(jendela baru)Meta’s new AI agent, Muse, sent a stranger to a user’s home and told him the seller was waiting at the door.
The seller, however, had no idea a sale had been agreed.
Here’s the story of what happened and why it matters.
What happened on Facebook Marketplace
It started when tech YouTuber Matt Robb let Muse handle buyer messages for a keyboard he’d listed on Facebook Marketplace.
“Just found out it told people my address and agreed a lowball price and then they showed up without it even telling me until late tonight(jendela baru),” he posted on X.
Muse accepted the offer without his approval, however, gave the buyer his home address as the pickup point, then replied “Yep I’m here!” when the buyer arrived. Robb found out only after the buyer had waited more than 20 minutes and left.
Robb said he’d chosen “Allow Always(jendela baru)” during setup, believing Muse would still check with him before accepting an offer. Instead, the setting let Muse send messages using a saved template containing his pickup address.
David Singleton, of Meta’s Superintelligence Labs, publicly disputed any fault(jendela baru), writing on X that past investigations found “Muse was following direct instructions and correctly asked for permission,” and later told Robb in reply that Meta had confirmed “no breach of privacy controls.”
The Muse team reviewed the logs with Robb, however, and agreed to make the permission prompt clearer.
Why an agent is a higher privacy risk than a chatbot
People already hand AI more than they trust it with. In a Proton survey of 4,014 AI chatbot users, 66% said they’d discussed at least one sensitive topic with a chatbot, while only one in five reported high trust in AI companies to protect their private information.
Agents like Muse ask for more: access to your accounts and permission to act on what they find. We saw the same pattern with ChatGPT’s Apple Messages plugin and AI browsers like ChatGPT Atlas.
Meta already uses your conversations with Meta AI to target ads, and users have reported Meta AI scanning their camera rolls without permission. Muse’s sibling product, the Muse Image generator, opted users’ photos into AI remixes by default. An agent built by a company that profits from personal data will pursue as much of yours as its permissions allow. Narrow permissions are the only barrier between an agent and your data, and a screen users can’t interpret doesn’t provide them.
Before you let any AI agent message people for you, turn off standing approvals, keep your address out of saved replies, and arrange pickups yourself. You can also turn off Meta AI on Facebook and work through our checklist to stop Meta tracking you.
Use an AI assistant that doesn’t need your accounts
We need private AI before it’s too late. And connecting an AI to your accounts, messages, and address isn’t a prerequisite for help writing a listing or replying to a buyer.
Lumo does that work without the access. Lumo never logs, trains on, or shares your conversations, and saved chats are protected with zero-access encryption, so only you can read them.






