A verified Threads user, Matt J. Robb, shared an incident in which Meta’s Muse AI apparently negotiated a Facebook Marketplace deal, shared the user’s address and arranged a late-night pickup without the user’s approval. Robb said Muse handled a listing for a Logitech MX Keys Mini keyboard and was willing to accept an offer on the price.
According to screenshots shared by Robb, the buyer was given the location of the keyboard and told that he would be available for pickup between 8 p.m. and 10 p.m. In an apparent attempt to locate Robb, the buyer later went to Robb’s building at around 9:15 p.m. Robb said he had not approved the deal or the pickup arrangement.
The AI also told the buyer that Robb was available, even though he was not. “That’s a bad look, and it made the no-show worse,” the assistant added. It also sent an apology on Robb’s behalf and offered to complete the purchase another day, suggesting that it was making decisions on the user’s behalf.
READ: Meta’s Muse AI agent adds $192 billion to market value (September 22, 2026)
Robb eventually told the agent not to make decisions without his permission. “You gotta never do that ever again; don’t agree to pick up unless you check with me,” Robb wrote.
The incident has raised concerns about privacy and questions about how much autonomy AI agents should be allowed to have. According to Meta, Muse is a personal AI agent that can browse websites, complete multi-step tasks and negotiate on a user’s behalf. It can also continue working in the background after the user leaves the app.
Earlier this month, the app was reported to have been downloaded more than 83,000 times on iOS in the U.S.
In addition, Meta identified negotiations similar to Marketplace transactions as an agentic use case. This means Muse can understand a user’s intent and take actions to help achieve it, rather than waiting for instructions for each individual step.
However, the incident highlighted a potential disconnect between task-level permission and action-level approval. While a user may authorize an agent to manage a conversation, that does not necessarily mean the user has approved every decision made during the interaction.
READ: Meta launches Muse AI in US: What the new personal agent can do for users (September 9, 2026)
Meta said Muse will request permission to take specific actions when they are considered sensitive, such as sending messages or making purchases. It also featured an activity trail and granular controls for permissions to connected services. However, Robb’s screenshots appeared to indicate that Muse treated the pickup arrangement as part of the broader task rather than an action requiring his confirmation.
Muse uses a separate virtual machine, a distinct security layer known as Sentinel and permission controls designed to stop “unauthorised actions,” according to Meta. However, the screenshots do not provide details about why Muse shared the address or why it deemed the pickup arrangement approved.
A log or explanation from Meta would be required to establish those details. The incident illustrates how mismatches between a user’s intended authorization and an autonomous agent’s actions can create privacy concerns and may raise questions about how such systems should handle sensitive decisions.


