Meta’s Muse Is Better at Surveilling Than Helping Me

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane September 20, 2026 5 min read
Meta’s Muse Is Better at Surveilling Than Helping Me


Meta’s new AI assistant, Muse, has gathered over 900,000 downloads in its first week.

The app appeared on Instagram with a prompt to handle daily tasks like booking reservations or managing emails. It connects to bank accounts and email inboxes. The default avatar is a beige figure resembling an Ewok, arms outstretched as if ready to grab user data.

Muse acts as a mainstream version of AI agents already popular in Silicon Valley, such as OpenClaw and Instinct. The company reports high engagement. Users interact by texting the agent task requests. The AI responds with a thumbs-up emoji and works in the background. Muse is also available through WhatsApp.

After using the tool for a few days, the experience felt more focused on data collection than completing tasks.

Meta spokesperson Emil Vazquez told WIRED that Muse is the first personal AI agent built for everyone with built-in protections and user controls. He described any other approach as ludicrous.

Web Browsing

Muse’s ability to surf the web is impressive. It uses a virtual machine to browse the internet on your behalf, running searches and clicking through pages. When testing similar tools last year, such as the now-defunct ChatGPT Agent, the AI’s clicks were erratic. Muse rarely gets lost.

I asked Muse to order breakfast from a local bakery called Kahnfections in San Francisco. The agent visited the website and added a biscuit sandwich with garlic aioli, cheddar cheese, egg, and bacon to the cart.

The app requested a credit card via Stripe to complete the purchase. Muse noted that the site forced a single-select choice for cheese, so it picked cheddar and added a note asking for Swiss. The agent selected the no tip option. I ended up walking to the shop to order something else.

Meta uses its platforms to promote Muse. WhatsApp and Messenger handle onboarding. Instagram features a large library of Reels videos. The Facebook Marketplace integration stood out during testing. Muse found cheap, local couches within my parameters and offered to message sellers to arrange pick-ups. The agent nudged me the next day to consider getting the couch I said was my favorite.

Muse stores details about interactions and preferences in a Memory document found by tapping the avatar. The description reads: “Your curated long-term memory: durable facts, preferences, and commitments.” Users can request a wipe or manually edit the file. Meta does not currently offer a toggle to turn off the memory feature.

Data Collection

Under the ideas tab, Muse constantly suggested connecting more information. After I said I wanted help saving money for a vacation, the app offered to wire a savings tracker to real balances. It claimed this would make weekly summaries work off real numbers instead of estimates.

Rory Mir, director of open access at the Electronic Frontier Foundation, notes that talking to an AI means talking to the company hosting it. He says chat windows are just a way to put information directly into Meta servers about ourselves.

Every suggested interaction felt like an opportunity to upload more data. Ideas included scanning the whole inbox to flag messages, photographing documents for filing, photographing meals to estimate calories, and checking passport and license expiry dates.

Muse users are automatically opted in to having their interactions used for AI model training. Meta says this data is sanitized to remove identifying information. The collection may include context used when accessing connected data sources like an email inbox or bank account. Users can turn off this collection in the settings under Data controls by disabling Help improve our AI models.

Consumer advocates see the forced opt-in as a major red flag. Calli Schroeder, senior counsel at the Electronic Privacy Information Center, says this undermines the argument that users should trust Muse with all information. She compares it to Meta’s recent history of manipulative tactics, such as automatically enrolling adult Instagram users in an AI deepfake tool before pulling the feature.

Tarek Sheasha, vice president at Meta Superintelligence Labs, defended the practice in a blog post. He wrote that every Muse user gets a better personal agent as the collective use helps the model understand human life. Meta plans to release confidential versions of its virtual machine later this year that prevent the company from accessing the data inside.

Tracking Impact

Muse data is not directly shared with advertisers, but the agent’s browsing can impact what users see. The safety blog suggests that if the agent makes a dinner reservation or picks a product on Facebook Marketplace, that action could indirectly influence ads on Instagram.

Rory Mir says this is a continued trajectory of controlling what people see and collecting more data.

It is rational to be anxious about handing over a credit card to an agent. Outsourcing shopping decisions can have unintended consequences. Advocates warn that companies might prioritize certain brands in an agent’s output based on sponsorship deals. Meta’s Chief AI officer Alexandr Wang hinted in an interview with Axios that the company is looking for revenue opportunities in Muse that are not ads.

I enjoy the slow scrolls of online shopping where I can spend an hour on a website and leave with nothing. Browsing Depop for leather jackets builds a sense of taste. If Muse does everything, I lose the journey that led to the decision.

Calli Schroeder says that at some point, the AI makes all meaningful taste decisions. She finds the concept of turning that over to a machine horrifying.

Passive Users

Relying on agents could degrade functioning while these tools collect data.

Margaret Mitchell, chief ethics scientist at Hugging Face, says the design of AI agents disengages users. She co-wrote a research paper unpacking how agentic tools are not effectively designed for human oversight and may worsen the ability to assess what the agent is doing.

Users may become overly reliant on the tools since agents have access to more information. One potential impact is cognitive degradation, where users rely on automations from a confident-sounding source and are less able to make independent decisions.

Mitchell sees high levels of personalization as priming users to share even more data. She notes that aligning to a user in what it talks about further pulls people into interacting and divulging private information. Recent research shows AI tools may start to mirror a user’s speaking style as they collect more interaction data.

I decided to send this data collector back to its cave and deleted the app.

Before I could remove Muse from my phone, the agent sent one final ping. It read: “Connect your apps so I can do more.” I heard you the first time.


Scroll to Top