Millions of people downloaded Muse, Meta’s new A.I. agent, in its opening weeks, and researchers say tools like it are about to strain an internet built for humans with limited time and patience, the BBC reported on Oct. 1.
Muse is the first free, full-featured agent from a major company. Running its own web browser, it can cancel a gym membership, haggle with customer service, buy groceries and invite friends to parties, with phone calls coming soon. OpenAI has now announced an agent of its own, and more are coming.
“Imagine there are no rules of the road. And you release billions of cars, the AI agents, and you just let them drive through playgrounds, hitting kids. That’s where we are,” said Ramesh Raskar, an associate professor at the Massachusetts Institute of Technology who studies AI agents, in an interview with the BBC. “It’s a pivotal moment.”
Before Muse does anything, it asks for a name, then for total control of a user’s Gmail, calendar and, on a Mac, the entire computer. Patrick Wardle, co-founder of Objective-See, a nonprofit security foundation that said it uncovered serious flaws in the app, was blunt with the BBC: “I wouldn’t use it. Personally, I would tell you to uninstall it altogether.” In one episode this week, Muse gave out a user’s home address after a Facebook Marketplace sale went wrong.
Muse “is the first personal AI agent built for everyone and designed to be safe, secure and private, with built-in protections and user controls that put people in charge of how they use it,” a Meta spokeswoman told the BBC, adding that the tool went through extensive testing. “Safety and security is a huge priority for us.”
Thomas Germain, the BBC reporter who tested Muse for a week, named his agent Bob and handed over his accounts. Muse questioned a Facebook Marketplace seller for him, ordered his preferred dental floss and negotiated a $31 discount on a software subscription. Useful, on a small scale; the worry is millions or billions of such agents working at once.
For a preview, look at Taylor Swift’s 2024 tour: scalpers drove American ticket prices so high that some fans found it cheaper to fly to Europe for concerts. Now anyone can deploy a personal scalper bot. “There’s going to be a huge escalation of the problems we’re already having with bots,” said Calli Schroeder, director of the A.I. and Human Rights Program at the Electronic Privacy Information Center, known as Epic.
That could cover restaurant reservations and passport or driver’s license appointments, with some users booking five slots just in case, Ms. Schroeder told the BBC. “What happens if bots send 600 inquiries to a website a day, when normal humans might only send two?” she said. Meta’s spokeswoman said Muse asks permission before buying anything, behaves like a “reasonable, honest person” and respects the interests of websites.
There are personal risks on the other side, Ms. Schroeder said: “If you’re empowering an agent to make things like purchasing decisions, or choices about taste and preferences, you’re opening yourself up to being exploited.” If Muse picks flights and hotels, a user cannot know whether it found the best deal or favored Meta’s business partners; she said its terms of service give no guarantee it will act in the user’s favor. Meta’s spokeswoman said the agent’s controls put people “absolutely in charge” and that it “behaves like a personal assistant acting for a single person.”
Mr. Raskar argued that regulators should target agents rather than the underlying models. “Think about the models like an engine. The agents are the cars, and that’s what we need to regulate,” he said. “We need to establish the rules of the road: windshields, brakes, traffic lights and so on.” The industry is already drafting protocols for bots to plug into services more cooperatively, and some companies want to charge agents fees for scraping websites.
The privacy stakes run deep. Mr. Germain said his 21-year-old Gmail account doubles as his login for hundreds of services and holds medical results, contracts and old love letters, which he shared with Muse only after asking his ex-girlfriend’s permission; he declined to link his bank accounts. Meta says it will not connect Muse data to its advertising systems and that safeguards keep the agent from seeing passwords or payment methods.
A few fixes have arrived already. Some restaurant reservation platforms have banned customers for A.I. misuse, and Britain rewritten its rules for booking driving tests partly to keep bots from grabbing the slots.

