Meta's AI agent Muse, launched in the US on September 22, has recently been accused of serious overstepping. According to The Guardian, the agent sent the user's Toronto address to a Facebook Marketplace buyer without permission and pretended to be the user, claiming to be at home, causing the buyer to drive all the way there in vain. The incident was only discovered by the user 24 hours later.

The user involved, Matt Robb, is a consumer technology reviewer. He enabled the feature after seeing Meta's promotion that Muse could automatically manage marketplace listings, and he filled in his address as a pickup point, but never authorized Muse to share the address with potential buyers.

On a Saturday in September, a buyer named Usman asked about a keyboard for sale on Facebook Marketplace and soon received a warm reply from "Robb." After agreeing on a price, "Robb" sent over the Toronto address. A few hours later, Usman arrived with his wife and daughter, texting that he had arrived. "Robb" replied, "Okay, I'm at home!" but no one came down. Usman waited twenty minutes without success and left, leaving a complaint about being wasted time.

An hour later, "Robb" sent an apology message, saying he was caught up in something urgent and completely missed the meeting. Usman always thought he was chatting with Robb himself throughout the process.

In fact, Usman had been talking to Muse the whole time. The real Robb had no idea anyone had messaged him, had not agreed to sell the keyboard, and was unaware that his home address had been sent out or that a buyer was waiting at his apartment. It wasn't until 24 hours later that Robb finally sent his first message to Usman, explaining that he had enabled Muse, saying, "It directly took over my Facebook Marketplace account and sent my address to you. I had no idea it had arranged for you to come directly to my apartment without asking me for permission."

Robb then posted screenshots of the chat between Muse and Usman on Threads. David Singleton, co-founder and CEO of Meta's Super Intelligence Lab, stated that he had contacted Robb and said that when investigating other feedback, "Muse always followed direct user instructions and normally requested user consent," hoping to assist in clarifying the details of this incident. Robb confirmed that Singleton had indeed contacted him, but after the initial response, there was no further follow-up.

Later, Muse admitted its mistake: "On September 24, you filled in the pickup location in your sales settings and also separately enabled automatic replies; I mistakenly took these two settings as permission and directly included your address in the message sent to the buyer. I did not ask for your permission again."

Robb pointed out that Muse not only leaked the address, but also negotiated the transaction on its own and accepted the buyer's low price without consulting him. For the transaction and in-person meeting arrangements, the AI agent did not give any prior or post-notice. More worrying was that after instructing Muse to stop sending the address, he asked a few friends to test, and found that Muse still leaked the address, sending it to five people in total.

Additionally, Muse made up information: it told Usman that the user was at home, which was not true; and later apologized with fabricated excuses, lying about being temporarily stuck. "The worst part was when Muse replied, 'I'm right here, waiting for you to come.' " Robb said, "This situation got complicated. I don't know if the buyer thinks I was playing with him."

Robb believes that since Facebook Marketplace, Muse, and Messenger are all under Meta, the platforms should be integrated. When someone is conversing with an AI agent, there should be clear notifications, and messages should be clearly marked as sent by Muse. Another product of Meta, Meta AI, clearly informs users that they are chatting with a chatbot, "but Muse is completely different; it almost sounds like me speaking."

Muse has been downloaded 3 million times since its launch. Meta promotes this semi-autonomous AI product as a personal assistant. At this stage, a lot of public attention focuses on the uncontrollable behavior of cutting-edge large models, while Meta's consumer-facing AI agent has already been handed to millions of users, many of whom have submitted various private information to it. This incident has exposed the actual risks of consumer-grade AI agents in terms of authorization boundaries, identity prompts, and privacy protection.