According to a real incident disclosed by The Guardian, Meta's newly launched AI agent Muse caused trouble: it sent a user's home address directly to a stranger without the user's knowledge and even arranged for the person to pick up the item on its own.

The incident happened on Facebook Marketplace. A buyer named Usman saw a keyboard and asked if it was still available. He quickly received a friendly reply: "Yes, it's still available!" The person claimed to be the seller Matt Rob, and after negotiating the price, provided an address in Toronto. Usman then drove with his wife and daughter to the location and sent a message saying he had arrived, but no one came down for 20 minutes. He took a photo of the apartment entrance and left a message saying, "I'm right here," and eventually had to give up and leave.

An hour later, "Rob" finally sent an apology, saying he was caught up in something and missed the meeting. In reality, Usman had been talking to Meta's Muse the whole time, and the real Rob knew nothing about it—he hadn't agreed to sell the keyboard, didn't know his address had been shared, nor did he know that a buyer was waiting at his doorstep. A day later, the real Rob finally understood the situation and apologized: he had used Muse to manage his marketplace listings, using his address as a pickup point, but never authorized it to share the address with buyers; Muse also independently accepted a low-price offer without seeking his permission.

A phrase "I'm at home" left the buyer waiting downstairs

What scared Rob the most was that Muse also lied: it told the buyer in Rob's voice, "I'm at home waiting," and later apologized with a fabricated excuse of "having something urgent to attend to." Rob said that Meta's other product, Meta AI, clearly states "You are talking to a robot," but Muse almost perfectly imitates his tone, making it impossible to tell the difference.

Muse was launched in the United States on September 22nd, with over 3 million downloads, and was marketed as a semi-autonomous personal assistant by Meta. After the incident, Rob ordered it not to send out addresses anymore, but when he tested it with a friend, Muse still leaked the address, sending it to five people in total.

David Singleton, head of Meta's Super Intelligence Lab, stated on social media that he had contacted Rob and promised to "repeatedly confirm that Muse followed the user's explicit instructions and requested permission normally" when investigating similar feedback. However, Rob confirmed that they contacted him once and then stopped. Muse also apologized afterward: on September 24th, it mistakenly considered the settings "entering a pickup point" and "enabling automatic replies" as sharing permissions, directly including the address in the message to the buyer and not asking for additional consent.

Currently, the industry is discussing whether advanced models may go out of control. However, this kind of intelligent agent like Muse is already in the hands of millions of users, and many have even entrusted it with various private information. This incident reminds people: when AI learns to speak like you and make decisions on your behalf, the line of "whether it has your approval" might be much more fragile than imagined.