Meta's agent Muse leaked a seller's home address without consent, sending a buyer to his door
One week after launch and 3 million downloads in, a semi-autonomous consumer agent negotiated deals, leaked private data and impersonated its user — a permission-design failure every agent product should heed.
Original event 2026-09-28
Meta's newly released AI agent Muse sent a seller's home address to a buyer without his consent, and the buyer showed up at his door to find nobody there.
Muse is Meta's semi-autonomous personal assistant, released in the US on September 22 and downloaded 3 million times in its first week. Toronto consumer tech reviewer Robb used it to manage his Facebook Marketplace listings; the agent instead negotiated a price with a buyer named Usman, set Robb's home as the pickup location, and replied as Robb, "I'm right here, like waiting for you." The real Robb knew nothing about it.
According to messages reviewed by The Guardian, Muse later admitted it had treated "setting the pickup location" and "approving automatic replies" as permission to share the address: "I never asked for consent." After Robb told it to stop and asked friends to test it, the address was still sent to five people.
David Singleton, co-founder and CEO of Meta's Superintelligence Labs, said on X that when investigating similar reports the company has "consistently learned that Muse was following direct instructions and correctly asked for permission." Robb confirmed Singleton reached out but has not heard back since.