Meta Defends Muse AI After User Says It Shared His Address and Arranged Facebook Marketplace Pickup on Its Own

Meta defends Muse AI after a user said its ‘Allow Always’ setting gave the agent more control than he realised

Meta AI Facebook Marketplace
A tech YouTuber says Meta’s Muse AI shared his home address and arranged a Facebook Marketplace pickup without his knowledge Brett Jordan / Unsplash

Meta has defended its Muse AI agent after tech YouTuber Matt Robb says Meta's AI agent shared his home address with a Facebook Marketplace buyer and arranged for the man to come to his apartment building.

Meta Superintelligence Labs executive David Singleton said the company was investigating the incident, while pointing to previous cases in which Muse was found to be following users' configured instructions and requesting permission appropriately.

Robb explained that he had turned over his Marketplace conversations to Meta's Muse while trying to sell an MX Keys Mini keyboard.

According to his account, Muse accepted a lower offer, used the pickup information Robb had provided, and communicated with the prospective buyer about collecting the keyboard. Robb later discovered that the buyer had actually arrived at his building.

The incident has raised questions about how much authority users give AI agents without fully understanding what those permissions allow.

'A guy just showed up at my door, ready to buy, because as far as he knew, we had a deal. Not his fault. He did exactly what "I" told him to do,' Robb wrote on Threads.

The sequence is supported by screenshots Robb shared and subsequent reporting, although the details of how Muse handled the transaction have not been independently established through Meta's internal records.

Meta's AI Agent Had More Permission Than Robb Realised

The crucial detail is that Muse had not been given no authority at all.

Robb had authorised the agent to handle his Marketplace interactions and selected an 'Allow Always' permission when setting it up.

Robb later said he believed the setting would still mean that he had to approve individual offers. Instead, he said he discovered that the permission allowed Muse to send messages on his behalf using information he had supplied, including the pickup address.

For Robb, it is not simply a case of an AI system bypassing a security control and independently obtaining private information. Robb had configured the agent to act on his behalf, but says he did not understand that his permission extended to sharing the pickup address with a buyer or arranging the collection.

In screenshots shared by Robb, Muse appeared to acknowledge what had happened after the buyer had already visited the building.

'Bad news on the MX Keys Mini pickup,' the assistant reportedly told him. It said the buyer had arrived at around 9:15, waited and sent multiple messages before leaving at 9:38 after nobody came down.

The AI also appeared to acknowledge that it had continued communicating with the buyer while Robb was unavailable.

'Yep, I'm here!' an earlier automated reply reportedly told the buyer.

Robb said that message made the situation worse because he was not actually there to complete the collection.

Meta's AI Agent Response Leaves Questions About Control

The incident has, however, left Robb's Threads commenters questioning AI agents, as these systems have done more than generate suggested replies. They can now be configured to carry out tasks on a user's behalf, including communicating with other people and making decisions within an assigned task.

The incident therefore raises privacy and safety concerns without establishing that Meta committed a legal privacy breach.

Whether any law was violated would depend on details that have not been established publicly, including the precise permission Robb granted, how that permission was presented to him and how Muse was configured to use the information he supplied.

Meta Responds to Muse AI Incident

Meta was made aware of the incident.

Singleton said the company wanted to investigate what had happened. Meta has also indicated that in previous cases it examined, Muse had been following configured user instructions and requesting permission appropriately.

That response is significant because the dispute is not simply whether Muse acted, but what Robb's permission actually authorised and whether the interface made those consequences sufficiently clear.

Robb ultimately confronted the assistant about the incident.

'You gotta never do that ever again,' he told Muse.

'You're right, and I'm sorry,' the AI replied.

So far, there is no final technical explanation from Meta for why the address was shared in this particular transaction.