
Meta Muse’s AI Agent: Useful Tasks, Wider Risks
Published by AINave Editorial
Meta’s Muse AI agent can do more than answer questions: it uses a browser to act on a person’s behalf. In a week-long test, a BBC reporter had Muse contact a Facebook Marketplace seller, order dental floss and negotiate a $31 discount on a software subscription. The same workflow can require access to Gmail, calendars and, on Mac, the computer itself, making permissions part of the product’s risk profile from the start. The reported tasks and requested access
The pressure comes from agents acting at scale
The concern is not that Muse itself has been shown to overwhelm websites. It is that agents can perform many actions quickly, and users can run them in parallel. Experts interviewed by the BBC warn that this could intensify competition for scarce concert tickets, appointments and restaurant reservations. Someone could ask an agent to book several appointments “just in case,” a low-effort behavior that becomes consequential when many people do it. Experts’ concerns about ticketing and bookings
The same mismatch could affect businesses that rely on human-paced inquiries. One expert posed the possibility of a website receiving 600 bot inquiries a day where it might normally get two from people. The BBC also cited an analysis finding bot web traffic rose 124% in the year to June 2026; that figure describes bot traffic broadly, not traffic caused by Muse. Meta says Muse is designed to respect websites’ interests and avoid behavior such as refreshing a page 500 times an hour. The traffic figure and Meta’s stated safeguards
A fixed flaw still matters to trust
Security researcher Patrick Wardle told the BBC that a vulnerability he found could have let an attacker hijack Muse and its data, and potentially control connected devices such as a phone or smart lock. The BBC reports Meta fixed the flaw immediately. Wardle questioned what the oversight said about security vetting, while Meta said it had delayed Muse for additional privacy and security testing. The account does not include technical details or an independent postmortem, so it supports a serious reported incident, not a conclusion about the patch’s effectiveness. The reported vulnerability, fix and responses
Email access makes data policy concrete
An inbox can hold medical, legal and financial information alongside everyday messages. Meta says users can choose whether Muse scans all of Gmail or only messages relevant to a task, and says the data is not connected to its advertising systems. But the BBC reports that Muse data is used to train new AI models by default. Meta says it sanitises that data to remove personally identifiable information and offers a setting to opt out. Meta’s stated Gmail and training-data controls
That combination shows why an agent’s governance cannot stop at the model: its permissions, data handling and behavior toward other services shape the consequences of letting it act. Muse’s reported usefulness is tangible, but so is the amount of trust its workflows ask users to extend. The BBC’s account of Muse’s tasks and data practices





















