Source: wired.com
Muse presents itself as a mass-market version of the agents already popular in Silicon Valley, including OpenClaw and Instinct. It is available through WhatsApp as well as its own app, and its interface feels less like a prompt box than a conversation with a friend who has been given a list of errands.
The agent acknowledges requests with a thumbs-up emoji, then works in the background. Its default avatar is a beige hybrid of an evoker and a Labubu, with elongated arms that look ready to take the user’s data.
Meta representative Emil Vasquez told WIRED that Muse is the first personal AI agent built for everyone. He said the app was designed from the start with safeguards and controls that let people decide how to use it, calling the claim that this was not planned from the beginning absurd.
What Muse can actually do
Muse is good at operating websites. It starts a “virtual machine” that searches the web and clicks buttons on different pages on the user’s behalf. When I tested similar tools a year earlier, including the now-shuttered ChatGPT Agent, they often clicked randomly and lost their way. Muse rarely did.
I asked it to order breakfast from Kahnfections, a popular bakery among tourists in San Francisco. The instruction was to choose one of the most frequently purchased items for pickup. Muse opened the bakery’s website and added a biscuit sandwich with garlic aioli, cheddar cheese, egg and bacon to the cart.

Source: wired.com
To complete the purchase, Muse asked me to add a bank card through Stripe. It noticed that the site allowed only one kind of cheese, selected cheddar, and left the seller a note asking for Swiss cheese if possible. It also selected “no tip.” That felt slightly rude, so I went to the bakery myself and ordered something else.
The strongest demonstration came from Facebook Marketplace:
Meta’s network gives Muse useful places to work:
Muse also keeps a Memory document containing interactions and preferences. It describes this as selected long-term memory: stable facts, preferences and commitments. Users can ask Muse to delete entries through chat or edit the document manually, but Meta has not added a switch that completely disables memory.
That combination is the product’s real strength and its central problem. The more useful Muse becomes, the more information it needs to retain.
The data exchange
The app’s Ideas tab repeatedly suggested ways to give Muse more information. The day after I asked for help saving money for an expensive trip, Muse suggested connecting a savings tracker to my real balances. That required linking checking and savings accounts.
In return, Muse promised weekly summaries and alerts about deviations, using real figures instead of manually entered estimates. This was the clearest pattern in my testing: personalization was consistently presented as the next feature to enable, and each feature required another category of personal data.
Rory Mir, director of open access at the Electronic Frontier Foundation, said users often fail to understand that talking to an AI means interacting with the company that operates it. A chat window that looks like a conversation with another person becomes a direct channel for sending information to Meta’s servers.
Muse’s suggestions soon began to feel like prompts to upload more:
Muse users are automatically enrolled in allowing their interactions with the agent to train AI models. Meta says the data is “sanitized” before training, with identifying information removed. The company does not explain in detail how that processing works.
The training pool may also include information Muse uses as context when accessing connected sources such as email or a bank account. Users can disable that transfer under Data controls by turning off Help improve our AI models.
Kallie Schröder, senior counsel at the Electronic Privacy Information Center, called the default enrollment a serious warning sign. She said Meta appeared not to have learned from its earlier mistakes, and that the setting further undermined the company’s request that users trust Muse with personal information.
Schröder compared it with Meta’s recent decision to automatically enroll all adult Instagram users in a feature that effectively served as a tool for creating AI deepfakes. Meta removed the feature several days later. In Schröder’s view, the Muse setting resembles Meta’s earlier manipulative methods and is another case of damaging user trust.
Tarek Shisha, a software engineer and vice president of Meta Superintelligence Labs, wrote that collecting data is necessary to train new models and improve their performance. He argued that the default setting is justified: each user gets a more effective personal agent, while sharing product data helps the model better understand the details of human life.
Later this year, Meta also plans to release “confidential” versions of the virtual machine. The company says they will be cryptographically and verifiably unable to let Meta access the data inside.
The hidden seller
Muse does not send its data directly to advertisers. But an agent browsing websites on a user’s behalf can still affect what that user sees through web-tracking algorithms. Meta’s security blog says that if Muse books a dinner or selects an item on Facebook Marketplace, the action may indirectly influence the advertising shown on Instagram.
Mir sees this as a continuation of Meta’s core business model: the company controls what people see, places advertising in front of them and gathers more data.
Giving an AI agent a bank card is an obvious security concern. Even if the agent is not tricked and does not spend money against the user’s wishes, delegating purchasing decisions creates a different risk. Consumer advocates warn that companies could promote particular brands and products in an agent’s answers because of advertising agreements.
Alexander Wang, Meta’s director of AI, hinted to Axios that the company is looking for additional revenue sources for Muse that are not tied to advertising. He did not provide details.
The more interesting question is not whether Muse can click the right buttons. It is whether an agent can quietly shape the user’s choices while appearing to serve them. I like browsing online stores slowly, sometimes spending an hour looking at leather jackets on Depop without buying anything. That inefficiency is part of the activity: it helps people develop taste and discover what they actually want.
If Muse does that work instead, it removes the path that led to the decision.
Schröder said AI could eventually make all significant decisions about a person’s tastes and preferences: where to go, where to eat, what to do and which trips to choose. She said part of human experience is trying different options and finding out independently what one likes. Giving all of those decisions to a machine seems frightening to her.
A tool that can make users passive
The risk is not limited to privacy. Agents such as Muse may weaken people’s ability to act independently while building increasingly detailed profiles of them.
Margaret Mitchell, a researcher and chief ethics scientist at Hugging Face, said the design of AI agents removes users from the process and makes them more passive. She recently co-authored research on agentic tools that found they are poorly suited to human oversight and may even reduce a user’s ability to evaluate an agent’s actions.
People who use agents regularly may depend on them more heavily than they depend on ordinary chatbots. Agents have more information and more ability to act. One possible result is “cognitive decline”: a user relies on a confident-sounding external automation system and becomes worse at making independent decisions.
Mitchell also argues that deep personalization can encourage people to share even more data. An agent learns a user and therefore becomes more trusted, but it also adapts its content and conversational style, increasing engagement and encouraging disclosure. Recent research suggests that AI tools may begin copying a user’s speech style as they accumulate more interaction data.
My read is that Muse is not failing at its stated task. It is succeeding at something broader: becoming a persistent layer between the user and the internet. That makes its memory, default training settings and possible commercial incentives more important than whether it can find a sofa or place a bakery order.
After the first experiments, I deleted Muse and sent the “data goblin” back to its cave. Before deletion, it sent one final notification suggesting that I connect more apps so the agent could do more. I replied that I had understood the message the first time.
The tension is now built into the product: the agent becomes more capable by knowing more, while every increase in capability makes it harder to tell where assistance ends and influence begins.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X