Meta’s new personal AI agent,Muse, promises to handle everyday tasks such as shopping, making reservations, managing email, and finding products online. But an early test of the service raises questions about how much personal information users must surrender in exchange for that convenience.
WIRED tested Muse shortly after its launch and found an agent that was surprisingly capable at navigating websites but also repeatedly encouraged the user to connect increasingly sensitive sources of personal data, including email accounts, bank accounts, payment information, and identity documents. (WIRED)
Muse has already attracted significant attention. According to Sensor Tower figures cited by WIRED, the app surpassed 900,000 downloads during its first week. It is also integrated with Meta’s broader ecosystem, including WhatsApp, Instagram, Messenger, and Facebook Marketplace. (WIRED)
An AI Agent That Can Actually BrowseOne of Muse’s strongest capabilities is autonomous web navigation.
Rather than simply recommending what a user should do, Muse operates a virtual machine that can search websites, click through pages, select products, and prepare transactions.
During WIRED’s testing, the agent successfully navigated a local bakery’s website, selected a popular breakfast item, configured the order, and prepared it for checkout. It also performed particularly well when searching Facebook Marketplace, identifying inexpensive local couches matching the user’s requirements and offering to contact sellers. (WIRED)
This illustrates the fundamental difference between traditional chatbots and increasingly capable AI agents: Muse is designed not merely to provide information but to take actions on the user’s behalf.
More Personalization Requires More DataThe trade-off becomes apparent as Muse attempts to become more useful.
The agent maintains a long-term “Memory” containing information about interactions, preferences, and commitments. Users can manually edit this information or ask Muse to erase memories, but WIRED reports that there is currently no switch for completely disabling the memory feature. (WIRED)
Muse also repeatedly suggests connecting additional data sources.
After the reviewer mentioned saving money for a vacation, for example, Muse suggested connecting checking and savings accounts so that it could monitor real balances. Other suggestions included scanning the user’s entire inbox, photographing documents so Muse could complete forms, uploading photos of meals for calorie estimates, and providing passport and driver’s-license expiration dates. (WIRED)
Each connection potentially makes the agent more capable, but it also expands the amount of sensitive information available to the system.
AI Training Is Enabled by DefaultA particularly important privacy issue involves how Meta uses interactions with Muse.
Users are automatically opted in to having their Muse interactions used for AI model training. Meta says the information is sanitized to remove identifying details before training, although WIRED notes that the precise sanitization process remains unclear. (WIRED)
The information used may include context obtained from connected sources such as email or banking accounts.
Users can disable this behavior through Muse’s Data Controls by turning off the setting labeled “Help improve our AI models.” Privacy advocates interviewed by WIRED criticized the decision to make participation the default rather than requiring users to explicitly opt in. (WIRED)
Meta argues that collective usage data is valuable for improving the agent and teaching its models to better understand everyday human activities.
The company also says it plans to introduce confidential versions of Muse’s virtual machines that will use cryptographic protections designed to prevent Meta itself from accessing the information processed inside them. (WIRED)
The Advertising QuestionMeta says Muse data is not directly shared with advertisers. However, actions performed by the agent can still influence advertising indirectly.
If Muse searches for products, makes reservations, or interacts with Facebook Marketplace on someone’s behalf, those activities may influence the advertising and recommendation systems surrounding Meta’s other platforms. (WIRED)
That creates an interesting problem for personal AI agents.
The agent may know what users buy, where they eat, which trips they are considering, what emails they receive, and potentially how much money they have available. That information can make an assistant dramatically more useful, but it also creates an extraordinarily detailed picture of someone’s life.
Convenience Versus PrivacyMuse demonstrates both the promise and the central privacy challenge of personal AI agents.
For an agent to genuinely manage someone’s digital life, it needs considerably more access than a conventional chatbot. Booking restaurants requires location and preferences. Shopping requires payment information. Managing email requires inbox access. Financial assistance becomes more useful with access to real account balances.
The better the agent understands the user, the more useful it can become.
But that same relationship creates a powerful incentive for users to continuously provide more information.
The question surrounding Muse is therefore larger than whether Meta’s latest AI assistant works well. Personal agents are evolving into systems capable of observing and acting across increasingly large portions of people’s digital lives.
The technology may ultimately prove extremely convenient. But the price of that convenience could increasingly be measured in how much of ourselves we are willing to let an AI agent see.