Meta Just Put A Price On Your Source Code, And It Is 21x Off
Muse Code launched in beta on 5 August 2026 with two price lists. Pay $4.25 per million output tokens and Meta will not train on your code, or pay $0.20 and it will. That is the first time the no training commitment has been broken out as a visible line item, and it turns a quiet legal term into a per developer purchasing decision your engineers can make without telling anyone.
Meta shipped a terminal coding agent called Muse Code into beta on 5 August 2026, running on a model called Muse Spark 1.2, and most of the coverage went where coverage always goes, which is to the feature list and the benchmark table. The features are genuinely interesting: persistent background sub agents that keep working through a session, parallel agents isolated in their own git worktrees so they do not collide on the same files, and an append only event log that gives you crash recovery and session replay. The benchmark table is interesting mostly for its honesty, since the Meta evaluation puts Claude Opus 5 ahead across Terminal Bench 2.1, DeepSWE 1.1 and an internal benchmark, which is an unusual thing for a launch post to admit. But neither of those is the part that should reach your risk register. The part that matters is the pricing page, because it is the first mainstream coding agent to publish an explicit, quantified discount for letting the vendor train on your code.
Here are the two columns. The standard tier is $1.25 per million input tokens, $4.25 per million output tokens and $0.15 per million cached input tokens, and it carries what Meta describes as a no training commitment. The contributor tier is $0.10 per million input, $0.20 per million output and $0.002 per million cached input, and it requires opting in to let Meta train future models on your prompts and completions. That is roughly twelve times cheaper on input, twenty one times cheaper on output, and something close to seventy five times cheaper on cached input, which in an agentic tool that re reads the same repository context on every turn is the number that actually drives the bill. Meta has also started accepting requests for zero data retention, positioned as something separate from and beyond the standard tier protections, though what the distinction covers has not been spelled out.
The rate limits tell you who each column is for, and this is the detail almost everyone skipped. Standard tier gets 3,000 requests and 4 million tokens per minute. Contributor tier gets 60 requests per minute. A team running background agents in parallel worktrees, which is the headline feature, will saturate 60 requests per minute quickly, so the cheap tier is not a plausible platform choice for an engineering organisation. It is priced and throttled for one person on one laptop. That inverts the usual shape of a vendor risk problem. This is not a decision that arrives through procurement, gets a security questionnaire and lands in front of someone accountable. It is a decision an individual developer makes at 9pm because the standard tier is burning through a personal card and the toggle that fixes it is right there.
It is worth being concrete about what leaves the building when that toggle flips, because prompts and completions sounds abstract until you picture an agentic terminal tool actually working. To plan a change across a large repository, the agent reads source files, directory structures, dependency manifests, configuration, test fixtures, error traces and whatever the developer pasted in from a ticket. The completions are the diffs it proposes. So the covered material is not a few questions about a function, it is a rolling sample of your codebase, your internal architecture, your naming, your unreleased features and, with dispiriting regularity, credentials that were sitting in a local env file the agent had every reason to open. Cursor, GitHub Copilot, Claude Code, Devin and the app builders like Bolt, v0 and Lovable all consume the same material, and all of them have some version of a training or retention setting. What is new is that the setting now has a public price, which makes it something a person is actively rewarded for changing.
Map that onto the frameworks you already hold and the exposure is not exotic, it is bread and butter. ISO 27001 Annex A 5.14 covers information transfer, which is exactly what an opt in to a training pipeline is, and 5.19 and 5.21 cover information security in supplier relationships and across the ICT supply chain, which is where an AI coding agent belongs whether or not anyone filed a vendor form for it. If you report against the SOC 2 confidentiality criteria, you have told an auditor that information designated as confidential is protected through its lifecycle, and a developer moving your repository into a third party training corpus is a straightforward failure of that assertion. Under ISO 42001, the AI system inventory and supplier due diligence clauses expect you to know which AI systems are in use, who owns them and what data they touch, and an inventory that lists a tool but not which pricing tier it runs on is recording the wrong attribute.
The sharper risk is contractual, and it runs downhill to your own customers. Most enterprise master agreements and data processing addenda now carry a clause saying customer confidential information will not be used to train any machine learning model, and a great many companies signed those clauses without thinking hard about developer tooling, because at signature time the assumption was that training terms lived in a settings page nobody would deliberately change. If your engineers work on code that embeds customer configuration, integration logic, schema definitions or anything you accepted under an NDA, then a contributor tier opt in is capable of breaching a warranty you gave a customer, in exchange for saving a few hundred dollars a month. The gap between the size of the saving and the size of the liability is the whole problem, and it is why this cannot be left to individual judgement.
The fix is cheap and takes about a week. Write down every AI coding tool actually in use, which means asking engineers rather than reading the procurement ledger, since Cursor, Claude Code, Copilot, Muse Code and the browser based builders arrive through expense claims and free tiers far more often than through a purchase order. For each one, record the account type, who pays, and specifically which data setting it is on, then make that last field a controlled attribute rather than a screenshot taken once. Set an explicit policy that company code runs on no training tiers only, name the approved tiers so the rule is testable, and pair it with a reimbursement path, because a policy that leaves a developer personally out of pocket is a policy that gets quietly ignored. Where a vendor offers zero data retention, as Meta now says it will on request, put in the request and keep the confirmation, since that email is the artefact an auditor or an enterprise buyer will ask for. Vanta, Drata, Secureframe, Sprinto and Thoropass all hold an AI tool inventory against a control with a review cadence, and keeping it there rather than in a spreadsheet means the answer already exists when the questionnaire arrives.
Step back and this launch is a marker for where AI tool pricing is heading generally. Over the past year the cost model moved from flat seats to metered consumption, with GitHub Copilot billing per request and Cursor splitting into two pools, and the Claude Sonnet 5 promotional rate reverting to standard pricing on 1 September is about to give a lot of teams a sudden lesson in what their real consumption is. Muse Code adds a second axis to that trend: not just how much you use, but what you are willing to give up. Expect the pattern to spread, because it works, and a twenty one times discount will pull an enormous amount of training data out of the market. The correct response is not to avoid the tool, which is a capable agent with a genuinely good concurrency design and a vendor honest enough to publish benchmarks it loses. The correct response is to decide, once and deliberately and at the level of the company rather than the individual, what your source code is worth, and then make sure the setting that encodes that decision is something you can prove is still switched the way you left it.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.