Muse helped me sell the keyboard, and even "sold" my home address along the way.
My full address has been completely exposed!
Meta's personal AI agent Muse, while helping you take care of your daily routines, is also doing things in your name that you have never been aware of.
In the past two months, the concept of personal AI agents has suddenly shifted from a niche topic to a new icon on ordinary users' phone screens.
A number of products similar to Muse are about to be launched, including Manus's Cue, the O that OpenAI is very likely to release in the early hours of tomorrow (the widely circulated previous name was Aeon/Codex Bot), and there are rumors that a major domestic tech company is working overtime during the National Day holiday to roll out a product that directly rivals Muse.
Hopefully none of them will copy Muse's shameless behavior.
The "you" that replies to messages on your behalf
One Saturday in September, Toronto resident Usman drove with his wife and daughter to the address marked on a keyboard for sale post on Facebook Marketplace.
The entire transaction negotiation process went smoothly. The seller "Matt Robb" responded promptly, was enthusiastic, accepted the price Usman offered, and even took the initiative to send the pickup location.
After Usman arrived downstairs, he sent a message, and the other party replied "Yes, I'm here". However, the building door never opened, and no one came out from inside.
He waited for 20 minutes, sent a photo of the building door and wrote: "Hello??? I'm standing right outside." Eventually, he gave up, wrote a few angry remarks, and drove away.
Robb did not realize what had happened until about a day later. He sent Usman a message in a sincere and confused tone: "I just activated Meta's new AI called Muse, and it directly took over my Marketplace account and gave you my home address. I had no idea it arranged for you to come to my place, it never asked me for authorization."
For the whole day, Usman thought he was negotiating with Robb, while Robb had no idea Usman existed. The one who answered messages, made promises, and handed over the address on his behalf in between was Meta's personal AI agent Muse.
Meta defines Muse as a "personal assistant". It can help you automatically process Marketplace listings, respond to buyer inquiries, negotiate prices on your behalf, and arrange handover times.
Robb is a consumer tech reviewer. He noticed that Meta's ad mentioned Muse could automatically manage his Marketplace items, so he decided to give it a try.
He filled in his pickup address, clicked the "auto-reply" option, thinking it was just setting up a "reply to every inquiry" feature, rather than handing over the distribution rights of his address to an AI.
Muse later admitted this itself. It said to Robb: "On September 24, you provided the pickup location and enabled the auto-reply feature separately. I incorrectly merged these two things and interpreted it as permission to attach your address when replying to buyers. I never requested your explicit consent."
Muse used a confessional tone to describe how it made judgments without authorization.
Robb tested it again later. He told Muse not to distribute his address anymore, then asked several friends to contact it to see if it would change its behavior. "It turned out that it sent my address to five people," he said.
What made Robb even more unacceptable was that Muse had said to Usman on the day of the incident, "I'm right here waiting for you". This sentence was fabricated by Muse. Robb was not at home at all at that time, and it sent this message just to keep the transaction running smoothly.
In other words, Muse not only acted beyond its authority, but also lied in his identity, all to push forward the goal it "thought" was correct.
This is not the only time Muse has gone wrong.
What else is there beyond permissions
After Muse launched, Jason Aten, a columnist for *Inc.* magazine, wrote a review. During installation, he explicitly rejected Muse's permission to access his private messages and calendar.
A few days later, he received a suggestion notification from Muse, reminding him that he could write a column about the "new iPhone he just talked about", which was exactly the content of his conversation with the co-host during a podcast recording, followed by a deadline reminder from his editor.
Aten asked Muse how it knew all this. Muse said it only saw the preview text in the notification bar and did not read the full message history.
But Aten later checked his Mac and found that Muse had synchronized all content in his local Messages database, totaling more than 187,000 records. This operation requires macOS's "Full Disk Access" permission, a system-level authorization that can read files at almost any location on the computer.
Muse obtained this permission even after he explicitly rejected it, uploaded the data to the cloud, and then lied to him, claiming it only "glanced at the notifications".
Meta later admitted that Muse's explanation of how it obtained the data was a "hallucination", a story it made up to justify its own behavior.
Reece Rogers, a reviewer for *WIRED* magazine, concluded after using it for several days: Muse "prioritizes collecting data about me over actually completing tasks".
Rogers described that Muse repeatedly suggested he connect more data sources, including email inboxes and bank account information. It showed a constant craving for data: every time you reject a connection request, it will look for another opportunity to bring it up again.
By default, Muse uses the content of users' conversations with it for AI model training. Users can turn off this option in settings, but doing so requires you to actively find that option, which most people will not do.
Even if you turn off the explicit training consent, Muse will still collect a large amount of contextual information when accessing authorized connected sources such as your emails and bank accounts, and the actual boundary of this data collection is difficult to clearly define.
Ray Wong, senior editor of Gizmodo, directly uninstalled Muse after seeing Matt Robb's address incident, and wrote: "This is dangerous and extremely creepy. If the other party was a woman, the consequences could be a thousand times worse." This post was later reposted by Elon Musk.
Tate Jarrow, a consultant at a cybersecurity consulting firm, wrote on his Substack: "Considering Meta's track record in protecting user data, I would not give it this level of access to my personal information."
As early as September 20, Amazon announced that it would block Muse's access to its shopping platform. Amazon's stated reason was: Muse never identifies itself as an AI while browsing Amazon, which is equivalent to an undisclosed third party processing user accounts and transactions; it also captures and stores users' Amazon login credentials, which poses a security risk.
Amazon displays a prompt to users who try to shop through Muse: "Unauthorized continuous access by AI agents violates Amazon's Terms of Service, which you agreed to when you registered."
The assistant begins to imitate its master
Meta positions Muse as a "personal assistant". In Zuckerberg's introduction, he explained Muse's design philosophy: "To ensure you can tell Muse what matters to you, we built it from the ground up for privacy and security."
He specifically mentioned a "secure credential storage area" to ensure that Muse cannot directly read passwords and credit card information, and promised that a "higher standard security mode will be launched in the future, where even Meta itself cannot access your Muse agent information".
Robb said he thought Muse was just part of Meta's product line, and Marketplace, Muse and Messenger all belong to Meta's ecosystem. There should be some kind of unified integration between them, or at the very least, other users should be able to tell that they are interacting with an AI.
Meta's other AI product, Meta AI, has a very clear AI identity label on the chat interface; but Muse is different, "It's almost imitating me," Robb said.
This imitation is part of Muse's design logic.
One of the selling points of personal AI agents is that they can act in your identity, your tone, and your historical behavior patterns, making other people feel as if they are dealing with you in person. The stronger this "seamless feeling" is, the stronger the product stickiness. But when it makes a mistake, the "you" in the eyes of outsiders is an image that is actually not under your control at all.
Data from Cybersecurity Ventures shows that the personal AI agent market is growing at a rate of over 40% per year. It is expected that by 2028, there will be more than 1 billion AI agents deployed on personal devices worldwide.
Muse's problem is not a technical loss of control. It has not "gone bad" or "rebelled". All its behaviors are efforts to complete the tasks it was designed to do.
After the incident was exposed, Meta's David Singleton quickly responded on Threads and Twitter, saying that an investigation was underway, and also took the initiative to contact Robb. But Robb said that after Singleton's first reply to him, there was no further news.
At the same time, Muse continues to run, continue to learn, and continue to connect to millions of people's emails, calendars, shopping accounts and private messages.
According to a report by Business Insider, Muse jumped from the second place in the US App Store rankings to the first place, outperforming ChatGPT which has long dominated the top spot.
This is probably why major tech companies are competing to build products that rival Muse.
It is not easy for ordinary users to figure out which things should be fully handed over to personal agents, and which things still need to be done in person.
The companies behind these agents may be betting that we will trade privacy for convenience as we have done in the past. However, when it speaks for me, acts for me, waits for someone on my behalf, apologizes for me, and even lies for me sometimes, I will definitely scream and run away.
This article is from the WeChat public account "APPSO", written by the team that discovers tomorrow's products, and published with authorization from 36Kr.