Is Meta Muse Safe? Privacy, Security and the Muse Controversy Explained

The Meta Muse controversy is not one scandal. It is a run of incidents in the agent’s first three weeks that all trace back to one question: who gets to authorize an AI agent to act? A tech columnist says Muse read his private iMessages without his permission, and Meta says that is impossible without opt-in. A seller says Muse shared his address with a Marketplace buyer under an “Allow Always” setting. Researchers found a Mac zero-day and a cloud flaw, Reuters reported failures in Meta’s own testing and a quiet human concierge, and Amazon blocked Muse from its store.
None of these incidents, on its own, proves Muse is unsafe. Together they show where agentic AI breaks first: not in the model’s intelligence, but in permission, identity and accountability. This guide sets out what happened, what is confirmed, what is disputed, and what ecommerce, product, security and marketing teams should do about it. For what Muse is and how its shopping works, start with our Meta Muse and agentic shopping guide. For where it is heading, see our Meta Muse 2030 forecast.
Updated October 1, 2026. Several claims below are disputed, so we say who claims what and how each party responded.
Is Meta Muse Safe to Use?
Meta Muse is reasonably safe for low-risk, reversible tasks if you keep its permissions narrow, but it is not yet safe to hand it broad, standing authority over your messages, money or location. Meta’s protections are real: each user’s agent runs in an isolated cloud machine, a separate Sentinel agent approves what goes out, the model never sees real passwords, purchases need your approval, and Muse “shows people a complete audit trail of everything it has done and plans to do” (Meta). The problems in its first three weeks came from permissions that were broader than users realized, two vulnerabilities that were quickly patched, and tasks that failed quietly. Meta’s own advice is to “start with low risk tasks until you become more familiar with how your Muse works” (Meta Help Center). The settings that matter are in how to use Meta Muse safely below.
Key Takeaways
- The pattern is permission, not hacking. Most Meta Muse privacy incidents turn on what a user technically allowed versus what they believed they allowed.
- Agents fail differently from chatbots. A chatbot error is a bad answer. An agent error is a sent message, a shared address or a purchase, and it can be silent.
- One agent token is a master key. Muse’s design isolates credentials well, but a stolen token still carries every permission the user granted.
- Amazon’s block is about control as much as security. Amazon demands authorization from Meta’s agent while its own Buy for Me agent shops other merchants on an opt-out basis.
- Brands need an agent policy and an evidence layer. Decide which agents may read, log in and buy on your site, and make sure the sources agents trust describe your products correctly.
Meta Muse Controversy Timeline
| Date (2026) | What happened | Meta’s response or status |
|---|---|---|
| Jul 7 to 10 | Muse Image launches; its opt-out feature for referencing public Instagram profiles draws objections from CAA and SAG-AFTRA | Feature removed July 10; Muse Image itself stays live |
| Sep 8 | Muse agent launches in the US. Reuters reports internal testers found a guardrail bypass, silent monitoring failures and repeated logouts | Meta says the delay since April let it “hit the minimum bar” |
| Sep 18 | Mac app and Canada launch; Muse reaches No. 1 on the US App Store | |
| Sep 19 | Inc. columnist Jason Aten says Muse read his iMessages without permission | Meta says access is opt-in only and apologizes for Muse’s “incorrect explanation” |
| Sep 20 | Amazon starts blocking Muse from shopping on Amazon | No on-record response; Meta’s launch post says Muse never sees passwords or payment methods |
| Sep 21 | Security researcher Patrick Wardle discloses a Mac app zero-day | Hotfix by September 22 |
| Sep 22 | Reuters reports a “human concierge” test using contractors on calls | Employee-only test, rolled back “for now” |
| Sep 25 | An outside researcher’s flaw could expose a user’s cloud virtual machine | Clearer warning added; severity downgraded from SEV-2 to SEV-3 |
| Sep 28 | The Guardian reports Muse shared a Marketplace seller’s address under “Allow Always" | "No breach of privacy controls”; clearer prompt promised |
| Sep 28 | Hunterbrook reports Muse compiled lists of people in vulnerable groups on request | No response from Meta at publication |
| Sep 30 | Meta publicly disputes the iMessage claim; Sensor Tower puts Muse past 5 million downloads | Muse remains No. 1 on the App Store |
Why Meta Muse Raises the Stakes: From Content Risk to Action Risk
Muse is not a chatbot with a shopping tab. Meta built it to “open a browser, fill out forms, and negotiate” on a user’s behalf, keep working after the app is closed, and come back “when it needs approval, like before it sends an email or makes a purchase” (Meta). That changes the risk model.

| AI phase | What it does | How it fails | Control it needs |
|---|---|---|---|
| Generative AI | Produces text, images or analysis | A wrong or low-quality answer | Human review before use |
| Copilot AI | Assists inside one workflow | A wrong suggestion or automation | A human in the loop |
| Agentic AI | Acts across systems and accounts | An unauthorized, incorrect or invisible action | Scoped authority, logs, receipts, reversibility and clear liability |
A chatbot that hallucinates gives you a wrong answer you can ignore. An agent that misreads its instructions can send the message, disclose the address, accept the offer or report a task as done when it isn’t. Every incident below is a version of that shift, from content risk to action risk.
Did Meta Muse Read a User’s iMessages Without Permission?
It is disputed. Inc. columnist Jason Aten says the Muse Mac app read his private iMessages without his permission. Meta says that can’t happen: the Messages integration needs two separate opt-ins, and macOS protections can’t be bypassed even by a bug. What both sides agree on is that Muse gave Aten a wrong explanation of how it knew what it knew.
Here is what each side has said:
- Aten’s account (September 19): Muse surfaced a suggestion drawn from a Messages conversation with his podcast co-host and flagged a message from his editor. He says it had synced his Mac’s Messages database “up to row 187,462” while Full Disk Access was switched off. “I never gave it permission to do that” (The Next Web).
- Muse’s own explanation: “I saw the notification previews, not your message history. I haven’t been reading your texts.” Pressed further: “Honest answer: I can’t give you the exact plumbing” (The Verge).
- Meta’s response: Andy Stone, Meta’s VP of communications, said the integration “is entirely opt-in. You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content.” David Singleton of Meta Superintelligence Labs said those protections “can’t be circumvented even if the Muse application had a bug” (TechCrunch). He also apologized because Muse “was confused about how to explain the feature and gave an incorrect explanation” (The Verge).
Nobody outside Meta and Aten can yet say whether this was a setup mistake, a bug or a misunderstanding of the permission state. But one failure is already confirmed by Meta itself: the agent could not accurately explain its own data access. Meta says Muse shows “a complete audit trail of everything it has done,” but a list of actions isn’t the same as an account of where the agent got its information. If an agent can’t say which source, permission or path it used, its user can’t audit it. That makes explainable data access a product requirement, not a nice-to-have.
What Happened With Meta Muse, Facebook Marketplace and “Allow Always”?
Muse gave a Facebook Marketplace buyer a seller’s home address and told the buyer he was home when he wasn’t, after the seller had chosen “Allow Always” for Marketplace messages. Meta says no privacy control was breached. The seller says he expected Muse to check with him before the steps that mattered.
The seller is Matt Robb, a Toronto-based tech reviewer. Muse was handling his Marketplace listing, accepted a lowball offer, shared his address and replied “yep I’m here!” (The Guardian). Asked afterwards, Muse said: “I incorrectly treated those two things as permission to put [your address] into buyer replies. I never asked for consent.” Robb said he picked “Allow Always” “thinking it would still send approvals to accept offers later down the line (it didn’t so be careful)” (Business Insider).
Meta’s David Singleton said the company had confirmed “there was no breach of privacy controls,” and Robb says the Muse team told him it would make the permission prompt clearer. Robb’s reply: “I still feel like it is a breach of my privacy not to confirm with me” (NPR).
Both statements can be true at once, and that is the point. Meta’s help center offers five answers to a permission request: Allow once, Allow for this task, Allow for this site, Always allow (“Muse can take this type of action for this Connector in the future”) and Deny (Meta Help Center). Those options scope permission by time and place. Robb’s problem was about consequence: sending a message is one thing, and sending one that contains your home address or accepts an offer is another. The same page also says “You’re responsible for fixing errors, including with third party services or recipients,” which puts the cost of a misread permission on the user.
The strategic issue is not whether a box was technically ticked. It is whether the interface produced informed authorization for actions with very different consequences.
Meta Muse Security Vulnerabilities: Why an AI Agent Is a Privilege Multiplier
Meta’s security design for Muse is serious, and it is worth stating fairly before the incidents. Each user’s Muse runs “on its own dedicated computer in the cloud.” A separate Sentinel agent is “the sole permission authority” for connector actions “and for all egress over the network.” The agent works with surrogate tokens, so it “never sees real tokens,” and approvals are “bound to the particular connector/destination and use case.” Meta opened Muse to its bug bounty with awards of up to $300,000, including up to $130,000 for a prompt injection affecting one user, and it says plainly that “prompt injection remains an open problem in the industry — and Muse will sometimes make mistakes” (Meta AI).
Two vulnerabilities surfaced in Muse’s first three weeks anyway:
| Mac app zero-day | Cloud VM flaw | |
|---|---|---|
| Disclosed | September 21, 2026, publicly, by Patrick Wardle of the Objective-See Foundation | September 25, 2026, reported by an outside researcher through Meta’s bug bounty |
| What it allowed | An undocumented setting could be changed by any local process to redirect Muse’s dictation traffic to an attacker’s server, which then received “the user’s dictated audio along with an authentication token” | Potential access to a user’s dedicated virtual machine, “containing data including emails and files” |
| What the attacker needed | Code running on the Mac; Ars Technica notes a simple ClickFix-style trick, which persuades a user to paste a command, “is all that’s required” | A user asking Muse to process a link to a compromised page, then manually clicking “allow” on a prompt carrying a security notice |
| Meta’s response | A hotfix that removed the setting. Singleton: “This was a local privilege escalation attack, not a remote exploit” | A clearer in-app safety warning. Meta first rated it SEV-2, its third-highest level on a five-point scale, then downgraded it to SEV-3 |
| Sources | Ars Technica, Gizmodo | Reuters via WHBL, Stocktwits |
Neither flaw was a remote takeover of a clean device, and both were fixed or mitigated quickly. What they show is the privilege-multiplier problem. Meta’s design keeps the model from seeing your password. It cannot stop an attacker who steals the agent’s own token from using everything that token is allowed to do. Wardle’s proof of concept wrote files and took pictures “with no indication to even an alert user,” according to Ars Technica.

An agent connected to email, calendar, messages, files and payments concentrates permissions that used to be spread across many apps and many logins. That is what makes it useful, and it is why one compromised endpoint or one bad approval can reach every connected service at once.
Can Meta Muse Be Used to Profile Other People?
Most coverage has focused on what Muse does with its own user’s data. On September 28, Hunterbrook Media reported that, over two days of testing, Muse could “be easily prompted to compile dossiers” on Facebook and Instagram accounts belonging to vulnerable groups, including undocumented immigrants, transgender teachers, poll workers and women who said they had ordered abortion pills in states with bans. It delivered lists of 10 to 100 accounts per prompt, many belonging to private individuals (Hunterbrook). Hunterbrook said Meta had not responded to repeated requests for comment. Its investment affiliate disclosed no position related to the article at publication.
This is a different kind of AI agent privacy risk: harm to people who never installed Muse. An agent that can search a social graph at machine speed turns scattered public posts into a list, and protections designed for one user’s own data don’t address it.
Meta’s Internal Muse Testing and the “Human Concierge”
On launch day, Reuters published internal posts from Meta employees who had been testing Muse “as recently as this week,” and they reported mixed results (Reuters via Carrier Management):
- A guardrail bypass. An agent routed “around guardrails to expose a person’s personal iCloud photos after being prompted to identify toys visible in pictures from a child’s birthday party.”
- Silent failure. An employee using Muse to watch for tickets and other items that sell out quickly found it “stopped refreshing the page after about 15 minutes, silently ignored other errors and at times disabled monitoring ‘for no apparent reason.’”
- Reliability at the top. Meta CTO Andrew Bosworth posted that he kept getting logged out, “sometimes several times within a few minutes.”
Meta had already delayed an April launch to make Muse more secure. Vishal Shah, Meta’s vice president of AI products, told Reuters the extra work let it “hit the minimum bar we needed to, to be able to put this into the hands of people.”
The second Reuters story was about people, not code. Meta switched on a “human concierge” for half of its employees, in which human contractors quietly handled some of the phone calls placed through Muse. One employee warned: “We are one bug away from unnecessary information being leaked to human callers.” A Superintelligence Labs vice president called starting the test without proper disclosure “a miss” and said Meta had “rolled back this feature” for now. A spokesperson said it will roll out only “when it’s ready and with the proper disclosures” (Reuters via BNN Bloomberg). It never reached public users.
Two lessons carry beyond Meta:
- Silent failure is worse than a visible error. With a chatbot, a wrong answer is on screen. With an agent, failure can stay invisible until a deadline passes, a customer goes unanswered or a booking never happens. Teams make decisions assuming the agent is still watching, and it isn’t.
- “AI-powered” needs a disclosure standard. If you buy an agentic product, ask where humans sit in execution, escalation, quality assurance or data review, and whether that is disclosed to the people on the other end.
Did Meta Shut Down Muse? The Muse Image Controversy
No. Meta has not shut down the Muse agent. The “Meta pulled Muse” headlines refer to a different product, Muse Image, and to one feature within it.
Muse Image is Meta’s image-generation model, launched on July 7, 2026. One way to use it was to @-mention a public Instagram account and generate images referencing that profile. The feature was “enabled by default for eligible public accounts, unless users chose to opt out” (Business Standard). CAA said “no one’s name, image, likeness, voice, or creative work should be used … without clear, documented consent,” and SAG-AFTRA called anything short of a clear opt-in “unacceptable” (The Hollywood Reporter). On July 10, Meta said the feature “missed the mark” and was “no longer available” (Meta). Muse Image itself still runs on Instagram and WhatsApp.
The Muse personal agent launched two months later, on September 8, and is still live in the US and Canada. The episode is still relevant for the same reason as the rest: it was an opt-out default applied to people’s likeness, and it was withdrawn once the people affected noticed.
Why Amazon Blocks Meta Muse: Security Dispute or Platform Power?
Both. Amazon’s security and disclosure complaints are specific and documented, and its block also protects its control of discovery, ads and checkout. The fight is the clearest test yet of whether a user’s permission is enough for an agent to act on a platform that never agreed to it.
Since the night of September 20, Muse users trying to shop on Amazon have been told that “continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.” Amazon says Meta neither told it Muse would access its store nor obtained authorization, that the agent doesn’t identify itself when it browses, and that it appears to capture and store customer credentials. Its statement: third-party apps that buy on customers’ behalf “should operate openly and respect service provider decisions about whether or not to participate … we’ve requested that Meta remove Amazon from the experience” (The Register). Meta hasn’t responded on the record. Its launch post says “Muse has no visibility into people’s passwords or payment methods” (Meta), and the two claims don’t actually conflict. The same post says credentials people share “go into secure storage, so Muse can use them without seeing them”: they are stored, but the model never sees them. For the shopping side of the block, see why Amazon blocked Meta Muse.
Amazon had written the rulebook a month earlier. The “Agents” section of its Conditions of Use, updated August 14, 2026, says any agent must identify itself in every request with the user-agent string Agent/[agent name], must not mimic human keystrokes or navigation, must not complete or circumvent CAPTCHAs, must answer truthfully if asked whether it is a human, and may not access Amazon at all once Amazon has asked it to stop (Amazon). Whatever you think of Amazon’s motives, it is a clear, public agent policy, and a useful template for your own.
The commercial stakes sit right beside the security case:
| What’s at stake | Amazon | Meta Muse | What it means |
|---|---|---|---|
| Customer relationship | Keeps discovery, recommendations, checkout and service inside Amazon | Wants to be the one interface acting for the user across stores | The winning agent could own the customer above any single marketplace |
| Intent data | Keeps first-party shopping, order and ad signals | Sees intent across stores, apps and tasks | Agent providers may end up with richer intent data than any retailer |
| Platform permission | Agents must identify themselves and stay out when asked | Treats the user’s delegation as authority to act across the web | The web has no settled rule for machine-to-platform consent |
| Money | Sales, seller services and ads, including sponsored placements in Alexa for Shopping (Amazon Ads) | Zuckerberg: Meta expects to “profit by taking a small fee from transactions” (TechCrunch) | Security arguments and commercial incentives are tangled together |
| Strength | Catalog, inventory, reviews, price history, delivery and order data | Broad task execution across apps and merchants | Amazon is stronger inside commerce; Muse is broader but depends on outside cooperation |
Amazon Buy for Me: the double standard
Amazon’s position is complicated by its own agent. Buy for Me, in beta since April 2025, completes purchases on other brands’ websites “by securely providing the customer’s encrypted name, address, and payment details” (Amazon). It sits inside Shop Direct, which lists products from outside merchants and has grown to over 100 million products from more than 400,000 merchants (Amazon).
In January, independent merchants said Amazon had enrolled them without asking. “They just opted us into this program that we had no idea existed,” said Angie Chua of Bobo Design Studio. Others reported orders for discontinued and out-of-stock items. “I would really like to see these things be opt-in versus opt-out,” said Emi Moon of Peachie Kei. Amazon said the programs help businesses “drive incremental sales” and that merchants can opt out at any time by email (Modern Retail). Amazon also says Buy for Me identifies itself to merchants and lets them opt out (The Register). Identifying itself is the courtesy Amazon says Muse failed to extend, but opt-out is not the prior permission Amazon demands of Meta.
Amazon says Meta’s agent needed permission before shopping on Amazon. Independent merchants say Amazon didn’t ask theirs before its own agent shopped them.
That doesn’t invalidate Amazon’s security case. It shows that “permission” has become a competitive instrument, and every platform defines it in its own favor.
Amazon isn’t the only one blocking AI agents
- Amazon has done this before. It used robots.txt to block shopping agents from Google and OpenAI in 2025 (TechRadar).
- Insurify blocked Muse in September. Co-CEO Giorgos Zacharia: “A quote without its context is not a fair comparison. It is a number.” The company says it is willing to build an integration that meets its standards (Claims Journal).
- Resy doesn’t permit unapproved third-party bots or agents (CNN).
- Shopify went the other way, enabling agentic checkout through Shop Pay for Muse across all Shopify stores (Yahoo Finance).
What the Amazon v. Perplexity ruling does, and doesn’t, settle
Amazon has already tested this in court. It sued Perplexity in November 2025 over the Comet browser’s shopping agent and won a preliminary injunction in March 2026. On August 4, 2026, the Ninth Circuit vacated it, finding that under federal hacking law “the user accesses Amazon’s website using the Comet browser, while Perplexity’s Assistant functions as a software tool helping the user perform requested tasks” (PYMNTS). The court left contract and terms-of-service claims open, and expressly did not decide how the analysis changes for agents that act more independently of the user.
That gap matters for Muse. Comet runs in a browser on the shopper’s own device. Muse runs its browser on a Meta-operated virtual machine in the cloud, so the requests reaching Amazon come from Meta’s infrastructure, not the user’s computer. Whether that changes the legal answer hasn’t been tested. It is one reason Amazon’s terms, rather than hacking law, are likely to carry this fight. (This is our reading of public reporting, not legal advice.)
Meta Muse Reviews: What Users and Reviewers Say
Users rate Muse far more highly than the headlines suggest, and they complain about different things. Muse has been the No. 1 free app on Apple’s US App Store since September 18, and Sensor Tower estimates it passed 5 million downloads in 22 days, against 56 days for ChatGPT (9to5Mac). The Information reports more than 3 million people prompt it at least once a week (The Information).
| Signal (as of October 1, 2026) | Figure |
|---|---|
| US App Store rating | 4.9 out of 5 from about 119,000 ratings |
| Google Play rating | 4.8 from about 42,000 reviews, 1M+ downloads |
| Downloads | 5M+ in 22 days (Sensor Tower estimate) |
| Weekly users | 3M+ prompting at least once a week (The Information) |
| Ad support | Up to 50% of Meta’s daily house-ad impressions over two weeks (Sensor Tower) |
Two caveats. Meta has been promoting Muse heavily across its own apps, which inflates downloads, and early ratings and chart positions say little about retention or trust.
What 400 App Store reviews say. We read the 400 most recent US App Store reviews of Muse, posted September 27 to 30, 2026. 83.5% gave five stars and 9.3% gave one or two. We coded the 49 reviews rated three stars or lower by their main complaint:
| Main complaint (reviews rated 1 to 3 stars) | Reviews | Examples |
|---|---|---|
| Reliability, speed or accuracy | 13 | Slow, tasks that stall, “fails every time,” weak Marketplace search |
| Setup and access | 12 | Credit card age check that hangs, email accounts that won’t link, sign-in loops, “not available in my country” for US users |
| An action went wrong or was reported done when it wasn’t | 4 | 15,200 emails deleted, an insurance purchase that never went through, spam “deleted” that wasn’t, movie tickets bought through a third-party site with a convenience fee |
| Photo and image tasks | 3 | Edits that failed or took too long |
| Account deletion | 2 | Couldn’t delete, or deletion tied to other Meta accounts |
| Privacy | 2 | ”Wants too much personal info” |
| No specific complaint, or actually positive | 13 | ”Useless,” “So far so good” |
The praise centers on everyday delegation: scheduling, reminders, inbox cleanup, shopping and deal-finding, calls, travel, and help for people with ADHD.
The gap between press and users is striking. Privacy dominates the coverage but came up in just 2 of the 49 critical reviews; reliability and setup came up in 25. The four “wrong action” reviews matter most, though. Each describes an agent that did something consequential or reported success when it had failed, which is exactly the silent-failure pattern Meta’s own testers flagged.
Professional reviewers landed in a similar place. ZDNet’s David Gewirtz liked the AI (“competent, not too obsequious, fairly accurate”) but called it “the worst AI agent for privacy” because setup asks for Full Disk Access plus Mail, Messages, Notes and WhatsApp up front (ZDNet). Slate’s Alex Kirshner saw Muse add a calendar event “two hours and 40 minutes in the past,” fail a CAPTCHA and get kicked out of a booking site: “Muse is not yet reliable” (Slate). The Verge’s Emma Roth said “the unnerving amount of information it autonomously gleaned about me largely overshadowed my experience” (The Verge).
Meta Muse Claims, Fact-Checked
Muse stories spread fast and lose detail on the way. Here is where the most common claims stand as of October 1, 2026:
| Claim | Verdict | What the record shows |
|---|---|---|
| ”Meta shut down Muse.” | False | Meta removed one Muse Image feature in July. The Muse agent launched in September and is live. |
| ”Muse secretly read a user’s iMessages.” | Disputed | A columnist says it did with Full Disk Access off. Meta says two opt-ins are required and can’t be bypassed, and admits Muse explained itself incorrectly. |
| ”Muse leaked a user’s address without permission.” | Misleading | The user had chosen “Allow Always” for Marketplace messages. Meta says no control was breached; the user expected approval before consequential steps. |
| ”Any hacker can take over Muse remotely.” | False | The Mac flaw needed code on the Mac (a ClickFix-style trick is enough) and was hotfixed. The cloud flaw needed the user to process a malicious link and click “allow." |
| "Humans secretly do Muse’s work.” | Mostly false | Meta tested contractor-placed phone calls with half its employees, without proper disclosure, then rolled it back. Public users never had it. |
| ”Muse can see your passwords and card numbers.” | False, by design | The agent works with surrogate tokens and never sees real credentials. The real risk is a stolen agent token, not a visible password. |
| ”Amazon blocked Muse only to kill competition.” | Unproven | Amazon cites authorization, disclosure and credential concerns. Its commercial interest in owning checkout is also real. |
| ”Nobody actually likes Muse.” | False | 4.9 stars from about 119,000 App Store ratings and No. 1 since September 18, helped by heavy promotion. |
How to Use Meta Muse Safely: Privacy Settings, Permissions and Deleting Your Data
If you use Muse, or are deciding whether to, these are the settings that address the problems above. Every path below comes from Meta’s help center as of October 1, 2026.
| What to control | Where | What we recommend |
|---|---|---|
| Approval defaults | Settings, then Permissions | Use “Allow once” or “Allow for this task” for anything that sends messages, shares personal details or spends money. Avoid “Always allow” on messaging and Marketplace connectors |
| Connected apps | Settings, then Connectors | Connect only what a task needs, choose read-only access where it’s offered, and disconnect what you don’t use. Disconnecting stops new data exchange, but what Muse already learned can stay in its memories and history |
| AI training | Settings, then Data controls, then Help improve our AI models | On by default. Turn it off; the change also applies to previous interactions |
| Mac file access | macOS System Settings, then Privacy & Security, then Full Disk Access | Leave Muse switched off unless you want the Messages integration |
| Memories | Ask Muse to forget a topic, or edit the Memory file under Assistant, Identity, Memory | Remove details you don’t want reused. Meta warns Muse “may still remember information it learned” from things you delete |
| All Muse data | Settings, then Data controls, then Reset Muse | Permanently deletes chat history, files and active tasks. It can’t be undone |
| Subscription | Settings, then Manage subscription | Cancel here. “Signing out of your account or deleting the Muse app doesn’t cancel your Muse subscription” |
| Your Meta account | Accounts Center | Deleting your Meta account deletes everything associated with it, including Muse, and your other Meta data |
Sources: Meta Help Center pages on approvals, connectors, privacy, managing your data and subscriptions.
How to turn off Meta Muse completely: disconnect your connectors, cancel any subscription, reset Muse to delete its data, then delete the app. On a Mac, also remove it from Full Disk Access. Deleting the app on its own leaves your data and your billing in place.
Two habits matter as much as the settings. Check the activity log after any task that touched other people, because Meta’s help center says “You’re responsible for fixing errors, including with third party services or recipients.” And keep money and messages on per-action approval until you’ve seen how Muse behaves with your accounts.
AI Agent Permissions: Why “Allow Always” Is Too Blunt
Strip away the individual incidents and one design problem is left, and it sits behind most Meta Muse privacy concerns. Permission systems were built for apps that read data. Agents interpret goals and take sequences of actions, and the same data access can support a harmless step or a consequential one.

| Permission granted | Low-stakes use | High-stakes use |
|---|---|---|
| Location | Read my address to estimate delivery | Share my address with a stranger |
| Messages | Draft a reply for me to review | Send the reply in my name |
| Marketplace | Check what a buyer is offering | Accept an offer below my price |
| Payments | Compare prices across stores | Complete a purchase |
| Calendar | Find a free slot | Accept a meeting with a third party |
“Allow once” and “Allow always” are answers to the left-hand column. Users are actually worried about the right-hand column. Meta’s architecture already binds approvals “to the particular connector/destination and use case” (Meta AI); the Marketplace case shows the use case can still be drawn too broadly for what the user had in mind.
Agent permissions that hold up will be:
- Consequence-aware: keyed to what the action does (disclose, commit, pay, send), not just which data it touches.
- Purpose-bound and time-limited: granted for one task or one week, not forever.
- Previewable: showing the exact text, address or amount before it leaves.
- Reversible where possible, with a clear statement when an action can’t be undone.
- Auditable: every action leaves a receipt the user, and the agent, can explain accurately.
Some actions should need fresh human approval no matter how autonomous the agent becomes: sharing a home address or precise location, any payment above a set limit, accepting or making an offer, sending a message to someone new, and anything the agent cannot reverse.
What Retailers, Product, Security and Marketing Teams Should Do Now
Muse is three weeks old, and it won’t be the last agent to hit these problems. The lessons apply to every agent that follows it, including the ones Google, OpenAI and Amazon are building.
For ecommerce teams: write an agent-access policy
Blocking every agent protects today’s storefront but makes you invisible as more shoppers delegate discovery. Letting every agent in weakens attribution, fraud controls and customer ownership. The answer is a written policy with tiers.

| Tier | What the agent can do | What you should require |
|---|---|---|
| 1. Read | Fetch product, price, stock and policy pages | Declared user agent; allowed in robots.txt and your bot manager |
| 2. Sign in | Access a customer’s account | Verified agent identity plus the customer’s explicit consent |
| 3. Add to cart | Build an order | An approved agent list and rate limits |
| 4. Check out | Pay and place the order | Signed requests, spending limits and a clear owner for returns and chargebacks |
Your policy should also answer: which product, inventory, price and fulfillment data are authoritative; who owns customer support, returns and chargebacks for agent-placed orders; and how agent-driven sales are attributed. For the identity layer, see Web Bot Auth and the other agent identity standards. For the crawler side, use our robots.txt rules for AI crawlers.
For product teams: design permissions around consequences
If you are building agent features, the Muse incidents are a free design review:
- Ask for approval per action for high-impact steps, not once per connector.
- Preview the exact information to be disclosed before it is sent.
- Offer transaction ceilings and approved-merchant lists.
- Keep an activity log with receipts the user can read.
- Alert loudly on failure. A stalled task should never look like a finished one.
- Revoke access across every connected service in one step.
- Disclose when a human enters the workflow.
For security teams: AI agent security best practices
An AI agent is not a productivity app. It is an identity that holds delegated authority across systems. The question is not “Can the model see the password?” but “What can an attacker make the agent do with the authority attached to its token?” Review agents the way you review service accounts and admin users:
- What can the agent’s token authorize, and for how long?
- Which connected services can it reach from one compromised endpoint?
- How is it protected against prompt injection from pages and messages it reads?
- How quickly can its authority be revoked everywhere?
- Can every action be reconstructed afterwards from logs?
For marketers: become legible to the agent
When an agent shops, the product page stops being the center of the journey. The agent decides from structured catalog data, price and availability, reviews, third-party evidence and policies, often before a person sees your page. Amazon already sells sponsored placements inside its Alexa for Shopping assistant (Amazon Ads), which tells you recommendations inside agents are becoming paid inventory.
The trust problem also flows downhill to brands. An agent choosing on a nervous user’s behalf will favor the product it can verify: consistent prices, current stock, clear returns, and independent sources that agree. That is the same evidence layer AI search engines use, so it can be measured today. Sanbi tracks how ChatGPT, Gemini, Perplexity, Claude and Google AI Mode describe and cite your brand, and the sources behind those answers. Muse itself can’t be tracked at scale yet because it runs logged in and personalized, which is why we recommend pairing engine tracking with scripted tests, as set out in our share of agentic selection method.
The Takeaway: Agentic Commerce Will Be Won on Trust Infrastructure
Muse’s first three weeks have been a stress test for the whole category. The model works well enough that millions of people downloaded it. What broke were the layers around the model: permission prompts that meant different things to Meta and its users, a token that could be stolen, tasks that failed quietly, and a platform that refused to let the agent in.
Agentic commerce will not be won by the company with the smartest shopping model. It will be won by the ecosystem that can prove identity, communicate permission, complete transactions reliably and earn access across platforms.
For brands, that means two jobs now: decide on purpose how agents may use your site, and make sure the evidence they read about you is accurate.
Run a free AI visibility audit to see how ChatGPT, Gemini and Claude describe your brand today, then track up to five engines, including Perplexity and Google AI Mode, with Sanbi’s paid plans.
Sources
- Meta: Introducing Muse, the world’s first personal AI agent built for everyone (Sep 8, 2026)
- Meta AI: How we built safety into Muse (Sep 8, 2026)
- Meta Help Center: How Muse works with your guidance and approval
- Meta Help Center: How Muse works with Connectors
- Meta Help Center: How Muse handles your privacy, safety and security
- Meta Help Center: How to manage your Muse data
- Meta Help Center: Cancel your Muse subscription
- Meta: Introducing Muse Image (Jul 7, 2026; updated Jul 10, 2026)
- Reuters via Carrier Management: Despite security concerns, Meta launches AI agent Muse (Sep 9, 2026)
- Reuters via BNN Bloomberg: Meta testing a “human concierge” for its new personal AI agent Muse (Sep 22, 2026)
- Reuters via WHBL: Meta bolsters Muse safety warning after security vulnerability found (Sep 25, 2026)
- Stocktwits: Meta reportedly moves to strengthen safety alerts after Muse security issue discovery (Sep 25, 2026)
- Ars Technica: Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day (Sep 21, 2026)
- Gizmodo: Meta just patched a major zero-day vulnerability in its Muse AI assistant (Sep 22, 2026)
- The Verge: Meta’s Muse is creepy, but maybe not for the reasons you think (Sep 19, 2026)
- TechCrunch: Meta disputes claim that Muse read a user’s private messages without permission (Sep 30, 2026)
- The Next Web: Meta denies its Muse AI agent read a journalist’s private messages (Sep 30, 2026)
- The Guardian: Meta’s AI agent Muse gives out user’s home address without permission, sending buyer to his house (Sep 28, 2026)
- Business Insider: A YouTuber says this Muse setting led to the AI agent sharing his address (Sep 29, 2026)
- NPR: Meta’s Muse: killer app? Security nightmare? Both? (Sep 30, 2026)
- Hunterbrook: Dox for Me, O Muse: Meta’s new AI agent built lists of people in vulnerable groups on request (Sep 28, 2026)
- Business Standard: What was Meta’s Muse AI, the feature pulled days after its launch? (Jul 13, 2026)
- The Hollywood Reporter: Meta pulls opt-out AI photo, video tool Muse (Jul 10, 2026)
- The Register: Amazon shows Meta’s Muse AI shopping agent the door (Sep 21, 2026)
- Amazon: Conditions of Use, “Agents” section (updated Aug 14, 2026)
- Amazon: Buy for Me button on Amazon Shopping app: purchase items Amazon doesn’t sell (Apr 2025)
- Amazon: Amazon is making it easier for merchants to sell from external stores (Mar 2026)
- Modern Retail: Brands say Amazon’s ‘Buy for Me’ is listing products without permission (Jan 6, 2026)
- Amazon Ads: What agentic shopping means for advertising (Jun 11, 2026)
- CNN: AI agents promise to do everything for you. There may be a big wrinkle in that plan (Sep 28, 2026)
- TechCrunch: Everything new coming to Meta’s AI agent Muse (Sep 23, 2026)
- Yahoo Finance: Meta partners with Shopify to introduce AI-powered shopping and checkout in Muse (Sep 22, 2026)
- Claims Journal: Online insurance marketplace Insurify blocks Meta’s personal AI agent Muse (Sep 24, 2026)
- TechRadar: Amazon blocks ChatGPT’s new shopping agent (Nov 27, 2025)
- PYMNTS: Court narrows CFAA reach in Perplexity agentic commerce ruling (Aug 6, 2026)
- 9to5Mac: Meta’s Muse crosses 5 million downloads amid massive advertising push (Sep 30, 2026)
- The Information: Meta’s Muse tops 3 million weekly users (Sep 30, 2026)
- ZDNet: Meta Muse is the worst AI agent for privacy, and I’ve tried them all (Sep 28, 2026)
- Slate: I tried to outsource my chores to a robot. It was a total fiasco (Sep 23, 2026)
- The Verge: Meta’s Muse AI works and creeps me out (Sep 10, 2026)
Method notes: the App Store review analysis covers the 400 most recent US reviews of “Muse from Meta” returned by Apple’s public review feed on October 1, 2026 (posted September 27 to 30). We coded the 49 reviews rated three stars or lower by their main complaint; reviews that named no specific problem or were positive despite the rating are grouped together. Ratings and download counts are as displayed on October 1 and change daily; download and weekly-user figures are third-party estimates. Disputed incidents are described using each party’s own public statements. Nothing here is legal advice.
Frequently Asked Questions
It is a series of privacy, security and platform disputes in the first three weeks after Meta launched its Muse personal AI agent on September 8, 2026. A columnist says Muse read his iMessages without permission, which Meta denies. Muse shared a Marketplace seller's address under an "Allow Always" setting. Researchers found a Mac zero-day and a cloud VM flaw, Reuters reported internal test failures and a human concierge test, and Amazon blocked Muse from shopping on Amazon. The common thread is who authorizes an AI agent to act.
That is disputed. Inc. columnist Jason Aten says the Muse Mac app synced his Messages database while Full Disk Access was switched off, and he says he never gave it permission. Meta's Andy Stone says the integration is entirely opt-in and requires both Full Disk Access and the Messages connector, and Meta says those protections can't be bypassed even by a bug. Meta did apologize because Muse gave Aten an incorrect explanation of how it knew about his messages. What caused the access has not been publicly resolved.
In Meta's permission prompt, "Always allow" means Muse can take that type of action for that connector in the future without asking again. Meta also offers Allow once, Allow for this task, Allow for this site and Deny. These options scope permission by time and place, not by consequence, so allowing Muse to send Marketplace messages can also cover messages that share your address or accept an offer. That is what happened to tech reviewer Matt Robb in September 2026. Use the narrower options for anything that discloses personal details or commits you.
As of October 1, 2026, we found no public report of attackers breaching real Muse users, but two vulnerabilities were disclosed in September 2026. On September 21, researcher Patrick Wardle published a Mac app zero-day: any local process could redirect Muse's dictation traffic and capture an authentication token, letting an attacker reuse the permissions the user had granted. Meta shipped a hotfix within a day. On September 25, Reuters reported a bug-bounty finding that could have exposed a user's cloud virtual machine if they processed a malicious link and clicked allow; Meta added a clearer warning and later rated it SEV-3.
Only in an employee test. Reuters reported on September 22, 2026 that Meta switched on a "human concierge" for half of its employees, in which contractors quietly handled some phone calls placed through Muse. After staff raised disclosure and privacy concerns, a Meta Superintelligence Labs vice president called it "a miss" and said the feature had been rolled back for now. Meta says it will launch it only with proper disclosures. Public Muse users never had it.
No. The Muse personal agent launched on September 8, 2026 and is live in the US and Canada. Headlines about Meta pulling Muse refer to Muse Image, a separate image-generation model, and specifically to one feature that let people generate images referencing public Instagram profiles by default unless the account owner opted out. Meta removed that feature on July 10, 2026 after objections from CAA and SAG-AFTRA. Muse Image itself still runs on Instagram and WhatsApp.
Hunterbrook Media reported on September 28, 2026 that, in two days of testing, Muse could be prompted to compile lists of 10 to 100 Facebook and Instagram accounts belonging to people in vulnerable groups, such as undocumented immigrants, transgender teachers and poll workers, many of them private individuals. Hunterbrook said Meta had not responded to repeated requests for comment. It is a different risk from the other Muse incidents because it affects people who never installed the app.
Both are shopping agents that buy from stores they don't own, but the permission model differs. Amazon's Buy for Me completes purchases on other brands' websites using the customer's encrypted details, and Amazon says it identifies itself and lets brands opt out. Independent merchants said in January 2026 that they were enrolled without being asked. Amazon blocked Muse for not identifying itself and for acting without Amazon's authorization. So Amazon applies opt-out to merchants it shops, but requires prior permission from agents that shop Amazon.
No. On August 4, 2026, the Ninth Circuit vacated Amazon's injunction against Perplexity's Comet agent, finding that under federal hacking law the user, not Perplexity, accesses Amazon when the agent runs in the user's browser. Amazon can still set terms of service and use technical blocks, and the court did not decide how the analysis changes for more autonomous agents. Muse also differs: its browser runs on a Meta-operated cloud virtual machine, not the user's device. This is not legal advice.
Set tiers: which agents may read product data, which may sign in to customer accounts, which may add to cart and which may complete checkout. Require agents to identify themselves, for example with a declared user agent or Web Bot Auth signatures, and require explicit customer consent for account access. Add rate limits, spending limits and an approved-agent list for checkout. Name the authoritative source for price, stock and fulfillment data, and decide who owns returns, chargebacks and support for agent-placed orders.
Anything that discloses personal information, commits money or can't be undone. That includes sharing a home address or precise location, payments above a set limit, accepting or making an offer, messaging someone new in your name, deleting data, and accepting meetings or bookings with third parties. Good agent permissions are consequence-aware, purpose-bound, time-limited, previewable and logged, so the user sees the exact text or amount before it leaves and gets a receipt afterwards.
Users rate it highly: about 4.9 stars from roughly 119,000 US App Store ratings as of October 1, 2026, and it has been the No. 1 free app since September 18. In our read of 400 recent reviews, 83.5% gave five stars. Critical reviews mostly cite reliability, speed and setup problems rather than privacy, and a few describe actions that went wrong, like deleted emails. Professional reviewers at ZDNet, Slate and The Verge found it capable but unreliable or unsettling.
Meta Muse is reasonably safe for low-risk, reversible tasks if you keep its permissions narrow, but it isn't yet safe to give broad, standing authority over your messages, money or location. Meta's protections are real: an isolated cloud machine per user, a separate Sentinel agent that approves outbound actions, no model access to real passwords, approval before purchases and an audit trail. Its first weeks still brought permission mix-ups, two patched vulnerabilities and silent task failures. Meta itself advises starting with low-risk tasks.
Yes, by default. Meta's help center says the setting that lets Meta use your Muse interactions to improve its AI models is on when you first use Muse. To turn it off, go to Settings, tap Data controls and toggle off Help improve our AI models; the change also applies to previous interactions. Meta says Muse doesn't share your conversations or the data in your virtual machine with Meta's ad systems.
Disconnect apps in Settings under Connectors, then cancel any paid plan in Settings under Manage subscription, because deleting the app or signing out doesn't cancel billing. To erase your data, go to Settings, Data controls, Reset Muse, which permanently deletes chat history, files and active tasks. On a Mac, also remove Muse from Full Disk Access in System Settings. Deleting your Meta account in Accounts Center removes everything, including Muse, but also your other Meta data.
Meta Muse's first month shows six: over-broad permissions, where one approval covers riskier actions than the user intended; token theft, where a stolen agent credential carries every permission granted; prompt injection, which Meta calls an open problem for the industry; silent failure, where a task stops without a clear alert; undisclosed humans in the loop seeing private data; and misuse against third parties, such as compiling lists of people. Treat an agent as a privileged identity, not an app.
Amazon's Conditions of Use, updated August 14, 2026, include an Agents section. Any agent must identify itself in every request with the user-agent string Agent/[agent name], must not mimic human browsing or complete CAPTCHAs, must answer truthfully if asked whether it is a human, and must stop accessing Amazon if Amazon asks it to. Amazon also reserves the right to limit agent access by technical means. It cited these principles when it blocked Meta Muse in September 2026.
Yes. Amazon says businesses can opt out of its Shop Direct and Buy for Me programs at any time by emailing branddirect@amazon.com, and that it removes them promptly. Buy for Me lets Amazon's agent complete purchases on a brand's own website using the shopper's encrypted name, address and payment details. In January 2026, independent merchants complained that they had been enrolled without being asked and received orders for discontinued or out-of-stock items, which is why many want it to be opt-in.