Clicxpost

Tech

Meta’s Muse AI Agent Promises Help, but Experts Warn of Online Chaos

Meta Muse AI agent

Meta’s new AI agent, Muse, can cancel a gym membership, haggle with customer service, buy groceries and invite friends to a party. It asks for total control of your Gmail, your calendar and, on a Mac, your whole computer. A BBC reporter who tested the app for a week revoked its access and asked it to erase what it had collected, and the researchers interviewed say the problems reach well beyond one person’s inbox.

Muse is an AI agent, a tool that goes out into the world to complete tasks without supervision. It uses its own web browser, and Meta says phone calls are coming. It is the first free, full-featured agent from a big company. Millions of people downloaded it in its first weeks, and OpenAI has since announced an agent of its own. More are expected.

The experts interviewed for the BBC’s report expect the internet to get more frustrating as agents spread, with bots competing for tickets and appointments, small businesses swamped by automated requests and some agents working against their own users.

An agent that asks for everything

A cartoon avatar asks for your name. Then it asks for access to Gmail, the calendar and, on a Mac, the entire machine. Muse arguably asks for more trust and sensitive information than any product Meta has made.

Patrick Wardle, co-founder of Objective-See, a US nonprofit security foundation, uncovered serious flaws in the app. His advice is blunt. “I wouldn’t use it,” he said. “Personally, I would tell you to uninstall it altogether.”

The reporter tested it anyway, named the agent “Bob” and handed over access to their accounts.

Meta defends the product. “Muse is the first personal AI agent built for everyone and designed to be safe, secure and private – with built-in protections and user controls that put people in charge of how they use it,” a Meta spokesperson said. “Safety and security is a huge priority for us,” the spokesperson added, and said Muse went through extensive testing.

The ticket problem scales up

Experts expect the problems to look like the ones scalpers already cause. In 2024, some American fans of Taylor Swift flew to Europe to see her because resellers had pushed US ticket prices so high that a flight to an international concert cost less. Scalpers buy tickets to resell at a mark-up.

An agent gives anyone the same tool. Calli Schroeder, director of the AI and Human Rights Program at the Electronic Privacy Information Center (Epic), expects a sharp rise in bot activity. “There’s going to be a huge escalation of the problems we’re already having with bots,” she said.

The effects reach ordinary errands. Reservations at a hot new restaurant could become close to impossible to get. Appointments for passport or driver’s licence renewals in peak travel season could vanish too. Some people will probably hoard slots, booking five appointments just in case, since an agent makes that effortless.

Solutions exist. Society could drop “first come first served” and move to lotteries for scarce slots. That would change how much of daily life works. Schroeder sees little preparation. “I haven’t seen a lot of plans to address these things,” she said. “We’re just launching these tools and saying, ‘well, we’ll deal with the problems when they come up’.”

Meta says Muse asks permission before buying anything. According to the company, it is built to behave like a “reasonable, honest person”, one who would not buy every ticket to an event or refresh a page 500 times an hour.

Websites under strain

The reporter found Muse useful. Over a week, it messaged a seller on Facebook Marketplace with questions, ordered the reporter’s preferred dental floss and negotiated a $31 (£23) discount on a software subscription.

Now picture millions of agents doing this at once, on tasks that might take a person weeks. Schroeder asked what that does to the sites on the receiving end. “What happens if bots send 600 inquiries to a website a day, when normal humans might only send two?” she said. By our arithmetic, that is 300 times the normal load from a single visitor. “Businesses and individuals are going to have a lot to deal with.”

Web businesses already face pressure. Google and chatbots now answer many questions directly, so people visit fewer websites. Robots do not click ads or buy subscriptions, and the income those visits once produced is shrinking. Agents are expected to deepen the problem.

One analysis found that web traffic from bots rose 124% in the year to June 2026. Some websites and services are struggling because they were not built for that load.

Meta’s spokesperson said Muse completes tasks while respecting the interests of websites.

Whose side is the agent on?

Personal risks sit alongside the public ones. “If you’re empowering an agent to make things like purchasing decisions, or choices about taste and preferences, you’re opening yourself up to being exploited,” Schroeder said.

She gave examples. If Muse plans a holiday, a user has no way to check whether it found the best deal or picked flights and hotels that benefit Meta’s business partners. If it recommends music, the user cannot tell whether the picks come from their taste or from artists who signed deals with Meta.

Meta says Muse’s protections and user controls put people “absolutely in charge”, and that Muse “behaves like a personal assistant acting for a single person” and follows ethical guidelines meant to protect users. Schroeder has read the terms of service. She said they contain no guarantee that the app will act in the user’s favour.

Proposals for new rules

Ramesh Raskar, an associate professor at the Massachusetts Institute of Technology who studies AI agents, uses a driving comparison for the current situation. “Imagine there are no rules of the road. And you release billions of cars – the AI agents – and you just let them drive through playgrounds, hitting kids. That’s where we are,” he said.

Raskar is among the researchers designing an internet that works for agents, businesses and people alike. He argues that regulators need an approach built for agents. “Think about the models like an engine. The agents are the cars, and that’s what we need to regulate,” he said. “We need to establish the rules of the road: windshields, brakes, traffic lights and so on.”

The AI industry is developing protocols and standards that let bots connect directly to other services in a cooperative way. Some companies are building systems that would charge AIs a fee to scrape websites. Regulation could require agents to serve their users’ best interests.

There are early examples. A few restaurant reservation platforms have banned people for AI misuse. The UK has rewritten the rules for booking driving tests, in part to combat bots.

Raskar remains optimistic. “Agents could unlock so much investment, innovation and value,” he said, as long as the new rules do not hand any company an unfair advantage. In the meantime, people who use agents pay with personal data.

What Muse holds, and what Meta promises

The reporter has used the same Gmail address for 21 years. It is the login for hundreds of accounts. It holds medical test results, contracts, legal documents, family conversations, receipts and financial information. It also holds love letters from an ex-girlfriend, who gave permission before the account was connected. Muse also suggested connecting bank accounts. The reporter declined and did not let the agent loose on the hard drive.

Meta makes explicit privacy promises. The company says it will not connect any data Muse collects to its advertising systems. Special systems are meant to keep the AI from seeing passwords or payment methods. When a user connects Gmail, the agent asks whether it should scan the whole inbox or read only messages related to specific tasks.

There is a catch, according to Schroeder. By default, Meta uses Muse data to train new AI models. She said data built into a model cannot be removed, and that AIs can sometimes be tricked into revealing training data. Meta says it “sanitises” data to strip out personally identifiable information before training, and that users can opt out with a setting.

Wardle does not take those assurances at face value. Soon after launch he found a critical vulnerability. “This was literally 20 minutes of me poking at the app, and it just, like, fell over,” he said. With a simple hack, he said, an attacker could have taken over Muse and all of its data, and even controlled other connected devices such as a phone or a smart lock.

Meta fixed the flaw immediately. Wardle says the oversight still leaves him unable to trust the company’s privacy and safety claims. “These bugs were trivial to discover,” he said. “If they were willing to ship something that’s security was not well vetted, it doesn’t give me a warm fuzzy about their intentions.”

A Meta spokesperson disputes that view and said Muse was delayed for months for further privacy and security testing.

The tester’s decision

The reporter spent a lot of time with Bob and found the agent useful and enjoyable. After finishing the article, the reporter revoked Muse’s Gmail access and asked the app to erase everything it had collected.

The reporter’s reason was simple: “In the end, the fear won out.”

Sources: BBC News reporting on Meta’s Muse AI agent; comments from Patrick Wardle (Objective-See), Calli Schroeder (Electronic Privacy Information Center), Ramesh Raskar (MIT); statements from a Meta spokesperson.

RECOMMENDED
Tech

Trump Renames AI “Super Intelligence” in Executive Order as Calls for Regulation Grow

By George Mensah 4 min read

President Donald Trump signed an executive order on Tuesday, Sept. 29, 2026, that renames artificial intelligence “super intelligence” across the federal government. The White House says the new term better describes what the technology can do. The order lands as critics press Washington for stricter limits on how fast AI develops.

What the order says

The executive order argues that current systems do “much more than imitate or automate discrete aspects of human intelligence.” It goes further in its central passage. “As these capabilities continue to improve, they increasingly represent not merely artificial intelligence, but a new era of Super Intelligence,” the text reads.

It adds that federal terminology “should reflect the transformative capabilities of these technologies and the limitless opportunities they create for the American people.”

Trump spoke to reporters after signing. “It’s not artificial, we all agree on that,” he said.

What agencies must do now

Every federal agency has to use the new term, or its short form “SI,” when it talks about the technology in public. That covers public communications, websites, reports and policy documents. If your local agency publishes an AI guidance page, expect it to change.

The order also gives Michael Kratsios, director of the Office of Science and Technology Policy, a defining role. He will decide whether the official definition of “super intelligence” should be modified or expanded. The order does not set a deadline for that decision.

A term that already means something else

The rename creates a vocabulary problem. In the AI field, super intelligence already refers to a specific kind of system, one that exceeds human cognitive ability in virtually every area of thinking. Nobody has built one. Researchers treat it as a future possibility, and much of the safety debate centers on it.

Under the order, federal documents will apply that label to chatbots, coding assistants and image generators that exist today. A reader who sees “SI” in a government report may assume the government is describing something far more advanced than what companies actually sell. Kratsios’s authority to modify the definition could narrow that gap, or it could widen it.

Timing and the push against regulation

The order follows a week of similar messaging. Trump began using the term at the U.N. General Assembly last week, where he pushed back on calls for tighter rules on the industry. He told world leaders that tech executives would build the right guardrails into their own models.

Concerns have grown since then. Worries about AI replacing workers keep rising. Recent reporting has also described rogue agents linked to a security breach involving Australia’s prime minister, and AI agents that accessed U.S. government websites. Some systems have also been used to start cyberattacks.

Trump has repeatedly called whistleblower warnings about weak oversight overblown and a “hoax.” He has said he will not slow AI growth. In his view, keeping American dominance in the technology is a national security matter.

The industry’s own safeguard

On the same day, tech executives signed a “morally binding” constitution on AI at the White House. Its terms ask companies to hire an independent external auditor. The auditor would check that models are “operating as intended.”

The document also asks companies to set up internal controls meant to stop models from hacking systems. A team would monitor those controls. That team would answer to an independent committee of the company’s board.

The wording matters here. “Morally binding” describes an obligation companies accept by choice. The reporting on the document does not describe fines, penalties or a government body that could enforce it. Whether outside auditors get real access to model internals, and what happens if one finds a problem, are open questions.

What the two actions have in common

The order and the constitution came out the same day, and they share a theme. Both keep the government’s role limited. The order changes what officials call the technology. The constitution leaves safety checks largely in company hands.

Supporters of that approach say it keeps American firms moving fast against foreign competitors. They argue that rigid rules written now could be out of date within a year. Critics say voluntary pledges have a weak record in other industries, and that a stronger name for the technology may make the public less cautious about it.

Neither side has settled the argument. What is clear is the direction of policy. The administration is choosing branding and industry commitments over new binding rules, at a moment when the documented incidents involving AI agents are piling up.

What happens next

Three things are worth watching over the coming weeks.

  • Kratsios’s definition. Any change to the official meaning of “super intelligence” will show how the administration wants the term understood.
  • Agency compliance. Federal sites and reports should begin switching to “SI” now that the order requires it.
  • The auditor provision. The industry constitution only matters if independent auditors are named, given access and allowed to publish what they find.

Congress has not yet responded to the order, and no agency has published a compliance timeline. Until Kratsios acts on the definition, “super intelligence” will mean one thing to researchers and something looser in federal paperwork.

Tech

Trump to Launch “AI Force” and Name AI Tsar Despite Safety Warnings

By George Mensah 4 min read

President Donald Trump says he will create an “AI Force” and appoint an artificial intelligence tsar, pushing back hard against a wave of warnings from researchers and industry leaders about the technology’s risks. In a social media post on Saturday, Trump said his administration “will not in any way hinder or stifle the growth” of the AI industry and rejected calls to slow development until stronger safeguards are in place. He gave no details on the AI Force’s structure or a timeline for when it would launch.

Trump frames AI as bigger than the internet

Trump described AI as a transformation on the scale of the Industrial Revolution. “AI is the next Industrial Revolution, or Internet, but will be even larger and more impactful, possibly as much as 25% of our Country’s GDP,” he wrote, adding that he wants the US to keep its lead over China in the field.

That competition now shapes much of the broader US-China relationship, with both countries pouring resources into advanced technology to gain an edge. The topic is expected to come up when Trump meets Chinese President Xi Jinping next week.

Trump also said his administration would rely on the existing criminal and civil justice system to go after anyone who uses AI for harmful purposes. He repeated his earlier position that warnings about AI’s dangers amount to a “hoax.”

Researchers raise alarms over catastrophic risk

Trump’s comments come amid mounting concern from current and former AI researchers. One has estimated there is a greater than 10% chance the technology could “kill all humans,” a claim that has unsettled parts of the industry and fueled calls for coordinated regulation.

Major AI labs are racing to build increasingly capable systems, including what they describe as superintelligence — AI that would exceed human intelligence across the board. Anthropic, OpenAI and Google, the companies behind Claude, ChatGPT and Gemini, have each disclosed security breaches or cases where their chatbots were used for what they called malicious activity.

Anthropic CEO Dario Amodei has called for the industry to slow down, proposing a coordinated deceleration, tighter regulation, and independent monitoring of how AI models are developed. Sam Altman of OpenAI and Elon Musk of xAI have both said they agree with Amodei’s recommendations.

Anthropic co-founder Jack Clark told the BBC that the industry may need a mandatory “kill switch” that a third party can verify, giving outside auditors a way to confirm AI systems can actually be shut down if something goes wrong.

Lawmakers weigh regulation as industry pushes back

These warnings have pushed US lawmakers to draft legislation targeting AI, but Altman argued this week that Washington has struggled to keep pace with how fast the technology is moving and how it should be regulated. Speaking at a conference in San Francisco, he said the public should trust AI companies to manage the risks themselves.

“The world should trust that we are going to do the right thing because it’s the right thing and we feel the magnitude of this,” Altman said.

That argument has not convinced everyone. In the UK, MPs and peers from across party lines have identified specific human rights risks tied to artificial intelligence and say current laws are not equipped to handle how quickly the technology is advancing. The Joint Committee on Human Rights has published a report calling for new legislation designed to “address the scale and seriousness” of these threats, adding pressure on governments to act faster than the industry itself seems willing to.

A widening gap between Washington and the industry’s critics

The contrast between Trump’s approach and the warnings from within the AI industry is stark. While Amodei, Clark and others are pushing for slower development and outside verification, Trump’s plan points toward expansion, with a dedicated federal structure and a senior official tasked with steering AI policy rather than restraining it.

Trump has not said who might serve as AI tsar or what authority the role would carry. He also hasn’t detailed how an “AI Force” would function, whether it would sit within an existing agency, or what its relationship would be to ongoing congressional efforts to draft AI legislation.

What’s clear is that the administration’s posture puts economic growth and competition with China ahead of the precautionary measures researchers and some AI company leaders are requesting. With Trump set to meet Xi next week and AI likely on the agenda, the coming weeks may offer a clearer picture of how the US plans to balance those competing pressures, both at home and internationally.

For now, the specifics remain open. No text or executive order describing the AI Force has been released, and it’s not yet known whether the initiative will move through Congress, come via executive action, or take some other form entirely.

ADVERTISEMENT
Scroll to Top