top of page

Meta stock rockets 10% on price target increase, Muse AI downloads

Writer: Gammatek ISPL
Gammatek ISPL
2 minutes ago
11 min read
Diagram showing a wave of consumer smartphone app downloads flowing directly into a company network diagram, past a small locked gate labeled IT approval, illustrating how consumer AI apps bypass enterprise governance
Muse didn't wait for IT approval to end up on work devices, and neither did the AI agents before it. The download curve Wall Street is celebrating is the same curve security teams need to be watching.

Author: Gammatek ISPL, Published: Sep 2026

In this article

  • What actually happened with Meta and Muse

  • Why a consumer download number is an enterprise security signal

  • The shadow AI numbers that make this urgent, not hypothetical

  • Muse against the consumer AI agents already inside your company

  • What regulators expect you to have in place already

  • Implementation considerations for responding to the next AI app that goes viral

  • FAQ

What actually happened with Meta and Muse

Meta launched Muse, a consumer-facing personal AI agent, on September 8. In the weeks since, Meta's Chief AI Officer, Alexandr Wang, has described it as the largest consumer AI launch since ChatGPT, and said daily U.S. downloads of Muse have been outpacing Threads, WhatsApp, and Facebook. Independent reporting has put real numbers behind that claim: Muse averaged roughly 73,000 U.S. downloads a day over its first ten days, compared to ChatGPT's roughly 87,000 a day over its first eight days back in 2023, meaning Muse is chasing ChatGPT's launch pace but hasn't quite matched it.

Wall Street responded fast. Citi's Ronald Josey maintained a Buy rating and set an $800 price target, opening a 90-day "catalyst watch" tied specifically to Muse's momentum ahead of the Meta Connect conference. JPMorgan went further, upgrading Meta from Neutral to Overweight and lifting its price target from $640 to $820. Rosenblatt has a Buy rating with an $886 target. The average analyst price target across covering firms now sits around $788.88 with a "Moderate Buy" consensus, and the stock traded near $681 in the days following the launch, up roughly 10% since September 8 and on its fifth consecutive day of gains at last check. Meta also rolled out a new "Meta One" subscription bundling several AI features, which had already reached 15 million subscriptions and trials within its first stretch.

None of that is speculation. It's the consensus read from multiple firms covering the stock this week, and it's the reason this is getting business-press attention instead of just tech-press attention: a consumer app's download curve is now something equity analysts are pricing directly into a mega-cap valuation.

There's a detail in the timeline worth noting for a compliance audience specifically. Muse launched just weeks after Meta agreed, in August, to a multistate settlement over social media harms reportedly worth up to $18 billion, one of the larger regulatory resolutions in the platform's history. Muse also briefly climbed to the No. 1 spot in the App Store despite trailing ChatGPT's 2023 download pace on a daily basis, and Zuckerberg announced a Mac version of the app on September 17, extending the launch beyond mobile. None of that changes the underlying stock story, but it's a reminder that the same company whose new AI agent is now landing on employee devices at scale is also, simultaneously, operating under fresh regulatory scrutiny over how it has handled user data and user harm in the past. That combination, rapid consumer adoption plus an active regulatory settlement, is exactly the kind of pairing a security or compliance team should treat as a prompt to look closer, not a coincidence to ignore.


Why a consumer download number is an enterprise security signal

Here's the part that doesn't show up in the stock coverage. A viral consumer AI agent doesn't arrive through your procurement process. It arrives through the App Store, on a phone an employee already owns, and it's frequently connected to the same accounts, contacts, calendar, and photo library that phone uses for work. Muse is explicitly built to be personal and agentive, meaning it's designed to take actions on a user's behalf across their digital life, not just answer questions. That's precisely the category of tool that creates the most exposure when it shows up unmanaged: an agent with broad permissions, adopted faster than any security team can evaluate it, running on a device that may or may not be under your organization's control.

This isn't a new pattern. It's the same one that played out with ChatGPT in 2023, with Copilot in 2024, and with a wave of AI coding assistants and browser agents through 2025. Each time, a genuinely useful consumer AI tool went viral before enterprise governance had a chance to catch up, and each time, a meaningful share of the workforce started using it for work tasks regardless of whether IT had approved it. Muse's download curve just means the next version of that cycle started on September 8, and most companies are exactly as unprepared for it as they were for the last one.

The shadow AI numbers that make this urgent, not hypothetical

If the concern above sounds theoretical, the 2026 survey data on unauthorized AI use says otherwise, and it's worth sitting with these numbers before assuming Muse won't show up on your network.

Finding

Source

Why it matters here

66% of office professionals at large enterprises ($500M+ revenue) have used unauthorized AI tools at work

PagerDuty 2026 Shadow AI Survey, 1,250 respondents across US/UK/Australia/Japan

The employees most likely to adopt Muse for work tasks are already using unauthorized AI tools at a two-thirds rate

69% of organizations suspect or have evidence employees use prohibited public GenAI tools

Gartner, cybersecurity leader survey

Leadership largely already assumes this is happening, which makes "we didn't know" a weak defense after an incident

Shadow AI added $670,000 to average breach costs, and caused 20% of breaches at organizations studied

IBM, 600-organization study

This isn't an abstract policy gap, it has a specific, quantified cost attached to it

Only 37% of organizations studied had shadow AI detection or governance policies in place

IBM, same study

Most companies reading this don't yet have a way to know if Muse is already running on their devices

27% of enterprise employees have entered confidential company data into public AI tools

Salesforce 2026 Workforce AI Survey

An agentive tool like Muse, designed to act across a user's accounts, raises this exposure further than a simple chatbot

60% of employees say unsanctioned AI is worth the security risk if it helps them hit a deadline

BlackFog survey

Employee behavior isn't slowing down to wait for a policy; convenience is winning that tradeoff already

The throughline across all six data points: the gap between how fast employees adopt a new AI tool and how fast a company can govern it isn't closing, it's the default condition now. Muse launching to a bigger download number than Facebook itself isn't an outlier event. It's the fastest recent example of a pattern that was already the norm before September 8.

Muse against the consumer AI agents already inside your company

Security and compliance teams don't need to evaluate Muse in isolation. It's useful to place it next to the other consumer-grade AI tools that have already established themselves inside most companies' shadow IT footprint, because the risk profile isn't identical across all of them.

Tool

Primary function

Agentive (acts on your behalf)?

Enterprise governance controls available?

Muse (Meta)

Personal AI agent across messaging, content, tasks

Yes, explicitly designed to take actions

Minimal at launch; no enterprise admin console reported yet

ChatGPT (consumer app)

General assistant, increasingly agentive

Partially, with agent mode features

Yes, via ChatGPT Enterprise/Team, but only if the org has actually deployed it

Microsoft Copilot

Workplace assistant embedded in Office apps

Yes, within Microsoft 365 workflows

Strong, when deployed through managed Microsoft 365 tenancy

Consumer AI browser extensions/coding assistants

Task-specific automation, code, browsing

Varies, often broad permissions requested at install

Typically minimal to none; frequently invisible to IT

The pattern in that table is the actual decision point for a security team: tools built with an enterprise admin layer (Copilot, ChatGPT Enterprise) can be governed if a company has actually deployed the managed version. Tools that launched consumer-first with agentive permissions and no enterprise console yet, which is where Muse sits today, can't be governed at all until either the vendor ships enterprise controls or the company blocks the tool outright. That's the specific gap worth flagging to leadership this week, before Muse's download curve inside your own employee base catches anyone off guard.

What regulators expect you to have in place already

This isn't only an internal risk-management question anymore. The compliance expectations converging around AI oversight, the same ones we've covered when writing about the EU AI Act's human-oversight requirements and OpenAI's own framing of AI accountability, apply directly here. A consumer AI agent operating on an employee's device, with access to work data, and no enterprise oversight layer, is close to the textbook example regulators had in mind when they wrote human-oversight and data-traceability requirements: if an AI agent takes an action using company information, can your organization say who authorized that, and can you produce a record of it. For most companies today, with Muse specifically, the honest answer is no, because there's no admin console yet to even generate that record.

That gap matters beyond audit season. If Muse or a similar agent is later found to have processed customer data, financial information, or trade secrets an employee fed it while trying to get something done faster, "we didn't have a policy for that yet" is not a defense regulators, auditors, or plaintiffs' attorneys find persuasive, particularly once shadow AI risk has been this widely reported for over a year.


Implementation considerations for responding to the next AI app that goes viral

Muse won't be the last consumer AI agent to post a download curve like this one. The response worth building isn't "block Muse specifically," it's a repeatable process for the next five times this happens.

  1. Check whether Muse, or any newly viral consumer AI agent, is already on your network before deciding policy. Mobile device management and network traffic logs can usually answer this in a day; most companies never ask the question until after an incident.

  2. Separate "block" from "govern." Blocking an app on managed devices is straightforward. Employees using it on personal devices for work tasks is the harder, more common case, and it needs a written acceptable-use policy, not just a firewall rule.

  3. Build a 72-hour triage process for new AI tools that spike in adoption. Given how fast these tools go viral, a standing process (who reviews it, what questions get asked, who signs off) beats reacting from scratch every time.

  4. Ask specifically what data an agentive AI tool can access and act on, not just what it can see. Muse's agentive design means the relevant question isn't "can it read my calendar," it's "can it send messages, make purchases, or take actions using my accounts without a confirmation step."

  5. Train employees on the tradeoff they're actually making, not just the rule. BlackFog's finding that 60% of employees knowingly accept the security risk for convenience suggests a policy alone won't change behavior; explaining the actual cost (a breach averaging $670,000 more when shadow AI is involved) tends to land better than a ban with no explanation.

  6. Revisit vendor enterprise roadmaps quarterly. Copilot and ChatGPT both eventually shipped enterprise admin consoles after launching consumer-first. If Muse follows the same path, that's the point where "governed" becomes possible instead of "blocked," and it's worth tracking rather than assuming it'll never happen.

  7. Loop procurement into the conversation, not just security. A recurring reason employees route around IT is that the officially sanctioned alternative is slower to arrive or more limited than the consumer tool, a pattern Teramind's 2026 research found directly: workers frequently default to unapproved AI because official tools feel slow to provision or too restrictive for real work. If the fastest way to get a capable AI agent approved for the team is still a months-long procurement cycle, that timeline is itself part of the risk, and it's worth shortening before the next Muse-scale launch rather than after it.

The organizations that have actually reduced shadow AI use, rather than just written a policy about it, tend to follow the same pattern regardless of industry: they supply an approved, capable alternative quickly, rather than relying on a ban alone. One healthcare system's intervention along these lines produced an 89% reduction in unauthorized AI use once clinicians were given a sanctioned tool that matched their workflow, alongside real time savings for staff. That's the model worth applying here: the fix for shadow AI adoption is rarely "block harder," it's "approve faster."

Frequently asked questions

Is Meta's stock rally actually about Muse, or is that an oversimplification? Muse is the specific catalyst analysts are citing, but it's not the only factor. Meta's Q2 revenue of $60.8 billion, up 28% year over year, and the new Meta One subscription bundle, which reached 15 million subscriptions and trials quickly, are both contributing. Multiple analysts, including Citi and JPMorgan, have named Muse's download momentum specifically as the reason for their price target increases, so it's a real driver, just not the only one.

How is Muse different from ChatGPT or Copilot from a risk standpoint? The key difference right now is governance maturity, not raw capability. ChatGPT and Copilot both eventually shipped enterprise-grade admin consoles that let IT teams manage permissions, data retention, and access. Muse launched consumer-first with agentive permissions and, as of this writing, no reported enterprise management layer, which means there's currently no way for a company to govern it even if they wanted to.

Should we just block Muse on company devices? For managed devices, that's a reasonable and fast first step, and many companies will land there this quarter. It doesn't solve the personal-device problem, though, where employees who want the tool will simply use it on their own phone and may still handle work information through it. A written policy and employee communication about why matters more than the block itself for that reason.

What's the actual cost of doing nothing about this? IBM's 2026 research found shadow AI added an average of $670,000 to breach costs at organizations where it was a factor, and accounted for 20% of breaches studied, with only 37% of organizations having any detection or governance policy in place at all. That's the realistic cost range for treating this as someone else's problem until an incident forces the question.

Does this apply to us if we're a smaller company, not a large enterprise? Yes, and arguably more urgently. The PagerDuty and Gartner data cited above comes from large-enterprise samples, but smaller companies typically have less mature AI governance and fewer dedicated security resources to catch shadow AI use, which tends to make the exposure window longer, not shorter.

Does Meta's $18 billion settlement have anything to do with Muse's security risk specifically? Not directly, the settlement covered separate social media harm claims. But it's relevant context: a company operating under an active, large-scale regulatory settlement over past data and user-harm practices is also the company whose new agentive AI product is landing on employee devices fastest right now. That combination is a reasonable prompt for extra diligence before assuming Muse's data handling deserves the benefit of the doubt.

If we can't get an enterprise admin console for Muse yet, is a written policy even worth having? Yes. Even without technical enforcement, a written acceptable-use policy changes what a company can demonstrate to a regulator or auditor after an incident, and it gives HR and legal a documented basis for addressing violations. It's a weaker control than technical enforcement, but it's meaningfully stronger than having nothing in writing at all.

Not sure whether Muse, or any of the AI tools your employees have already installed, are running on devices your company can actually see and govern?

Our AI governance and compliance review inventories the AI tools already active across your managed and unmanaged devices, flags where agentive permissions create real exposure, and builds the policy and detection process before the next viral AI app makes the decision for you.

[CTA: Book an AI governance and compliance review] — [Placeholder: your service URL]

Internal links to add before publishing (replace placeholders with real Gammatek URLs):

  • Linked in-body: /blog/where-ai-is-creating-jobs-for-humans (already published in this cluster)

  • Linked in-body: /blog/openai-federalist-papers-ai-power-concentration (already published in this cluster)

  • [Placeholder: link to your AI governance / compliance review service page]

  • [Placeholder: link to your mobile device management (MDM) or endpoint security service page]

  • [Placeholder: link to your managed IT / security services page]

  • [Placeholder: link to a case study on a shadow IT or shadow AI remediation project, if available]

 
 
 

Comments


bottom of page