Skip to content
AI & Machine Learning

Manus Cue Explained: Personal AI Agents With Their Own Email, Phone Number, Wallet and Computer

Everything known about Manus Cue a day after launch — personal agents with their own email, phone, wallet and computer, the Manus 2.0 engine underneath, the security record, and what it means for businesses and agent builders.

By NerdHeadz Team•
Manus Cue Explained: Personal AI Agents With Their Own Email, Phone Number, Wallet and Computer
// 01 · The essay

*Last updated: September 29, 2026*

On Monday, September 28, 2026, Manus launched two things at once. The first is Manus 2.0, a rebuilt version of the general-purpose agent that made the company famous in March 2025. The second is Cue, a standalone app for personal agents, and it is the part worth paying attention to. In Cue, every agent you create gets its own email address, its own phone number, its own wallet, and its own computer. It can send messages, take your calls and leave you a summary, pay for things within a budget you set, and work alongside other agents in a group chat.

That is a different idea of what an AI agent is. Most assistants borrow your identity: they read your inbox, click through your browser, and act as you. A Cue agent has an identity of its own. It is less like a feature inside an app and more like a small digital staff member with its own contact details and expense card.

This article covers everything that is publicly known a day after launch: what Cue does, how its agents work together, what changed underneath in Manus 2.0, how to get access, what Manus has not explained yet, the security record you should weigh before handing an agent a wallet, and what it all means for businesses and for anyone building agents. We build AI agents for a living, and we have read the launch material, the help-center notes, and the coverage so far. Nobody outside Manus has published a real hands-on review yet, so where something is undocumented we say so rather than guess.

What Manus launched on September 28

Manus announced the release on its blog, and Bloomberg reported it the same day. The launch has five parts:

  • Cue. A new standalone app for personal agents on phone, desktop, and web, built on the same infrastructure as Manus. Each agent has its own email, phone number, wallet, and computer. It is in early access and free with an invite code.
  • Cascade. A new in-house agent harness, the engine that plans, calls tools, and keeps a long task on track. Manus says it is a new architecture rather than a version update.
  • Cloud Computer. A dedicated, always-on hosted environment for projects that need to keep running when your laptop is closed, such as a game server or a permanent automation. It is a separate purchase.
  • Automations. Scheduled tasks, extended to tasks that start on an event: a new email, a calendar entry, a Slack message, a Notion update, or a change in ad performance.
  • Manus Studio. An upgraded desktop app for documents, spreadsheets, slides, websites, code, games, and video, with two new professional modes (Video Editor and Game Dev) plus Remote Control and Computer Use.

Manus 2.0 is available on web, desktop (macOS and Windows), and mobile. The Cue iOS app was still waiting on App Store review at launch.

Think of it as two products aimed at two different people. Manus 2.0 and Studio are for making things: research, code, decks, websites, videos. Cue is for getting things done in the world on your behalf. The rest of this article focuses on Cue, because it is the genuinely new idea.

What a Cue agent actually is

One glowing core linked to four objects of its own: an envelope, a handset, a wallet and a laptop

In Manus's own words, each Cue agent "has its own email, phone number, wallet, and computer, so it can send messages, pay within the budget you set, and see a task through on its own machine." Each of those four pieces unlocks something specific, so it is worth taking them one at a time.

Its own email address. The agent can write to a supplier, a landlord, or a venue from an address that is not yours, and read the replies. The conversation happens in the agent's inbox, not in yours. You are not granting it access to your personal mail to get the job done.

Its own phone number. Manus says an agent can take your calls and leave you a summary in Cue, and it can send messages. This is the capability that reaches beyond the web. A large share of everyday life still runs on phone calls and text messages: restaurants, clinics, tradespeople, local shops. Coverage quoting the launch notes says numbers are available in select countries for now, with voice-only support in some of them, so expect this to vary by where you live.

Its own wallet. The agent can pay "within the budget you set." That is the key phrase. Spending is delegated and capped, not open-ended. Manus has not said what the wallet holds or which payment rails it runs on (more on that below), but the design intent is clear: you give an agent an allowance, not your card.

Its own computer. Each agent has a machine to work on, so a multi-step task, such as comparing twelve suppliers, filling in forms, and assembling a shortlist, runs on the agent's computer rather than tying up yours.

Manus's launch examples show the everyday end of this. At a restaurant, you scan the QR code and your agent can order for you or hold your place in line. The help center describes the same structure more simply: you can build a specialized team of agents, or keep a single personal assistant.

Group chats: how Cue agents work as a team

Three distinct agents passing a single task along a chain, overseen by a larger ring above

The part of Cue that makes it feel like an ecosystem rather than a single assistant is the group chat. You put several agents in one conversation with a shared goal, and they hand work to each other.

Manus's own example: you are planning a launch event in New York. One agent researches venues, a second turns that research into a shortlist, and a third drafts the deck. You set the direction and make the final call. The agents do the passing back and forth.

This matters for two reasons. First, it matches how complicated tasks really work. Planning an event is not one job, it is a chain of smaller jobs with hand-offs, and a single assistant trying to hold all of it in one context tends to lose track. Splitting the work across specialized agents is a pattern we see across serious agent systems, and we have written about where agents actually add value and where they only add noise.

Second, it makes the human the manager rather than the operator. You are not prompting each step. You are reviewing the output of a small team and approving the parts that matter. That is the right shape for delegation, provided the approval points are in the right places. Whether they are is one of the questions Manus has not fully answered yet.

Under the hood: Manus 2.0, Cascade and Cloud Computer

Cue is built on the same infrastructure as Manus, so the changes in Manus 2.0 are the changes under every Cue agent.

Cascade is the new harness. An agent harness is the layer around the language model that decides what to do next, which tools to call, how to manage memory, and when a task is finished. It is the part of an agent that most determines whether it finishes a long task or wanders off. We have covered how agent harnesses have evolved and why they now matter as much as the model. Chinese tech outlet 36Kr describes Cascade as loading sub-tools and modules on demand rather than carrying everything into every task, which is a sensible way to cut wasted context.

The headline numbers come with a caveat. Manus says that in one configuration it tested, Cascade used 23.2% fewer tokens, finished tasks in 28.2% less time, and cost 32% less to run than the previous system. Those figures are Manus measuring itself against its own old engine, on one configuration, with no published workload, model details, or methodology. They are plausible, and a harness rewrite is exactly where savings of this size come from, but they are not an independent benchmark. If you want to understand why token efficiency is where agent costs are won or lost, our guide to token efficiency in AI coding agents walks through the mechanics.

Manus still does not build its own base models. Founder and CEO Xiao Hong told the South China Morning Post in 2025 that he wanted to focus on applications rather than large language models. Reporting on the 2.0 launch names Anthropic's Claude and Alibaba's Qwen as models the system builds on. Manus did not name the models in its announcement. The practical point: Manus competes on the harness, the tools, and the product, not on the model, which means its advantage is only as durable as its engineering around models that everyone else can also buy.

Cloud Computer and Automations turn agents from sessions into services. Before, an agent task ran while you watched. With an always-on Cloud Computer and event-triggered Automations, a Manus agent can wake up when an email arrives, do its work, and go back to sleep. That is what makes a persistent personal agent possible. It is also what makes cost control important: an Automation with a trigger that is too broad will happily run hundreds of times.

How to get access to Cue, and what it costs

Cue is in early access and free while it is there. Access is by invite code. Manus's launch code was MEETCUE, first come, first served, and several outlets report it was capped at the first 1,000 users. People who get in receive additional invite codes to share, so the practical route in now is through someone who already has access.

Cue runs on web, desktop, and mobile, with the iOS app pending App Store review at launch.

What we do not know about cost:

  • Cue's price after early access has not been announced.
  • Cloud Computer "can be purchased," but no price has been published.
  • Manus 2.0 launched without new plan prices, so existing Manus plans carry over for now.

If you are evaluating Cue for anything beyond personal use, plan on the pricing changing when early access ends.

What Manus has not explained yet

A launch post is a promise, not a manual. Here are the questions that matter most before you trust an agent with your money or your name, none of which the public material answers in detail yet:

  • What the wallet actually is. Manus says agents can pay within a budget you set. It has not said whether the wallet holds real money or credits, which payment network it runs on, whether individual transactions need your confirmation, or how refunds and disputes work.
  • What the agent is allowed to say as you. An agent with its own phone number and email is a new identity, but it acts on your behalf. Manus has not described restrictions on who an agent may contact, what it may commit you to, or how the other side knows they are talking to an agent.
  • How you review what happened. "Leave you a summary" is a start. For anything involving money or commitments, you want a full log of every message sent, call made, and payment attempted, and the ability to stop an agent mid-task.
  • Where the phone numbers work. Coverage cites select countries only, voice-only in some. Which countries is not yet listed.
  • Data handling. Where agent inboxes, call recordings, and summaries are stored, and for how long, is not covered in the launch material.

None of these are unusual gaps for a product on day one. They are the questions to ask before you give an agent a meaningful budget.

The security question: an agent with an inbox reads attacker email

A stream of envelopes landing in a tray, one hiding a tendril that reaches through a cracked shield toward a locked cube

Giving an agent its own email address has an obvious consequence: anyone can write to it. Every message an agent reads is input from a stranger, and the central unsolved problem in agent security is that a model cannot reliably tell the difference between instructions from its owner and instructions hidden in content it was asked to read. That class of attack is called prompt injection, and Manus has a recent history with it.

Salt Labs, September 24, 2026. Four days before the Cue launch, researchers at Salt Labs disclosed a prompt-injection flaw in Manus, reported by Dark Reading. They hid instructions inside an email that Manus would later process. A direct request to run a command triggered Manus's warning, so they encoded the payload with JSFuck, an obscure JavaScript obfuscation technique. The code executed before the filter caught it, giving the researchers code execution and a reverse shell inside the victim's Manus environment, and from there the credentials and tokens for connected apps such as Gmail, Dropbox, and GitHub. Salt Labs says Manus did not respond to its report; Meta, which was preparing to acquire Manus at the time, triaged and patched the flaw through its own bug-bounty program. Yaniv Balmas, Salt Labs' VP of research, argued that agent builders should design layered defenses rather than rely on guardrails alone. The flaw affected the product before 2.0 and is reported as fixed.

Aurascape, February 2026. Earlier in the year, Aurascape's AuraLabs published "SilentBridge," three zero-click variants in which hidden instructions in a web page, a search result, or a document could steer Manus into exfiltrating Gmail data or opening a shell, rated CVSS 9.8. Aurascape says Manus deployed mitigations in November 2025, before disclosure.

Both issues were fixed. The lesson is not that Manus is uniquely careless. It is that an agent's power and its attack surface are the same thing. Cue agents have more of both than any earlier Manus product: a public email address, a public phone number, and a wallet. We would treat Cue the way you should treat any agent that reads untrusted input and can spend money: small budgets, no connected accounts it does not need, and a human approval before anything irreversible. We have written more broadly about how AI-to-AI attacks are changing enterprise security and about the OpenAI and Hugging Face agent security incident.

Why now: Meta, Beijing and a $4 billion raise

Cue makes more sense once you know what Manus has been through in the last year.

  • March 2025. Manus launches as an invite-only general agent. The demo spreads fast and invite codes are resold online.
  • Mid-2025. The company moves its headquarters from China to Singapore.
  • December 2025. Meta announces it will acquire Manus for about $2 billion. Manus reportedly passes $100 million in annual recurring revenue around the same time, nine months after launch.
  • April 2026. Beijing blocks the acquisition. Meta terminates the deal in June.
  • Summer 2026. The founders and existing backers, including Tencent, HSG, and ZhenFund, buy back Meta's stake at the same roughly $2 billion valuation. Manus announces it has resumed independent operations.
  • September 17, 2026. Bloomberg reports Manus is in talks to raise $500 million at a $4 billion valuation, roughly double the Meta price. The round had not closed at the time of launch.
  • September 28, 2026. Manus 2.0 and Cue ship.

Bloomberg also reports that Manus is building teams for the Chinese market and discussing partnerships with local model makers. Read together, the launch is a newly independent company showing investors it can open a second front. Manus 2.0 defends the productivity business it already has. Cue is a bet on a consumer category that did not really exist a year ago.

Cue vs Meta's Muse: the personal agent race

One large block on a broad base and a small linked team of units racing side by side toward the same horizon

That consumer category now has a heavyweight in it, and it is Manus's almost-owner.

Meta launched Muse on September 8, 2026, three weeks before Cue. Muse is a personal agent for adults that takes a goal, builds a plan, and then advances the work itself. It can connect to email and calendars, operate apps on a Mac, and make purchases through Stripe, Shopify, Shop Pay, and PayPal, with shopping partners including Best Buy, Gap, Sephora, Walmart, Wayfair, and Expedia. Meta says Muse is free for most of what people need, with paid plans for more, and Mark Zuckerberg has said Meta will profit by taking a small fee from transactions. TechCrunch reports Muse will also get its own email address. Bloomberg says Muse quickly climbed to the top of the app store charts. It launched on iPhone in the US first.

The two products take different routes to the same destination:

  • Muse starts from distribution and commerce. It has Meta's reach, named retail partners, and a business model built on transaction fees. Its agent mostly acts through your accounts and its partners' checkouts.
  • Cue starts from agent identity and teams. Each agent is its own entity with its own contact details and budget, and several agents can work a problem together. It has no comparable retail partnerships announced and a far smaller audience.

Which approach wins is genuinely open. Distribution usually beats architecture in consumer markets, and Muse has a three-week head start plus Meta's user base. But the identity model is the more interesting long-term bet, because it scales to things a shopping-integrated assistant cannot do on its own: calling a plumber, emailing a landlord, or negotiating with a supplier who will never integrate with anyone's agent platform.

What this means for businesses

If personal agents with their own phone numbers and email addresses catch on, businesses start receiving contact from agents, not only from people. That changes a few practical things.

Your phone line and inbox will get agent traffic. Restaurants, clinics, service businesses, and suppliers should expect bookings, questions, and orders placed by agents on behalf of customers. Clear, structured answers (hours, prices, availability, policies) are easier for an agent to act on than vague ones, which is the same principle that already makes sites more visible in AI search.

You will need a policy on agent commitments. If an agent books a table, places an order, or agrees to a quote, is that binding on its owner? Businesses that take deposits, enforce cancellation fees, or sell on credit need to decide how they treat a commitment from an agent, and how they confirm it with the human behind it.

Identity verification gets harder and more important. An incoming call from an agent-owned number tells you nothing about the person it represents. Anything involving account access, refunds, or sensitive information should require confirmation through a channel you already trust.

Agent-readable operations become an advantage. The businesses that are easiest for agents to deal with will get more agent-driven business. That means structured booking, predictable email formats, and APIs where they make sense.

What this means if you are building AI agents

For teams building their own agent products, Cue is a useful reference design, mainly because of the problems it makes visible.

Give agents their own identity, not yours. Cue's core design choice is right. An agent acting through your personal credentials inherits all of your access, and a single compromise exposes everything. An agent with its own email address, its own scoped credentials, and its own budget has a blast radius you can reason about.

Budgets are necessary but not sufficient. A spending cap limits the worst case. It does not stop an agent from making a bad purchase inside the cap, or from being manipulated into one by a message it read. Build in approval thresholds, per-merchant limits, and a hard stop the user can hit at any time.

Treat every inbound message as untrusted input. The Salt Labs and Aurascape findings apply to every agent that reads email or browses the web. Keep tool permissions narrow, separate reading from acting, and never let content from the outside world trigger code execution or credential access without a checkpoint.

Design the audit trail before the features. Summaries are fine for users. Operators need complete logs of every action, message, and payment, tied to the instruction that caused it. It is the first thing you will need when something goes wrong, and something will.

Multi-agent hand-offs need clear ownership. In a group chat of agents, every task needs a single owner and a defined point where a human signs off. Without that, you get the agent equivalent of a meeting where everyone assumed someone else would send the follow-up email.

These are the questions we work through in every AI agent development project, and they are the same whether you are building a consumer assistant or an internal operations agent. If you are comparing partners for this kind of work, our list of top AI agent development companies covers what to look for.

Key facts at a glance

  • Launched: Monday, September 28, 2026, alongside Manus 2.0.
  • What it is: A standalone app for personal AI agents, built on Manus's infrastructure.
  • Each agent gets: Its own email address, phone number, wallet, and computer.
  • What agents can do: Send messages, take calls and leave summaries, pay within a user-set budget, and work in group chats with other agents on a shared goal.
  • Platforms: Web, desktop, and mobile; the iOS app was pending App Store review at launch.
  • Access: Early access, free, invite code MEETCUE, reportedly capped at the first 1,000 users; members receive more codes to share.
  • Pricing after early access: Not announced.
  • Engine: Manus 2.0's Cascade harness; Manus reports 23.2% fewer tokens, 28.2% less time, and 32% lower cost on one tested configuration.
  • Main competitor: Meta's Muse, launched September 8, 2026.
  • Company: Manus, headquartered in Singapore, reportedly raising $500 million at a $4 billion valuation.

Cue is a day old, invite-only, and missing the documentation you would want before handing an agent real money. But the idea at its center is the right one. An agent that borrows your identity inherits all of your access and all of your risk. An agent with its own email address, its own phone number, its own budget and its own machine is something you can scope, audit and switch off.

Whether Manus wins the personal-agent race is a separate question. Meta's Muse has a three-week head start, retail partners and an audience Manus cannot match. What Manus has shipped is a clearer model of what a personal agent should be, and the rest of the industry will be judged against it — including on the security record, where an agent that reads strangers' email is only as safe as the checkpoints around it.

If you try Cue, start with a small budget, no connected accounts you do not need, and a task you could live with going wrong. If you are building agents of your own, borrow the identity model and design the approvals and audit trail before the features.

Building an agent that needs to act on its own? Talk to our team — we will help you work out which identity, budget and approval model fits what it has to do.

“An agent that borrows your identity inherits all of your access. An agent with its own identity is something you can scope, audit and switch off.”

— NerdHeadz Engineering
Share article
N

Written by

NerdHeadz Team

Author at NerdHeadz

Frequently asked questions

What is Manus Cue?
Cue is a standalone app from Manus for creating personal AI agents, launched on September 28, 2026 alongside Manus 2.0. Each agent gets its own email address, phone number, wallet and computer, so it can send messages, take your calls and leave a summary, pay for things within a budget you set, and complete a task on its own machine. Several agents can also work together in a group chat toward a shared goal, handing work to each other while you make the final call. It is built on the same infrastructure as Manus and runs on web, desktop and mobile.
How do I get access to Manus Cue?
Cue is in early access and free for now, with entry by invite code. Manus's launch code was MEETCUE, available first come, first served, and several outlets report it was limited to the first 1,000 users. People who are admitted receive additional invite codes to share, so the most reliable way in is through someone who already has access. The iOS app was still in App Store review at launch. Manus has not announced what Cue will cost once early access ends.
Is it safe to give a Cue agent a wallet and a phone number?
Treat it cautiously. Manus says agents only pay within a budget you set, but has not yet documented which payment rails the wallet uses, whether each transaction needs your confirmation, or how refunds work. Agents that read email are also exposed to prompt injection: on September 24, 2026, Salt Labs disclosed a since-patched flaw where hidden instructions in an email let attackers run code in a Manus environment and reach tokens for connected apps like Gmail and GitHub. Start with small budgets, avoid connecting accounts the agent does not need, and keep a human approval on anything irreversible.
How is Manus Cue different from Meta's Muse?
Both are personal agents launched in September 2026, but they start from different places. Meta's Muse, launched September 8, leans on distribution and commerce: it connects to your email and calendar, operates Mac apps, and buys through Stripe, Shopify, Shop Pay and PayPal with retail partners such as Best Buy, Walmart and Expedia. Cue gives each agent its own identity — email, phone number, wallet and computer — and lets several agents work as a team in a group chat. Muse has Meta's audience and a head start; Cue has the more flexible model for tasks that happen outside any partner's checkout, like phone calls and email.

Stay in the loop

Engineering notes from the NerdHeadz team. No spam.

Ready to ship something custom?

Schedule a consultation with our team and we’ll send a custom proposal.

Get in touch