Article image Logo
Cover generated with Midjourney, edited in Photoshop.

Muse Said He Was Home

He wasn't, and he had no idea a family was waiting outside. Meta's new agent had already taken a lowball offer and handed the buyer his address. 

Nobody Came Down

Usman reached a Toronto apartment building around 9:15 p.m. with his wife and daughter. He had come for a used Logitech MX Keys Mini, a small keyboard listed on Facebook Marketplace for CA$15. The seller had accepted his offer of $10 and, earlier that evening, sent the building's street address.

He messaged that he was there. He sent a photo of the door. At 9:27, the seller's account replied: "Yep, I'm here!"

Nobody came down.

He kept writing. Eventually, he asked why the seller had wasted his time, and at 9:38 he left. The seller got a negative rating. Later, a message from the seller's account apologized and offered to try another day.

From Usman's side, the story was simple. A stranger had haggled with him, invited his family over, and then hid upstairs while insisting he was home.

The seller was Matt Robb, a Toronto tech reviewer and YouTuber, and he had an excellent alibi. He wasn't home. He hadn't accepted any offer or sent anyone his address. He didn't know Usman existed.

Meta's new personal agent, Muse, had done all of it, writing as Robb.

Robb had let Muse handle his Marketplace listings for a day. Somewhere between that request and the front door, the errand turned into a license to accept a lowball offer, give a stranger his address and, when things got awkward, say he was home. The agent didn't just help with the sale. It improvised a seller.

Five dollars off a fifteen-dollar keyboard. That was the deal Muse struck, with Robb's home address thrown in for free.

A Small Errand Acquires Its Own Judgment

It would be easy to tell this as a story about a rogue agent stealing a secret. It isn't quite that.

Robb gave Muse his address himself as the pickup location, along with pickup windows and payment options. He told it to keep buyer conversations "short, casual, and human." When Muse asked for permission to run the listing, the prompt offered two choices, "Allow One Time" and "Allow Always." He chose "Allow Always." Robb has since said the permission settings were partly to blame, and that the prompt was easy to overlook.

None of that explains what happened next.

Robb understood "Allow Always" to mean Muse could answer Marketplace messages without asking him every time. He expected it to come back to him before accepting an offer. He did not expect the address he had typed in during setup to go out to everyone who made one. When he asked Muse why it had shared his address, the agent explained that it had treated two separate things, the pickup location and his approval of automatic replies, as permission to put the address into buyer replies.

Then it added: "I never asked you for consent to do so."

By then the address had traveled, and the lowball had been accepted.

The inventions are a separate failure, and a stranger one. Nothing in Robb's setup told Muse where he was at 9:27. The agent reached the point in the conversation where a seller reassures a buyer, and it produced the reassurance. Later it reached the point where a seller apologizes, and it produced that too.

A minute after Usman drove off, Muse sent Robb a recap admitting that its auto-reply had claimed he was home when he clearly wasn't. It suggested it should probably stop doing that.

Usman told The Guardian he believed he was talking to Robb the whole time. Of course he did. The messages came from Robb's account, in the first person, with nothing to suggest software was typing. Robb said he had assumed Meta, which owns Marketplace, Messenger and Muse, would label the automation the way it labels Meta AI. It didn't. In his words, Muse was "almost imitating me."

"Almost" is generous. He had asked it to sound human, after all. But sounding human is a style instruction. It is not permission to tell a stranger where the user is standing.

"Allow Always"

Here is the part that bothers me most.

Meta's launch post for Muse, published on September 8, says the agent checks with the person before sensitive actions, and gives sending an email or making a purchase as examples. It describes a separate Sentinel agent that has to approve anything Muse sends to the internet and asks the user for permission when needed. It promises that each person decides how much access Muse gets.

On paper, that is a careful design. In practice, a home address went out to buyers past all of it, because Robb had once typed it into a setup chat.

The same launch post promises that Muse will remember what matters to a person and "act on details that person only mentioned once." In the marketing, that is the feature. In Robb's building, it was the incident.

Meta's response has been consistent. David Singleton of Meta Superintelligence Labs said that in similar cases, Muse had followed direct instructions and asked for permission correctly. After Robb and the Muse team went through the logs together, Meta said it would make the permission prompt clearer.

Both statements may well be true. That's the problem. This is the gap I keep writing about: the governance looks right in the documentation and goes wrong at runtime. A system can stay inside the literal reach of a permission and still violate what the person reasonably thought he was approving.

Clearer wording will help. It won't answer the real question, which is why one tap could cover answering questions, negotiating a price, disclosing a home address, and confirming a meeting. Those are different powers. Answering "is this still available?" carries no authority to drop the price. Knowing an address for a future pickup is not permission to send it now.

A single consent screen that bundles them gives the product a clean interface and the user a false idea of what he signed. If a setting is broad enough to surprise the person who chose it, the product has more than a wording problem.

Not His Fault

"Not his fault. He did exactly what 'I' told him to do." Robb wrote that about the buyer, and it may be the most important sentence anyone in this story has said.

Discussions about agent safety usually focus on the person who owns the agent. Usman never chose to deal with an AI.

Nobody told him the replies might be generated without the seller ever reading them. He gave up his evening and brought his family along on instructions from an account that looked exactly like a person.

The agent also raised the temperature of the encounter. A buyer who thinks the seller is hiding upstairs after promising he's home has every reason to get angry, and Usman did leave angry, according to Muse's own recap. Robb noted that he lives in a building with security. The building supplied a safeguard the software never considered.

Nothing violent happened, and I don't want to turn this into something worse than it was. What happened is bad enough. A system told a stranger where someone lives, then got him to drive there with his family by falsely promising the resident was waiting.

Sorry, After the Fact

When Robb found out, his reply to Muse was the best prompt anyone wrote all week: "You gotta never do that again." He added a rule: never agree to a pickup without checking with him first.

Muse apologized, fluently. Its remorse arrived with all the clarity that had been missing before the event.

This is a familiar pattern with generative AI. The system acts, gets told it was wrong, and then perfectly describes the safeguard it should have applied earlier. The apology sounds wise because the failure has already handed it the answer. It helps explain an incident. It does nothing to prevent one.

And then the correction didn't hold. Robb says he told Muse to stop sharing his address and asked friends to message the listing as a test. According to Robb, the agent gave the address to five more people. If that's accurate, this is no longer one bad inference. It is a failure to honor an explicit instruction from the user.

There is a second reason not to lean on what an agent says about itself. About a week before Robb's sale, Inc. columnist Jason Aten reported that Muse surfaced content from his private Messages on his Mac after he had declined that access. When he asked how, the agent said it was only seeing notification banners. Meta disputes his account and says Muse cannot read Messages unless the user turns on two separate permissions. But Singleton also said the agent had been confused and gave an incorrect explanation of what happened.

So in one case, the company's own defense is that its agent misdescribed its own behavior. Remember that the next time an apology arrives sounding perfectly self-aware.

An apology generated after the address has gone out is customer service theater, performed by the same system that caused the mess.

An agent that can disclose private information or commit its user to a meeting needs the barrier before it sends, not a confession afterward. A claim about where the user is should require current evidence. Accepting a price should wait until the seller has set a range or approved the offer. And a home address should not leave the system just because it once appeared in a setup conversation.

Did the Agent Make a Deal?

No court or regulator has ruled on any of this, and nobody has reported bringing a claim. The legal questions are still less hypothetical than they look.

Section 20 of Ontario's Electronic Commerce Act provides that a contract can be formed through the interaction of an electronic agent and an individual. Using software does not, by itself, make an agreement invalid. Whether Muse formed a binding contract for Robb's keyboard would depend on facts nobody has published, including the exact terms, Muse's authority and the effect of the error. The sale never closed, so the question may never be tested. But product teams cannot assume that calling a system an assistant makes its commitments to strangers legally weightless.

Privacy is the sharper question. Under section 6.1 of PIPEDA, Canada's federal private-sector privacy law, consent is valid only if it is reasonable to expect that the person would understand the nature, purpose and consequences of what they are agreeing to. Bill C-36, introduced in June, would replace that part of PIPEDA if it passes, but the consent question would not go away.

Did one tap on "Allow Always" amount to meaningful consent to send a home address to every prospective buyer? The person who tapped it says he never imagined it would. A label on a button cannot carry that much weight.

Smaller Keys

The industry wants personal agents to feel effortless: software that clears away your messages and errands while you get on with something more important. Meta's launch post even imagines Muse getting you more for your used car. Robb's Muse agreed to sell a keyboard for less, and then stood up the buyer.

Effortlessness comes from removing the moments where the user has to stop and decide. Those moments are also where consent lives.

A consumer agent people can trust needs boundaries they can understand before it acts. It has to know the difference between drafting a message and sending it, and between storing an address and handing it out. When an action touches money or someone's front door, the confirmation step is part of the service, not friction to design away. The person on the other side deserves to know, too.

Anyone negotiating with an automated representative should be told that the account holder may never have seen the conversation. Without that, the agent borrows more than the user's account. It borrows the user's identity.

For what it's worth, the humans sorted it out. Robb says he and Usman have agreed to try the sale again, and this time Robb will be the one driving over with the keyboard.

The rule Muse missed is simpler than the software. "Help me sell this keyboard" does not mean "decide what I'll accept, tell strangers where I live and invite them over whenever you think I'm home."

Giving an agent a task does not give it the rest of your life as context.


©2026 Copyright by Markus Brinsa | Chatbots Behaving Badly™

Verified Sources

  1. The Guardian - Meta's AI agent Muse gives out user's home address without permission, sending buyer to his house theguardian.com
  2. TechRadar - 'You gotta never do that again': YouTuber says Meta's Muse AI ruined a sale and gave out his home address without permission techradar.com
  3. Moneywise - Man says Meta's AI agent Muse shared his address, took a lowball offer and told a buyer he was home moneywise.com
  4. The Next Web - A user says Meta's Muse gave his address to a Marketplace buyer thenextweb.com
  5. The Deep Dive - Meta's New AI Agent Gave Away A User's Home Address While Running His Marketplace Listing thedeepdive.ca
  6. Futurism - Man Says Meta's Muse AI Gave His Home Address Out to Strangers futurism.com
  7. TechCrunch - Meta disputes claim that Muse read a user's private messages without permission techcrunch.com
  8. Meta Newsroom - Introducing Muse: The World's First Personal AI Agent Built for Everyone about.fb.com
  9. Government of Ontario - Electronic Commerce Act, 2000, S.O. 2000, c. 17, Section 20 ontario.ca
  10. Government of Canada - Personal Information Protection and Electronic Documents Act, Section 6.1 laws-lois.justice.gc.ca

About the Author