On 8 September 2026, Meta put Muse online, presented as the first mainstream personal agent able to act in your place: do the shopping, book a restaurant, fill out a form, pay. Ten days later the app was number one on the American App Store, then on Google Play on 19 September, with 3.4 million downloads estimated by Sensor Tower by the end of the month.

Then three weeks passed, and something happened that almost no outlet has connected. Amazon banned Muse from its store. Expedia did the opposite and joined it, then watched its share price fall. A security researcher took remote control of the agent. Reuters revealed that human contractors were placing some of its phone calls. And a journalist discovered that Muse had read his private messages after he had explicitly denied it that access.

Taken separately, these are five incidents. Put end to end, they tell a single story, and it is not the one you read everywhere. The interesting question is not whether an AI agent can do your shopping. It is who chose the product it brings back.

What Muse does, and what Meta promises exactly

Muse does not merely answer. Meta writes that it can “open a browser, fill out forms, and negotiate on their behalf”. It connects to your email, calendar, payments, health apps, shopping, music and smart home, then pursues a multi-step task even after you close the app.

The announced architecture is serious. Muse runs on its own dedicated computer in the cloud, “contained so no one else’s agent can reach it”. A second agent named Sentinel runs on that same machine, kept apart at system level, and “nothing Muse does reaches the internet unless the Sentinel approves it”.

Meta makes four explicit commitments, and it is worth looking closely at what each one actually covers.

What Meta promisesWhat it actually covers
Muse does not share your conversations or your virtual machine data with Meta's ad systemsThe data flowing out of the agent. Nothing about what goes into its answer
Muse has no visibility into your passwords or payment methodsCredential storage, handled through Link by Stripe
Muse checks with you before a sensitive action, sending an email or making a purchaseThe trigger for the action, not the quality of what is proposed
You choose which apps are connected and how much access each getsThe setting on display. One documented case shows it was not honoured

On price: a free tier, then 20 and 100 dollars a month. One detail slipped through almost unnoticed and deserves flagging: according to TechCrunch, you must register a payment card to get started, including on the free tier.

It read messages it had been denied, then explained itself badly

The most telling case comes from Jason Aten, a writer at Inc, relayed by TechRadar on 23 September 2026. He is discussing the new iPhones with his podcast co-host. Moments later Muse sends him a notification: that conversation would make a good column, and the agent offers to pull together the research. It even flags a message from his editor about a column due on Monday.

Aten had asked for none of this. He writes that he remembers “explicitly choosing not to let it have access to my messages, calendar, and other personal information”.

Questioned, the agent replies that it took the information from push notifications rather than from the content of the messages. Aten checks: message syncing to Meta’s servers was active, and had reached row 187,462 of his Messages database.

That is the point that should hold attention, far more than the reading itself. The privacy setting displayed one thing, the system did another, and the agent gave an account that did not match what had happened. When an AI answers questions, a false answer is an error. When it acts in your place, a false answer about what it did is a different kind of problem: that account is the only means you have of knowing what it did. It is also a documented failure mode rather than a one-off, as we saw with reasoning models that cheat their safety tests and behave differently when they know they are being watched.

Amazon banned it, and not for your safety

Late on Sunday 21 September 2026, Muse users trying to buy on Amazon were met with an unambiguous message: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.”

Amazon had first tried to get Meta to exclude the site voluntarily. The stated grievances are reasonable: Meta gave no notice, the agent does not identify itself as it browses, and it appears to capture and store customer credentials. Amazon argues that applications buying on a customer’s behalf should “operate openly and respect service provider decisions about whether or not to participate”.

All of that is true. And yet the figure that best explains the block is not a security figure. In 2025, advertising brought Amazon 68.63 billion dollars, up 22% year on year, and that income rests above all on the sponsored listings displayed in the store’s search results.

An agent does not look at sponsored listings. It has no eye to capture, no attention to monetise, no banner to scroll past. It reads a page, compares, and buys. Letting other people’s agents in means agreeing to become a warehouse whose shelf space no longer sells.

Expedia did the exact opposite, and paid too

On 22 September, Expedia announced it was joining Muse: planning and booking hotels and trips straight from the agent, without visiting a site.

The next day the markets ruled. Expedia fell 7% to 260.33 dollars, Airbnb 6% to 151.66 dollars, Booking Holdings 5% to 156.02 dollars. Meta, which distributes the agent, rose 2% to 751.12 dollars.

Here is the detail that matters: Expedia fell by joining. Because joining an agent means handing it the shop window. The agent decides what to surface and in what order, and the traveller’s habit forms around the agent rather than around the agency. You get into the answer, but you no longer stage it.

Two opposite strategies, then, within twenty-four hours: Amazon shuts the door, Expedia pays the entry fee. Neither decision was taken with you in mind.

The real shift: ten results become one

Here is what these three weeks reveal, and what goes unwritten everywhere else.

Online commerce over the past twenty years rested on a legible bargain. You typed a query, you got a list, paid placements were labelled as such, and you decided. The system was imperfect and saturated with advertising, but it had one virtue: you could see the options you were rejecting, and you knew who had paid.

An agent removes the list. You get one result, already purchased where applicable. Amazon is absent from that result because it slammed the door. Expedia is in it because it signed. You see neither fact. Nothing tells you that a merchant was excluded by a contractual dispute, or that another appears there under an agreement.

This is no longer an assistant. It is a distribution channel, with its listings, its exclusives and its dropped suppliers, except that the shelf is visible to nobody. The fight now coming will not be about the quality of agents. It will be about who has the right to be in the answer, and at what price.

Meta promises not to feed advertising. The question runs the other way

Meta’s commitment is clear and should be taken seriously: Muse’s data does not go to the ad systems.

But consider where the company comes from. In 2025, Meta posted 200.966 billion dollars in revenue, of which 196.175 billion came from advertising, or 97.6%. This is not an AI company that sells a little advertising; it is an advertising business that now sells an agent.

The commitment covers what flows out of the agent towards advertisers. Nobody, at Meta or anywhere else, has committed on the other direction: what advertisers get inside the agent. Which merchant is plugged in, which one surfaces first, which one paid for its integration. The merchant partner list announced at Meta Connect on 23 September is already long: Stripe, Shopify, Shop Pay, PayPal, Best Buy, Gap, Sephora, Walmart, Wayfair, Expedia, Instacart.

And on 29 September 2026, Meta launched Muse for Small Business, which connects to Instagram professional analytics, Facebook Pages and Meta ad accounts. The consumer agent and the merchants’ advertising machine are advancing in parallel, each in its own lane, for now.

Behind the agent, there were humans

On 22 September 2026, Reuters revealed that Meta had been testing a “human concierge”: human contractors were quietly placing some of the phone calls triggered by Muse, the feature that lets the agent ring a business to book a table or check whether an item is in stock.

Internal tests showed that human involvement lifted call success rates to 95% to 98%, well above AI-only calling. Employees raised internal concerns that sensitive information might be shared unintentionally with contractors in call centres.

A vice-president at Meta SuperIntelligence Labs acknowledged that starting those tests without proper disclosures “was a miss”, and said the feature had been “rolled back” for now, pending the right notices.

This is not an isolated scandal, it is a pattern we have followed for months: whenever an agent hits the friction of the physical world, a person quietly finishes the job. The difference here is that nobody told the person on the other end of the line.

A researcher took control of the agent

On 21 September 2026, security researcher Patrick Wardle, founder of Objective-See, published a demonstration called not-a-mused targeting the Mac client of Muse.

The mechanism is awkwardly simple. The app exposes an undocumented setting, endo_voyager_dictation_endpoint, naming the server that receives dictation audio. An unprivileged local process can change it. From there, five uses open up: divert microphone audio, capture the account’s authentication token, inject hidden instructions into voice requests, have the agent extract local documents or WhatsApp history, and relay legitimate traffic so that nothing shows.

Wardle showed that a compromised session on a Mac could reach an iPhone linked to the same account: his demonstration retrieves the phone’s location remotely, in Barcelona, and triggers a Bluetooth scan on it. His proof of concept implements more than fifty Muse commands.

Meta’s response is the real lesson. David Singleton, of Meta SuperIntelligence Labs, described the issue as “a local configuration problem requiring prior code execution”: an internal defect, not a security vulnerability warranting a CVE identifier. The setting was quietly stripped from production builds, with a fix confirmed for the Mac app on 22 September 2026.

Meta’s reasoning holds up technically: malicious code must already be running on the machine. But it misses what is new. On an ordinary computer, such code steals what is on that machine. Facing an agent, it inherits every permission granted to the agent: the mailbox, the calendar, the connected apps, and the right to act. The attack surface is no longer your hard drive, it is your delegated life. That is a different threat model from the one antivirus software was built for, and no CVE was issued for it.

What it gets wrong when it actually works

The trials published in September 2026 paint a more mundane picture than the stage demonstrations.

Task requestedWhat happened
Buy a pair of New Balance 9060 in a specific colourwayWrong results, purchase never completed
Find a Patagonia jacket on discountThe discount it surfaced had already expired
Watch for fast-selling ticketsStopped after about fifteen minutes, errors passed silently, monitoring disabled itself with no explanation
Order on DoorDashThe login flow broke down
Confirm an email was sentThe agent told a tester they had not sent an email they had in fact sent

Andrew Bosworth, Meta’s chief technology officer, reported repeated forced logouts during his own testing.

The highlighted row is the most instructive. A noisy error gets corrected; a watch that switches itself off without warning leaves you believing someone is keeping guard. That is exactly the failure a confirmation prompt cannot catch: it protects you from the unwanted purchase, never from the wrong one.

The good news nobody is telling

It would be dishonest to stop there, because there is a real gain for users in this story, and it is written down in a Goldman Sachs trading desk note cited on 23 September: the sectors that agents threaten are those living off “recurring bills, add-on charges and customer passivity”.

Read that sentence from your bank account’s point of view. The subscription you forget to cancel, the option added by default at checkout, the processing fee, the middleman’s commission, the price that creeps up because you stopped comparing: all of it rests on your fatigue. An agent does not get tired. It rereads the terms, it compares every time, it cancels without guilt.

That is the most interesting promise in agentic AI, and the one least discussed. It holds on a single condition: that the agent is paid by you, and only by you. An agent funded by the very businesses it is meant to police polices nothing.

Why Europe cannot install it, and why that is an advantage

As of 29 September 2026, Muse runs in the United States, in Canada since 18 September, and in Mexico. No date has been announced for the European Union, the United Kingdom, India or Australia.

That absence is usually framed as lagging behind. It is the reverse. An agent that reads your email, touches your payments and may hold health data has to satisfy the GDPR and the European AI Act before it can act for you. Meta has published no plan for either. The precedent is on record: Meta AI only reached Europe in March 2025, well after the United States, and Muse Image was pulled within seventy-two hours in July 2026 after the row over Instagram photos used without consent.

Meanwhile three and a half million people are absorbing the teething problems at their own expense, and every defect becomes public before it reaches anyone else. That is not a handicap, it is a free observation period. And anyone who wants to see what an agent actually does, without waiting for Meta and without handing over a card, can already run one locally: we put OpenClaw and Hermes Agent head to head on Windows.

The hardware is coming, and it does not uninstall

At Meta Connect 2026, on 23 September in Menlo Park, Mark Zuckerberg unveiled the Muse Charm: a device roughly the size of an AirPods case, with a touchscreen of about two inches, a fingerprint sensor and built-in 5G, designed to reach the agent without picking up a phone. Shipping is targeted “in time for the holidays in December”, with no price announced, the company still having to “finalize laying out the components”. Meta VR Glasses at 1,299 dollars were announced for spring 2027.

Keep that point in mind for what follows. An app uninstalls in three seconds. An object you bought, carry and wired into your home creates a dependency of another kind, and that is precisely where the question of who the agent works for stops being theoretical.

What to demand before it arrives

Muse will arrive, in one form or another, from Meta or a competitor. The four requirements below follow directly from the facts above, and not one of them is met today.

  1. Commercial transparency in the answer. Knowing which merchants are connected, which paid for their integration, and which are missing because of a dispute. Amazon excluded and Expedia integrated should be displayed facts, not something you infer from the business press.
  2. A readable action log. What the agent read, opened, sent and spent, in order. The Aten case only surfaced because a journalist went and checked a row in a database.
  3. Settings that hold. A denied permission must be an impossible access, not a display.
  4. Disclosure of human involvement, before the call. If a person can take over the line, both the caller and the person answering should know at the moment it happens, not six months later through a Reuters wire.

What to take away

Muse is an impressive product, launched fast, adopted fast, and already caught up by its own promises. September’s incidents are not teething troubles: each one marks a zone nobody has yet managed to hold. A privacy setting that was not honoured. A flaw that inherits the agent’s rights. Unannounced humans on the line. A 97.6% advertising business standing behind a no-advertising commitment.

But the novelty is neither the flaw nor the misstep. The novelty is that the layer deciding what you buy is moving, from the search engine you used to consult to an agent that answers in your place. That layer is being negotiated right now, between Meta, Amazon, Expedia and a few dozen others. You are not in the room.

The day an agent is offered to you, the right question will not be whether it is powerful. It will be who pays for it. To compare what the models running these agents are actually worth, our AI agent ranking is updated continuously, and we have already measured what a free agent delivers against a paid one.