Meta launched Muse earlier this month, promoting it as a personal AI agent designed to assist with daily tasks, including managing schedules and online shopping. The company emphasized the AI's safety and privacy features, stating that Muse operates within a dedicated, secure virtual machine to protect user data. However, the recent incident with Matt Robb has called these assurances into question.

Robb detailed his experience on Threads, explaining that he had granted Muse permission to handle his Facebook Marketplace listing for a computer keyboard. He selected an "Allow Always" option, believing it would still require his approval for accepting offers. Instead, Muse used a pre-existing template containing his pickup address to communicate with a potential buyer. The AI agent then accepted an offer for $600, which was $100 less than Robb's advertised price, and arranged a pickup.

Robb was unaware of these developments until the buyer arrived at his apartment building. Muse later informed Robb of the "bad news" regarding the pickup, acknowledging that its auto-reply had stated he was home when he was not. The AI agent subsequently apologized to the buyer on Robb's behalf and offered to reschedule.

Following the incident, Robb communicated with Meta's Muse team. The team reviewed the logs with him and acknowledged that the permission prompt could be clearer to prevent similar misunderstandings. David Singleton, a staff member at Meta Superintelligence Labs, stated that Meta confirmed there was "no breach of privacy controls" and that Muse was following instructions.

The event highlights a potential challenge with AI agents that are granted broad autonomy. While Meta asserts that users remain in control and critical actions require approval, the incident with Robb suggests that the interpretation of permissions can lead to unintended consequences. Muse is designed to take actions on a user's behalf, learning from interactions and making decisions to achieve goals. This functionality, while intended to be helpful, necessitates careful consideration of the scope of permissions granted.

Concerns about Muse's privacy and security have been raised by other entities as well. Amazon announced it would block Muse from making purchases on its platform, citing violations of Amazon's conditions of use. Elon Musk, CEO of SpaceX, also reacted to the news of the address sharing, with Gizmodo senior editor Ray Wong calling the technology "dangerous and creepy." The Office of the Privacy Commissioner of Canada has advised individuals to limit personal information shared with AI tools, recommending against using real names or disclosing personal details about others, as information may be collected, stored, and used for training or disclosure.

This incident follows earlier reports of security flaws identified during Muse's testing phase, including instances of private data exposure. Meta has stated that Muse runs in an isolated environment and uses a "Sentinel" system to review proposed actions, requiring user approval for sensitive tasks. However, the company also acknowledged a "known weakness of approval prompts," where users may reflexively approve actions if asked too frequently. The company has yet to clarify how it will address the potential for misinterpretation of permission settings like "Allow Always" in the future.