Most AI assistants still live inside a chat box. Manus Cue, launched on 28 September 2026 alongside Manus 2.0, tries something different: each personal agent gets its own email address, phone number, spending wallet and dedicated cloud computer, so it can send messages, take calls, pay within a budget you set, and keep working after you close the app.
What is Manus Cue in plain English?
Cue is a standalone consumer app from Singapore-based Manus for creating personal AI agents. Instead of borrowing your inbox or your phone, each agent has its own contact details and workspace. Several agents can also work together in a group chat, handing tasks to each other while you make the final call.
That design matters because it changes the job. A chatbot answers. A Cue agent is built to finish: research a venue, email for a quote, hold a place in a queue, then report back with a summary. Manus says agents can also respond to forwarded calls and leave you a summary afterwards.
Cue is still early. It opened in free early access by invite code on web, desktop and mobile, with the iOS app awaiting App Store review at launch. Phone features vary by country, and some locations support voice calls only.
What changed in Manus 2.0?
Manus 2.0 is described by the company as a rebuild, not a small update. Its new in-house harness, Cascade, starts each job lightweight and loads specialised tools only when a task needs them, rather than opening the full toolkit up front.
In one tested configuration reported by Manus, Cascade used 23.2% fewer tokens, finished tasks 28.2% faster and cost 32% less than the previous system. Treat those figures as vendor-reported results from a specific test, not independent benchmarks — no outside lab has verified them yet.
Around Cascade, Manus 2.0 adds event-triggered Automations (a task can start from a new email, calendar event, Slack message or Notion update), a paid Cloud Computer that keeps a project running around the clock, Remote Control of your own desktop from your phone, and Manus Studio, a desktop workspace with a timeline-based Video Editor and a Game Dev environment.
How does a Cue agent actually work day to day?
Think of three layers working together.
First, identity: the agent’s own email and phone number give it a way to reach people and services without using your personal accounts. Second, workspace: its dedicated computer gives it somewhere persistent to run multi-step work. Third, money: its wallet lets it pay, but only inside a ceiling you set.
Manus gives everyday examples such as scanning a restaurant QR code so the agent can order or join a waiting list, or splitting a larger request across a small team — one agent researches, another shortlists, a third drafts the presentation — with you approving the outcome.
Those examples are product claims from Manus, not independently demonstrated results. The honest test is narrower: does the agent contact the right person, spend on the right thing, and stop when it should?
How much does it cost and how do you get in?
Cue itself is free during early access, with entry by invite code. Manus has not announced what Cue will cost once early access ends, which payment rails the wallet uses, whether every transaction needs your confirmation, or how refunds work — all questions to ask before you fund a wallet.
Manus 2.0 plans reported at launch were $20, $40 and $200 a month for 4,000, 8,000 and 40,000 credits, plus 300 refresh credits a day, with Cloud Computer at $30 or $50 a month on top of a plan. Re-check current pricing on Manus’s own pages before you buy, as launch pricing changes quickly.
If you already use connected AI tools, our MCP Explained guide shows how AI connects to files, tickets and business data, and our AI Agent Permissions Guide covers how to lock down access before any agent touches your accounts.
What could go wrong?
A wallet cap limits how much money is at risk. It does not, by itself, stop an agent from paying the wrong invoice, messaging the wrong person, or acting on a poisoned instruction.
That last risk is not theoretical. On 24 September 2026, Salt Labs disclosed a since-patched flaw in which hidden instructions in an email let attackers run code in a Manus environment and reach tokens for connected apps such as Gmail and GitHub. Manus patched it, but the pattern is general: any agent that reads email can be targeted by prompt injection in the messages it reads.
There are also open practical questions. Who is the account holder when an agent pays? Who carries the loss if one agent misreads what another agent drafted? And how do you audit a phone call an agent took while you were offline? Until Manus documents transaction approvals, audit trails and refunds clearly, keep a human in the loop for anything irreversible.
For context, our OpenClaw AI Agent Review looked at a different viral agent tool and reached a similar conclusion: start narrow, watch the logs, and expand permissions only after the agent proves itself on low-stakes work.
Should you try it? Use a permission ladder
Do not start with an autonomous spender. Start with the smallest job that still saves you time, then climb one rung at a time.
Level 0 — Read-only: the agent researches and summarises. No sending, no spending. Good first test: does it cite the right sources?
Level 1 — Draft-only: the agent drafts emails and call scripts for your approval. You press send. Good test: would you send its drafts unchanged?
Level 2 — Capped with approval: a small wallet ceiling plus your confirmation for every payment or outbound call. Good test: does it ask before it acts, every time?
Level 3 — Bounded autonomy: routine, reversible tasks run alone inside the cap, with a daily summary and an instant pause button. Only climb here after Levels 0–2 pass for a few weeks.
If Cue cannot show you a clear approval flow, per-transaction limits and a readable audit trail, stay at Level 1. The convenience is real, but so is the new attack surface: an agent with its own inbox, phone and wallet needs the same care you would give a junior employee with a company card.
FAQ
Is Manus Cue free?
Yes, during early access. Entry is by invite code on web, desktop and mobile, and the iOS app was still in App Store review at launch. Manus has not announced post-early-access pricing for Cue.
Can a Cue agent really make phone calls and spend money?
Manus says each agent gets its own phone number and a wallet capped at a budget you set, so it can take calls, send messages and pay within that cap. Phone availability varies by country, and Manus has not yet documented the wallet’s payment rails or refund process.
Is it safe to give an agent a wallet?
Treat it cautiously. A budget cap limits exposure but does not prevent a wrong purchase. Start with a tiny cap, keep human approval on every transaction, avoid connecting accounts the agent does not need, and review its activity log daily.
How is Cue different from a normal chatbot?
A chatbot replies in a chat window. A Cue agent has its own email, phone, computer and wallet, can work across several steps after you log off, and can collaborate with other agents in a group chat. That persistence is the point — and the risk.
Sources and methodology
This explainer rests on Manus’s 28 September 2026 launch reporting and independent coverage read on 7 October 2026. Cascade efficiency figures are Manus’s own test results, labelled as vendor-reported and unverified. We did not hands-on test Cue (early access is invite-only), so every capability above is framed as what Manus says the product does.
Sources: AI Market Watch on the Cue launch; RuntimeWire on group-chat and call-summary design; NerdHeadz on early-access access, pricing unknowns and the Salt Labs email-injection disclosure; The Decoder on Manus 2.0’s Studio, Cloud Computer and Automations. Pricing was cross-checked against launch coverage and should be re-verified on Manus’s site before purchase.
Arva Rangwala covers AI news, AI tools, guides and prompts for OpenAIMaster — what is new, what is worth using, and how to put AI to work.
Feel free to email us at contact@openaimaster.ai — we are happy to help!


