agent doesn't identify itself as it browses — it just moves through the site looking like traffic. And three, the spicy one — Amazon says it appears to capture and store customer credentials.

Sam: Wait — capture and store credentials? That's the kind of line that should make everyone sit up, given the rest of this story.

Alex: Hold that too, because it rhymes with the privacy section later. And Amazon isn't only blocking Meta — it blocks Google, OpenAI, Perplexity, and Anthropic's agents as well. This is a policy, not a grudge.

Sam: So is Amazon just being Amazon — the walled-garden villain? Because that's the easy story.

Alex: It's the easy story and it misses the mechanism. Here's the thing that made it click for me. A Best Buy or a Gap needs demand more than it needs to own the checkout — so it happily takes the reach an agent brings. Amazon doesn't need reach. Its store is the customer relationship.

Sam: So for Amazon, letting an outside agent buy on its shelves is like...

Alex: Like inviting a rival concierge into your shop to make the choice for your own customer — and, while they're at it, ripping out the sponsored listings that pay your bills. Someone framed the standoff perfectly: Amazon blocked Muse because the page earns more than the sale.

Sam: "The page earns more than the sale." Say more — that's the whole quarter in six words.

Alex: It means the ads and placements on an Amazon product page make Amazon more money than its cut of the item you buy. An agent that skips the page to grab the product destroys the more profitable half of the business. So blocking it isn't grumpy — it's math.

Sam: And here's what surprises me: Walmart opted in. Walmart is the one player big enough to slam its own gate, and it opened it. Why?

Alex: That's genuinely the surprise of the launch, and I don't think anyone fully knows Walmart's hand yet. The clean reading is that it's a bet — Walmart would rather be inside the agent that's winning than betting its whole future on shoppers coming to walmart-dot-com out of habit.

Sam: So the opt-in list is basically a confidence meter. Open the gate if you need the traffic; shut it if you already own the customer.

Alex: You just said the whole thing better than I did. And here's the part the breathless coverage skipped — the blocking isn't rare. A scan of the ninety-two largest U.S. retailers reportedly found roughly a third quietly blocking Muse.

Sam: A third? And "quietly" — meaning no press release, they just... locked the door and said nothing.

Alex: Quietly. And I want to be honest about that number: it's a single-source scan, so treat it as a reported estimate, not a hard count. But directionally it's damning either way. Amazon is just the only one that said it out loud.

Sam: So the retail analyst take on all this — is anyone keeping the temperature honest? Because I can feel myself getting swept up.

Alex: Neil Saunders, who runs GlobalData Retail, did exactly that. He called the buzz around Muse the acceleration of agentic shopping — but then said, and I think this is the wise line, "I wouldn't say it's a tipping point — it's an important part of the journey." An agent is only as useful as the shelves it can reach. And right now Muse can reach the challengers who need it, not the incumbents who don't.

Sam: Okay. You made me park the pricing about twenty minutes ago. Cash it in. Why is twenty bucks a month a magic trick?

Alex: Because it's a decoy. The twenty and the hundred-dollar tiers are real, but they are not the plan. They're a rounding error against the pool Meta is actually eyeing.

Sam: Which is?

Alex: Retail media. That's the industry term for the fees retailers and brands pay to influence what a shopper sees — the sponsored slot, the "recommended for you." In the U.S. alone it's already about a sixty-nine-billion-dollar business, and north of two hundred billion globally.

Sam: So this is just... digital shelf space. The end-cap display, but online.

Alex: Perfect analogy — it's the end-cap, the thing brands fight and pay for. Now think about what an agent is. It narrows a thousand products down to three, and buys one for you. That is the most powerful placement surface ever built. An assistant that decides which three products you even see is the ultimate advertising engine.

Sam: Ohh. So the shopping isn't the product. My attention — or my agent's attention — is the product. Again.

Alex: Again. And this is the tell. The most plausible long-run model isn't a subscription at all. It's a hybrid: a modest fee for the capability, plus retailers and brands paying for better standing inside the agent's answer — and on the sale itself, clipping the ticket, taking a small cut the way a marketplace or a card network does.

Sam: Which, when you say it out loud, is just... the ad business Meta already runs. Wearing a new coat.

Alex: It's the ad business Meta already dominates, wearing a new interface. That's why the market added something like a hundred billion dollars to Meta's value in a single week. The venture investor Rory O'Driscoll put it cleanly: the phone app is the sideshow — "the real fight is agentic commerce."

Sam: Give me the asymmetry in real numbers, because "rounding error" is easy to say.

Alex: Sure. Imagine even a wildly optimistic paid subscriber base at a hundred bucks a month. It raises a fraction of what a single percentage point of take on those trillions McKinsey expects agents to mediate would throw off. Nobody serious is building an agent to sell subscriptions. They're building it to sit at the toll gate.

Sam: So is this a done deal? Meta prints money forever?

Alex: No — and I want to give the counter-case real air, because it cuts against the doom story. eMarketer's early data actually suggests agents might enhance retail media rather than kill it, by sending higher-intent traffic — people who are further along, more likely to actually buy.

Sam: That makes sense. If my agent is checking out, I've basically already decided. That's a better customer than someone idly scrolling.

Alex: Right. But then there's the worry that has real teeth, and it's a beautiful little piece of human behaviour. Walmart's own data reportedly showed that when an agent buys directly, the basket shrinks.

Sam: The basket shrinks — meaning I buy less?

Alex: Meaning the agent grabs the one thing you asked for and walks straight past the impulse aisle. No "ooh, chocolate at the register." No "well, since I'm here." The agent doesn't get tempted, and impulse is what fattens every cart in retail.

Sam: That is such a clean insight. The entire supermarket is designed around your weak moments, and the robot has no weak moments.

Alex: The robot has no weak moments. And that's the structural threat to the whole model. So the analysts stay cautious. Truist's Youssef Squali estimated Muse could add about twenty-eight and a half billion dollars in annual revenue by 2030 — and in the same breath warned Meta's early lead may not last.

Sam: So every dollar of that projection is riding on a toll that doesn't formally exist yet, and a list of retailers that's shrinking as fast as it's growing.

Alex: That's the honest summary of the bull case. It's real. It's also a bet.

Sam: Okay, so far this is a Meta story. But you keep hinting Meta's actually late to this.

Alex: Meta's late. This field has been quietly wiring itself for over a year, and the striking thing is how similar everyone's blueprint is. It's always the same three parts: an agent, a payment rail, and a protocol to move money with a cryptographic audit trail.

Sam: Translate "protocol with a cryptographic audit trail" for me — that's a lot of syllables.

Alex: Think of it as a tamper-proof receipt the moment an agent spends your money. It proves you authorised this agent, to spend up to this much, at this store — so when a robot buys something, the bank and the shop can both trust it was really allowed. That's the plumbing everyone's racing to standardise.

Sam: And the real divide between the six players isn't the plumbing, it's...

Alex: Open standard versus walled garden. Same pipes, opposite philosophies. Let me walk the field. Google is furthest along on infrastructure. Its Agent Payments Protocol — AP2 — launched back in September 2025 with more than sixty partners, including PayPal, Mastercard, and American Express. This spring it shipped an update that added something called "Human Not Present" payments.

Sam: "Human Not Present" — that sounds mildly terrifying. What is it?

Alex: It's an agent buying when you're not there at all. The classic case: limited-release concert tickets drop at 10 a.m., you're in a meeting, your agent grabs them the instant they go live. And the genuinely strategic move — Google donated AP2 to the FIDO Alliance, the industry standards body, so it becomes a shared standard instead of a Google lock.

Sam: So Google's playing the "let's all agree on the rails" card. Why would they give it away?

Alex: Because if you own the standard everyone builds on, you win even when you're not the toll collector. And Google's got Universal Cart, unveiled at its I/O conference in May, which follows a shopper across Search, Gemini, YouTube, and Gmail. One cart, everywhere you already are.

Sam: Okay, that's Google. Where does OpenAI sit?

Alex: OpenAI, with Stripe, published its own open protocol — the Agentic Commerce Protocol — and its clever bit is Shared Payment Tokens, which keep the retailer as the merchant of record.

Sam: Meaning the store still officially makes the sale, so it doesn't feel like OpenAI is stealing the customer.

Alex: Exactly — a peace offering to nervous retailers. And Visa tied its Intelligent Commerce effort directly to OpenAI in June. Mastercard's got Agent Pay, announced back in April 2025, moving money through what it calls Agentic Tokens. The card networks basically want to be the rails under every agent, no matter who wins.

Sam: Smart. They don't care who owns the concierge, they just want a cut every time he swipes. And then there's Amazon, doing its own thing entirely.

Alex: Amazon renamed its shopping assistant from Rufus to Alexa for Shopping this spring, built its own "Buy for Me" agentic checkout, and is running the exact opposite strategy: deploy my own agent, block everyone else's. So the plumbing is converging on a shared standard — but the strategy is splitting hard into open reach versus closed control.

Sam: It's basically the Android-versus-Apple fight all over again, just for your shopping cart.

Alex: That's a really fair way to hear it — the open, everybody-in coalition versus the closed, we-own-the-whole-thing garden. Same movie, new medium.

Sam: Alright, this is the part I've been waiting for, because Meta and privacy in one sentence usually reads like a joke. But you told me before we started that they've actually done something serious here.

Alex: They have, and I want to give it its full due before we get skeptical, because both halves of this are true and holding them together is the entire story. Meta knows its own reputation — which is exactly why Muse arrived wrapped in the most elaborate privacy architecture the company's ever shipped.

Sam: Concrete claims. What did they actually promise?

Alex: First: Muse doesn't share your conversations, or the data inside your VM, with Meta's ad systems — even when your Muse account is linked to your other Meta stuff. Then it goes further with something called the Muse Confidential VM. It encrypts the entire virtual machine — your agent's whole little world — with a key held only by you.

Sam: Wait — a key only I hold. So even Meta can't get in?

Alex: That's the claim. It runs inside what's called a trusted execution environment, and the pitch is that no one, Meta included, can enter your agent's world. And here's the detail that made me take it seriously: they recruited Moxie Marlinspike to design it.

Sam: Okay, catch me up — who's Moxie Marlinspike? The name rings a bell.

Alex: He's the founder of Signal — the encrypted-messaging app the privacy world actually trusts — and he's the architect behind WhatsApp's end-to-end encryption. He is, roughly, the most credible cryptography name you could possibly put on a project like this. He doesn't lend his name to security theatre.

Sam: So this isn't a marketing checkbox. That's like hiring the world's best locksmith and then publishing the blueprints.

Alex: That's precisely the posture. Meta promised to publish the VM's code and a transparency log, and to give outside security firms source access for ongoing audits. Analysts have started calling it a genuine third model of trust — alongside Apple's Private Cloud Compute and Google's approach. The pitch isn't "trust us." It's "we've made it mathematically impossible for us to betray you."

Sam: I have to say, said like that, it's the strongest thing I've ever heard an agent maker offer. So where's the catch? Because I can hear you winding up.

Alex: The catch is who's making the promise. This is the company of the Cambridge Analytica scandal. And in September 2026 — the very month Muse launched — a New Mexico jury found that Meta had made users believe they controlled their information while it was actually selling access to third parties.

Sam: The same month. That's almost too on-the-nose.

Alex: It gets sharper. Meta confirmed that starting December 16th, 2026, it will begin using data from your interactions with its AI products to target ads across its platforms.

Sam: Okay, now I'm confused, and I think our listener is too. You just told me the VM is walled off from ads. Now you're telling me the AI data feeds the ad machine. Which is it?

Alex: Both — and this is the needle Meta is threading, so let me be really precise. The Muse VM and its conversations are walled off from advertising. But Meta AI more broadly — the assistant across its other products — is being pointed straight at the ad engine. Two different things wearing similar names.

Sam: And remember Amazon's third complaint — that Muse seems to capture and store customer credentials. Against this backdrop, that line lands a lot differently.

Alex: It lands much harder. That's the exact anxiety the Confidential VM is engineered to answer — and the exact anxiety the track record keeps alive. Same worry, from both directions at once.

Sam: So the honest verdict isn't "trust it" and it isn't "it's a con."

Alex: No. The honest verdict is that the cryptography, if it ships as described and the audits actually hold, could be real and verifiable. And a user is still completely right to ask why the company that needs your commerce data the most is the one promising hardest not to look at it.

Sam: And crucially — the Confidential VM, the good part, isn't even fully out yet, is it?

Alex: That's the fine print. It's in limited testing, not general release. Until the binaries and the audits are public, the promise is exactly that — a promise. The engineering is credible. The track record earns the skepticism. You have to hold both, and anyone selling you just one half is selling you something.

Sam: So bring us home. If someone's listening on a walk right now, what's the takeaway they carry out the door?

Alex: The arc is easy to trace and the near-term is already set. Muse launched September 8th. Amazon blocked it within about two weeks. At its Connect conference on September 23rd, Meta gave Muse a voice and real-time video, opened it in Canada, and revealed a little keychain gadget called Charm — shipping in December — to talk to it hands-free. On the 29th it launched Muse for Small Business.

Sam: And December is the month where everything collides.

Alex: December is the collision. Charm ships and the December 16th ad-data policy takes effect in the same window. Muse rolls onto Meta's AI glasses, Instacart comes online, and the user-key Confidential VM is due to widen beyond its first testers. So here are the three hinges I'd actually watch.

Sam: Go.

Alex: One: does the toll materialise? Will retailers and brands actually pay for placement inside an agent — or does that basket-shrink problem, the robot with no weak moments, starve the whole model before it starts?

Sam: Two, I'm guessing, is the gate.

Alex: Two: does the gate stay shut? If Amazon and a third of big retailers hold the line, Muse's reach is capped at the challengers — and an assistant that can't buy where you actually shop is a demo, not a habit.

Sam: And three is the one that keeps me up.

Alex: Three: does the trust hold? The Confidential VM either ships verifiable and genuinely resets what you can expect from Meta — or it stays a testers-only promise while the ad machine quietly eats everything around it.

Sam: So let me try to say the whole thing in one breath. Meta didn't launch a shopping app. It made a bid to become the front gate of commerce — and it absolutely has the distribution to win that spot.

Alex: It has the distribution to win the front gate. Whether it deserves to stand there is the question the next two months answer. That's the tension in the whole thing — the best-resourced player, the strongest privacy engineering, and the worst trust record, all in the same launch.

Sam: And here's what I'm walking away with: the friendliest-looking product of the year is actually the sharpest strategic move of the year. The errand-runner is a Trojan horse, and it's a really nicely built one.

Alex: Beautifully built. That's the whole trick — the tollbooth had to look like a concierge, or nobody would walk through it.

Sam: So the quick recap, before we let you go. Muse looks like an errand-runner but it's really a bid to own the front door of shopping — the moment you decide what to buy. The real prize isn't the subscription, it's retail media, a sixty-nine-billion-dollar toll that an agent choosing your three options is perfectly built to collect.

Alex: The field's split between open coalitions — Google, OpenAI, the card networks — and walled gardens like Amazon, which blocks every rival agent because its page earns more than its sales. And the privacy story is genuinely two true things at once: the most serious encryption an agent maker has shipped, from a company that lost a jury verdict for misleading people the same month.

Sam: Three things to carry out the door: the front door of commerce is moving inside the agent; whoever owns that agent owns the toll; and the next real test is December, when Meta's best privacy promise and its most invasive ad policy land in the exact same week.

Alex: And honestly, that's the feeling I hope you leave with — a clearer view of where this is all heading. It's a genuinely fast, murky, high-stakes picture, and that's exactly what makes it worth following closely rather than glancing at once a quarter.

Sam: One honest note on how this show is made: it's AI-generated. Dan builds a custom stack of AI tools to research, analyse, verify and illustrate the questions actually worth understanding — mostly to learn them himself — and publishes it for anyone who wants to follow along. AI-assisted, fact-checked, and always worth a second look.

Alex: Before you go, one genuinely useful thing you can do: follow the show. Whatever app you're listening in right now, there's a follow or a plus button — one tap, it's free, and it does two things. You get every new episode the moment it lands, and for a small independent show like this one, a follow is honestly the single biggest lever there is for helping it reach other people trying to make sense of all this.

Sam: And one last thing on your way out. If there's someone in your life who keeps asking where AI is actually heading, send them this episode — genuinely one of the kindest things you can do, for them and for us. It's still a small, independent show, and every share does more than you'd think.

Alex: We'll see you next time — thanks so much for listening.