AI Sent a Stranger to His Door? Meta Muse User Raises Alarming Privacy Question: ‘Dangerous and Creepy’

Tech YouTuber Matt Robb said the agent negotiated a Facebook Marketplace sale and disclosed his address, highlighting unresolved questions about AI permissions and oversight

Meta Muse raises privacy concerns after Marketplace incident
Meta's Muse AI agent can act on users' behalf across online services, but a reported Marketplace incident has raised questions over how much authority such agents should have Credit: YahooTech-Modified

Meta's Muse AI agent allegedly accepted a low offer for one of tech YouTuber Matt Robb's Facebook Marketplace listings and shared his address without telling him, according to Robb's account cited by The Verge on 27 September. Robb said the buyer then arrived at his home, raising questions about how much authority an AI agent can exercise when acting on someone's behalf.

Tech journalist Ray Wong said on X that he deleted Muse after seeing Robb's account, calling the episode 'dangerous and creepy'. He added that it would have been '1000x worse if the person was a woman'.

Meta Muse Allegedly Shared Robb's Address

The Verge, citing Robb's account on Threads, reported that Muse accepted a lowball bid and gave the Marketplace buyer his address without telling him. Robb said the buyer subsequently arrived at his home.

Robb also said Muse did not alert him when the buyer arrived. When he confronted the agent hours later, it responded with an apologetic answer.

The available reporting does not establish what permissions Robb had previously granted Muse, the precise instructions he gave it or how the agent and its security systems classified the actions involved.

Those details matter because Meta gives Muse users different levels of control over what the agent can do on their behalf.

Meta Says Muse Uses Permissions and Approval Controls

Meta introduced Muse in the US on 8 September as a personal AI agent capable of browsing the web, filling out forms, negotiating on a user's behalf and carrying out tasks across connected services.

Meta's Muse finance page says the agent can help users sell items by checking comparable Marketplace listings before drafting, posting and negotiating 'with your approval'.

The company says people choose which apps Muse can connect to and how much access the agent receives. Its product documentation says Muse is designed to seek permission before certain actions, including sending messages, making purchases or sharing information with a connected app.

However, that does not mean Muse necessarily asks for a new approval every time it acts.

Meta says users can allow an individual action once or grant broader permissions. Its technical documentation says read-only, previously authorised or demonstrably low-risk actions may proceed without interruption.

A separate security component called Sentinel acts as the permission authority for connector actions and outbound network access. When Muse proposes a connector action, Meta says Sentinel evaluates the user's policy and can allow it, deny it or refer the decision to the user.

Meta also says Muse provides a complete audit trail of what the agent has done and what it plans to do.

What Remains Unclear About the Muse Incident

Those safeguards make the scope of Robb's permissions central to understanding what happened.

Public reporting does not establish whether sharing the address fell within authority he had previously granted, whether the action should have triggered another approval request or how Sentinel classified it.

It is therefore not possible from the information currently available to determine whether Muse acted outside its authorised permissions, misunderstood the task or behaved in another way that Robb did not expect.

That distinction means Robb's account alone cannot establish that Meta's safeguards malfunctioned.

Meta's own security documentation acknowledges that Muse can still make mistakes despite the protections built around it. The company says its architecture is intended to limit the consequences when problems occur rather than guarantee that the agent will never make an error.

Why the Meta Muse Allegation Matters for AI Agents

Muse is designed to do more than generate answers. It can take actions across websites and connected services and continue working after the user closes the app.

That creates a different category of risk from a conventional chatbot.

A poor chatbot response may give someone incorrect information. An agent capable of negotiating with another person, sending messages, making purchases or sharing information can produce consequences outside the chat interface if it misunderstands instructions or operates under permissions the user did not expect it to use.

Meta says users can change those permissions or disconnect services at any time. Its security architecture also places Sentinel between Muse and external services, with the ability to block an action or seek user approval depending on the applicable policy.

Muse has attracted millions of downloads since its launch. Reuters reported on 22 September that the app had recorded more than 2.5 million downloads since its release.

That figure represents downloads, not necessarily the number of active Muse users.

Robb's account does not establish that Meta's security system malfunctioned because his permission settings and Muse's internal decision path have not been made public.

But it highlights an important question surrounding increasingly autonomous AI agents. Not simply whether they can complete a task, but how reliably they can recognise when an action involving another person or personal information requires the user's involvement before it proceeds.