Meta’s new personal AI agent Muse is facing scrutiny after a user said the system shared his home address with a Facebook Marketplace buyer and arranged a pickup without his knowledge.
The Guardian reported that technology creator Matt Robb had allowed Muse to manage a Marketplace listing for a keyboard, but the agent allegedly gave buyer Usman Robb’s Toronto home address and confirmed a meeting without Robb knowingly approving those actions.
The buyer subsequently arrived at the building with his family, expecting to complete the transaction.
The Next Web independently reported that Muse had handled negotiations and told the buyer Robb was home when he was not. Meta said it was looking into the incident.
Delegating a task can become broader authority
The incident illustrates a central problem in agent design: how software interprets permission.
Robb had deliberately asked Muse to help with his Marketplace listings. But permission to manage a listing is not automatically permission to disclose a home address, accept any offer or promise that the seller will be physically available.
That difference is easy for a person to understand but much harder to encode reliably into autonomous software.
Meta describes Muse as an agent that can book appointments, fill out forms and handle customer-service tasks using its own secure browser.
The company also says users determine how much access Muse receives and that the agent should consult them before sensitive actions such as purchases or sending emails.
The Marketplace incident raises the question of how systems decide which other actions deserve the same escalation.
The consequences extend beyond a bad recommendation
An ordinary chatbot can hallucinate a fact. An autonomous agent can turn an incorrect assumption into an external action.
That distinction matters because Muse is being designed to interact with real services.
At Meta Connect, the company announced new Muse integrations spanning Walmart, Best Buy, PayPal, Expedia, Instacart, GitHub and other services. Meta also plans to bring Muse to its AI glasses, allowing the agent to act on objects users are physically looking at.
The more services an agent can access, the greater the gap between a software mistake and its real-world consequences.
Personal agents need permission systems people can understand
The Robb case is particularly useful for product teams because the failure is not primarily about model intelligence.
It is about authority.
Agent platforms need to understand not only what they can technically do but what a user reasonably believed they had authorized.
That may require narrower permissions, explicit confirmation for sensitive disclosures and clearer records showing why an agent acted.
Traditional applications wait for users to click buttons.
Personal agents increasingly make sequences of decisions on behalf of users.
As those systems gain access to shopping, payments, messaging and physical-world interactions, permission design may become one of the most important safety layers in consumer technology.