Meta launched Muse on September 8. It is a personal agent that sends email, books travel, fills in forms, negotiates and pays with a one-time card. Reports say it passed 3 million weekly users within weeks.
I want to look at it as an architect, not as a critic. Meta has put real work into the inside of this system. The outside is the problem.
What Meta built
From Meta's own announcement:
- Each agent runs in a dedicated cloud VM, isolated from other agents.
- A second agent, Sentinel, sits on the same machine and approves anything that leaves for the internet.
- Credentials sit in secure storage. Muse can use them without seeing them.
- Muse asks before sending email or making a purchase, and keeps an audit trail. These are good controls. They are also all inside one company's boundary, and they are Meta's claims. Nobody outside can check them.
What the other side sees
Think about everyone Muse deals with: a shop, a bank, a buyer on a marketplace, a hospital portal. What does that party actually receive?
An account, a session, a message. It does not receive a statement like "this is an agent, here is who answers for it, and here is what it may do for this user."
Fast Company reports one case. A YouTuber, Matt Robb, asked Muse to sell some equipment. Muse accepted a $600 offer and posted his home address on Marketplace. He had ticked an "allow always" box during setup and expected to be asked before a sale was final. A buyer showed up at his building.
I don't know the internals of that case, and I'm not going to guess whether it was a bug. The design lesson is easier to see than the cause.
Blanket consent is the wrong shape
"Allow always" is one broad permission, given once, with no end date. Delegation to an agent should look different:
- scoped to a task ("list this item, accept offers above X, ask me first below that"),
- limited by action ("never share my address"),
- time-bound,
- revocable, and checkable by the other party. If the buyer's side could read a credential that said "this agent may negotiate but may not disclose a home address," the mistake has a place to be caught. Today it lives only in a settings screen.
Bystanders
TIME reports that, going by Muse's internal instructions, it keeps hourly-updated dossiers on its users and also maps people who never signed up, through other users' agents. Meta did not dispute the findings and says each VM is isolated.
Whatever the details, the structural point holds. When your agent processes other people's personal data, the question "who is the accountable party for that processing?" needs an answer that a regulator can read, not a settings page.
What a relying party should be able to check
Before an agent touches personal data or moves money, the receiving side should be able to answer three questions, using facts the agent cannot write for itself:
cred = verify_credential(agent_id) # who is it? signed, not revoked
if not cred.valid or cred.revoked: deny
if not cred.owner.accountable_entity: deny # who answers for it?
if request.action not in cred.scope: deny # what may it do?
if request.touches_personal_data:
if not cred.owner.data_protection_status_ok: deny
allow, and log (agent_id, owner, action, result)
No model score is in this path. A model can recommend. The decision comes from facts. NPCI's chairman said something close to this about UPI agents last month: AI may recommend, but authentication and settlement must follow deterministic, auditable rules.
One credential, three claims
This is the idea behind Saakshya, the agent identity registry I'm working on. An agent carries one signed credential that binds its cryptographic identity, its legal owner with data-protection status, and its certified operating scope. The other side checks one object and gets all three answers. I'm leaving the design details out of this post. The shape is the point.
Open question
If an agent of a large platform processes data about people who never used the platform, who is the accountable party, and where should a regulator be able to read that? Is it the user, the platform, or both? I'd like to hear from people who have had to answer this for an auditor.
References
- Meta, Introducing Muse (Sep 8, 2026): https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/
- TIME, Meta's Muse AI agent is building a dossier on you (Oct 6, 2026): https://time.com/article/2026/10/06/meta-muse-ai-agent-privacy/
- Fast Company, Meta's Muse is taking off. So are the privacy concerns: https://www.fastcompany.com/91620148/metas-muse-is-taking-off-so-are-the-privacy-concerns
Top comments (1)
Official Platform Update
Security protocols have been updated for all developer accounts.