For Matt Robb, the choice to try out an AI personal agent was easy. He’s a tech reviewer. To test the latest innovation, he downloaded Meta’s Muse to handle his Facebook Marketplace messages.
It didn’t take long for the new tech to backfire. Within four days, the AI personal agent accepted offers below asking price, gave multiple prospective buyers his home address and told one buyer that Robb was at a pickup location when he wasn’t even aware of the interaction.
As a YouTube technology reviewer with a degree in computer science, Robb is accustomed to quirks that come with new products, especially AI, but said that before his experience with Muse, his feelings about AI were mostly positive.
“Now I feel like, okay, I kind of get the concerns now,” Robb told USA TODAY.
Meta released its personal assistant, autonomous AI software that takes actions across apps on behalf of a user, on Sept. 8. The company touted it as “a secure, private personal AI agent that proactively helps with people’s goals and suggests ideas.”
AI personal agents, sometimes called personal assistants, are distinct from chatbots like OpenAI’s ChatGPT or Anthropic’s Claude because they can take action on a user’s behalf, such as sending an email or making a purchase. Experts say they also bring new risks.
How an AI Agent Shared a User’s Address
Robb decided to test Muse on Facebook Marketplace, a platform also owned by Meta, to handle incoming messages from prospective buyers. On Sept. 26, he got a bite from someone who wanted to buy his keyboard. That’s when the issues began. Muse accepted an offer $100 below asking and sent Robb’s address without notifying him of the interaction or telling the buyer they were speaking with an AI agent.
In a later conversation addressing the issues, Meta told Robb that an error on its end caused the pricing issue. The company also said he had given the agent permission to send messages on his behalf using a template it assembled from information it requested during setup, including his pickup address.
“The part that threw me off was, it didn’t even admit that it’s an AI. It was talking as if I was talking,” he told USA TODAY, adding that it mimicked his “lowkey” tone and casual voice.
In one message reviewed by USA TODAY, Muse wrote, “Yep, I’m here! …Message me when you’re at the door.”
The buyer responded that he was also there, sending a picture of the apartment to confirm the location. No one showed up, and he left.
About two hours later, Muse — still imitating Robb — wrote, “Hey, really sorry about tonight, got tied up and missed you completely. My bad for wasting your time. The keyboards still here if you want to try again another day, lmk.”
The buyer gave Robb a poor rating. Robb was finally notified when Muse sent an apology.
“Muse actually popped up, like, ‘Hey, Matt, I did something bad today,'” Robb said. The message informed him of the interaction — or lack thereof — that had taken place, taking full responsibility.
The encounter went viral when Robb posted about it on Threads. “Deleted Muse after seeing this post,” one person responded. In a follow-up post, Robb shared parts of a conversation he had with Meta to figure out what went wrong.
“I did go into this knowing it’s new, it’s experimental,” he said. “It’s not like I blindly went into it, but at the same time, I’m glad it happened to me, and not someone more vulnerable.”
How AI Agents Differ From Chatbots
September has been a busy month for the AI personal agent market. Around the same time Meta released Muse, three other AI assistant companies were also growing: Instinct announced a fundraiser valued at $2.5 billion, Town was reportedly in talks to raise $1 billion, and Ollie raised $7.5 million.
On Sept. 29, OpenAI announced its own version of a personal agent called “dots,” meant to compete directly with Meta’s Muse.
The impact of this rise in personal agents can also be seen among consumers. A recent Visa survey found that 64% of respondents expect to use AI shopping agents within two years, and 56% would already let AI agents search and compare products.
According to Michael Reitblat, who runs an AI commerce platform called Forter, agentic traffic more than tripled in a month since Muse and Instinct launched. In its first week alone, Muse made up 48% of all agentic orders on Forter.
Personal agents are useful “because they can take an arbitrary input and act,” said Ian Rogers, chief human agency officer at cybersecurity company Ledger. “But that’s also exactly where the danger comes in.”
What Makes Personal Agents Risky?
This danger is sometimes referred to as the “lethal trifecta,” according to Rogers. It is the combination of “access to secrets, input from the outside world and exfiltration risk.” Exfiltration risk is the danger that comes with the ability for the agent to share personal information without authorization.
“We all know it’s not possible for them to be useful if they don’t have access to things like our email or our calendar, our contact list, like these kinds of things, right?” he added. “But those are inherently secrets that you don’t want to be extracted and infiltrated. And so managing that is really important.”
How Are Companies Managing Risk?
Each assistant is tailored to slightly different audiences, meaning risk management looks different across companies.
At Town, for example, the company is focused on assisting in the workplace rather than personal life. Jean-Deniz Greze, the CEO and “Mayor” of Town, said its product emphasizes human approval at every step.
“It is more like a relationship between two beings,” he told USA TODAY. “And as such, trust has to be earned in the relationship before you ask it to do more and more and more.”
Meta’s Muse, tailored to assisting in personal life, emphasizes individual permissions for each app and access point. The company told USA TODAY that individuals can ask Muse to “forget” certain pieces of information and that it has audit trails of every action it has taken.
Still, concern is natural, Greze added.
“If you’re conservative about it, you should stand in the sidelines and see how it works,” he said. “You’ll be sold it enough that you will have plenty of opportunities to decide whether it’s for you.”
Where AI Personal Agents May Be Headed
Despite his interaction with the agent, Robb said he will likely continue to use Muse, perhaps even purchasing a Muse Charm, a physical device for the AI agent.
“I kind of feel like Meta’s gonna fix this,” he said.
Personal agents may soon become ubiquitous, entirely replacing the way users currently search the web or access applications, Greze said.
“I think mostly you will interact with just one assistant that will do things for you on existing websites,” he said.
Rogers voiced a similar prediction, comparing the place personal agents are in now to where email was in the 1990s.
“The notion that everybody would use some hosted email provider was like craziness in 1996, but that’s where we’ve ended up,” Rogers said.
“We’re just moving into an entirely different era of what it means to secure things,” he added. “And these things just take time to kind of catch up and sort themselves out and become true consumer products.”
Greta Reich covers the artificial intelligence industry for USA TODAY through a fellowship from the Tarbell Center for AI Journalism. Funders do not provide editorial input.

Add a Comment