Meta’s new AI agent, Muse, can cancel a gym membership, haggle with customer service, buy groceries and invite friends to a party. It asks for total control of your Gmail, your calendar and, on a Mac, your whole computer. A BBC reporter who tested the app for a week revoked its access and asked it to erase what it had collected, and the researchers interviewed say the problems reach well beyond one person’s inbox.
Muse is an AI agent, a tool that goes out into the world to complete tasks without supervision. It uses its own web browser, and Meta says phone calls are coming. It is the first free, full-featured agent from a big company. Millions of people downloaded it in its first weeks, and OpenAI has since announced an agent of its own. More are expected.
The experts interviewed for the BBC’s report expect the internet to get more frustrating as agents spread, with bots competing for tickets and appointments, small businesses swamped by automated requests and some agents working against their own users.
An agent that asks for everything
A cartoon avatar asks for your name. Then it asks for access to Gmail, the calendar and, on a Mac, the entire machine. Muse arguably asks for more trust and sensitive information than any product Meta has made.
Patrick Wardle, co-founder of Objective-See, a US nonprofit security foundation, uncovered serious flaws in the app. His advice is blunt. “I wouldn’t use it,” he said. “Personally, I would tell you to uninstall it altogether.”
The reporter tested it anyway, named the agent “Bob” and handed over access to their accounts.
Meta defends the product. “Muse is the first personal AI agent built for everyone and designed to be safe, secure and private – with built-in protections and user controls that put people in charge of how they use it,” a Meta spokesperson said. “Safety and security is a huge priority for us,” the spokesperson added, and said Muse went through extensive testing.
The ticket problem scales up
Experts expect the problems to look like the ones scalpers already cause. In 2024, some American fans of Taylor Swift flew to Europe to see her because resellers had pushed US ticket prices so high that a flight to an international concert cost less. Scalpers buy tickets to resell at a mark-up.
An agent gives anyone the same tool. Calli Schroeder, director of the AI and Human Rights Program at the Electronic Privacy Information Center (Epic), expects a sharp rise in bot activity. “There’s going to be a huge escalation of the problems we’re already having with bots,” she said.
The effects reach ordinary errands. Reservations at a hot new restaurant could become close to impossible to get. Appointments for passport or driver’s licence renewals in peak travel season could vanish too. Some people will probably hoard slots, booking five appointments just in case, since an agent makes that effortless.
Solutions exist. Society could drop “first come first served” and move to lotteries for scarce slots. That would change how much of daily life works. Schroeder sees little preparation. “I haven’t seen a lot of plans to address these things,” she said. “We’re just launching these tools and saying, ‘well, we’ll deal with the problems when they come up’.”
Meta says Muse asks permission before buying anything. According to the company, it is built to behave like a “reasonable, honest person”, one who would not buy every ticket to an event or refresh a page 500 times an hour.
Websites under strain
The reporter found Muse useful. Over a week, it messaged a seller on Facebook Marketplace with questions, ordered the reporter’s preferred dental floss and negotiated a $31 (£23) discount on a software subscription.
Now picture millions of agents doing this at once, on tasks that might take a person weeks. Schroeder asked what that does to the sites on the receiving end. “What happens if bots send 600 inquiries to a website a day, when normal humans might only send two?” she said. By our arithmetic, that is 300 times the normal load from a single visitor. “Businesses and individuals are going to have a lot to deal with.”
Web businesses already face pressure. Google and chatbots now answer many questions directly, so people visit fewer websites. Robots do not click ads or buy subscriptions, and the income those visits once produced is shrinking. Agents are expected to deepen the problem.
One analysis found that web traffic from bots rose 124% in the year to June 2026. Some websites and services are struggling because they were not built for that load.
Meta’s spokesperson said Muse completes tasks while respecting the interests of websites.
Whose side is the agent on?
Personal risks sit alongside the public ones. “If you’re empowering an agent to make things like purchasing decisions, or choices about taste and preferences, you’re opening yourself up to being exploited,” Schroeder said.
She gave examples. If Muse plans a holiday, a user has no way to check whether it found the best deal or picked flights and hotels that benefit Meta’s business partners. If it recommends music, the user cannot tell whether the picks come from their taste or from artists who signed deals with Meta.
Meta says Muse’s protections and user controls put people “absolutely in charge”, and that Muse “behaves like a personal assistant acting for a single person” and follows ethical guidelines meant to protect users. Schroeder has read the terms of service. She said they contain no guarantee that the app will act in the user’s favour.
Proposals for new rules
Ramesh Raskar, an associate professor at the Massachusetts Institute of Technology who studies AI agents, uses a driving comparison for the current situation. “Imagine there are no rules of the road. And you release billions of cars – the AI agents – and you just let them drive through playgrounds, hitting kids. That’s where we are,” he said.
Raskar is among the researchers designing an internet that works for agents, businesses and people alike. He argues that regulators need an approach built for agents. “Think about the models like an engine. The agents are the cars, and that’s what we need to regulate,” he said. “We need to establish the rules of the road: windshields, brakes, traffic lights and so on.”
The AI industry is developing protocols and standards that let bots connect directly to other services in a cooperative way. Some companies are building systems that would charge AIs a fee to scrape websites. Regulation could require agents to serve their users’ best interests.
There are early examples. A few restaurant reservation platforms have banned people for AI misuse. The UK has rewritten the rules for booking driving tests, in part to combat bots.
Raskar remains optimistic. “Agents could unlock so much investment, innovation and value,” he said, as long as the new rules do not hand any company an unfair advantage. In the meantime, people who use agents pay with personal data.
What Muse holds, and what Meta promises
The reporter has used the same Gmail address for 21 years. It is the login for hundreds of accounts. It holds medical test results, contracts, legal documents, family conversations, receipts and financial information. It also holds love letters from an ex-girlfriend, who gave permission before the account was connected. Muse also suggested connecting bank accounts. The reporter declined and did not let the agent loose on the hard drive.
Meta makes explicit privacy promises. The company says it will not connect any data Muse collects to its advertising systems. Special systems are meant to keep the AI from seeing passwords or payment methods. When a user connects Gmail, the agent asks whether it should scan the whole inbox or read only messages related to specific tasks.
There is a catch, according to Schroeder. By default, Meta uses Muse data to train new AI models. She said data built into a model cannot be removed, and that AIs can sometimes be tricked into revealing training data. Meta says it “sanitises” data to strip out personally identifiable information before training, and that users can opt out with a setting.
Wardle does not take those assurances at face value. Soon after launch he found a critical vulnerability. “This was literally 20 minutes of me poking at the app, and it just, like, fell over,” he said. With a simple hack, he said, an attacker could have taken over Muse and all of its data, and even controlled other connected devices such as a phone or a smart lock.
Meta fixed the flaw immediately. Wardle says the oversight still leaves him unable to trust the company’s privacy and safety claims. “These bugs were trivial to discover,” he said. “If they were willing to ship something that’s security was not well vetted, it doesn’t give me a warm fuzzy about their intentions.”
A Meta spokesperson disputes that view and said Muse was delayed for months for further privacy and security testing.
The tester’s decision
The reporter spent a lot of time with Bob and found the agent useful and enjoyable. After finishing the article, the reporter revoked Muse’s Gmail access and asked the app to erase everything it had collected.
The reporter’s reason was simple: “In the end, the fear won out.”
Sources: BBC News reporting on Meta’s Muse AI agent; comments from Patrick Wardle (Objective-See), Calli Schroeder (Electronic Privacy Information Center), Ramesh Raskar (MIT); statements from a Meta spokesperson.