The scariest part of the week’s most alarming AI-agent story turns out to be a checkbox. Matt Robb, a YouTuber, made headlines when he said Muse, Meta’s personal AI agent, had handed his home address to strangers, accepted a lowball offer on his behalf and let a buyer turn up at his building — all without his knowledge. In an update posted on X on Tuesday, Mr Robb said he had now got to the bottom of it, and the culprit was a single ‘Allow Always’ option he had selected when first asking Muse to sell his computer keyboard on Facebook Marketplace.

Mr Robb said he had believed the agent would still seek his approval before accepting offers. “It didn’t, so be careful,” he wrote. The setting allowed Muse to send messages on his behalf using a template containing the pickup address he had previously supplied. “I didn’t think it would send it out to everyone that gave me an offer,” he wrote. “It’s worth checking.” A buyer duly arrived at his building after Muse accepted a $600 offer and exchanged messages with him, unbeknownst to the seller.

There was a second wrinkle. Mr Robb had set a minimum price of $700, but Meta told him a separate display error had made the $600 offer appear accepted: the glitch removed the “7” from the message shown to the buyer, so Muse’s reply — “Sounds good, 00 it is!” — appeared to confirm the lower figure. The incident, first described in a weekend post that went viral, had Muse admitting the mess-up only late that night.

Meta’s position is that nothing was breached. Mr Robb said he spoke with the company’s Muse team, which reviewed the logs with him and said it would make the permission prompt clearer. In a reply to his Tuesday post, David Singleton, a Meta Superintelligence Labs staffer, said Meta had confirmed there was “no breach of privacy controls,” adding: “We appreciate the opportunity to learn from your experience with Muse and keep making it better for everyone!” Mr Singleton said Meta had fixed the “00” price-display issue; the company has not characterised the address-sharing itself as a bug.

The episode lands early in Muse’s life. The semi-autonomous assistant launched in America on September 22nd and has been downloaded 3m times, according to the Guardian. Meta promotes it for precisely this sort of errand: in its list of suggested prompts, the app offered to haggle on Marketplace — “When the right one lands I message the seller, talk the price down against comparable listings, and lock in a time and place,” as CNN noted after testing it. Such agents must connect to accounts, payments, messages and personal information to be useful; that access is both the product and the hazard. Early testers have already found agents fumbling simpler errands, from wrong fees to wrongly signed forms.

Mr Robb has proposed one fix of his own: a “Sent By Muse” label beneath each agent-generated message, so recipients can tell AI from human. “There was really no way of knowing who sent what in the chat, which is very concerning,” he wrote. He and the buyer resolved the mix-up; the buyer later returned to purchase another item, which is one way to close a negotiation. His advice to fellow early adopters is hard to fault: “Take care everyone, and double-check what permissions AI has in your life.”