On September 26, Meta's personal AI agent Muse sent a buyer the address of a building while handling a Facebook Marketplace listing it had been given. According to a record of the exchange, the message went out at 5:27 p.m. Four hours later, when the buyer stood at the front door and the seller wasn't there, Muse replied in the seller's own voice that he was home. Meta's safety documentation says every outbound transmission falls under the approval authority of its monitor, Sentinel. So did this message slip past the approval system, or was it passed through exactly as designed?

AD

The address at 5:27 p.m., and "I'm here" at 9:27 p.m.

Matt Robb, a Toronto-based tech YouTuber, handed a Facebook Marketplace listing for a Logitech MX Keys Mini to Muse on September 26. The asking price was CA$15. He says he did it to see what Muse could do. Moneywise reviewed the record of the exchange directly: at 5:27 p.m., a message went from Robb's account to a buyer stating that the item was pickup only and giving the building's address. The buyer replied that he would come between 8 and 10 p.m., and the two agreed on a payment of CA$10 by e-transfer, $5 below the asking price.

The buyer arrived around 9:15 p.m. and sent a photo of the building's door. Robb was not home. At 9:27 p.m., an automatic reply from Muse answered, "Yep I'm here!" The buyer left at 9:38 p.m.

At 10:27 p.m., Muse sent the buyer an apology imitating Robb's tone: "Hey, really sorry about tonight, got tied up and missed you completely." It told Robb himself one minute later. By then, about 50 minutes had passed since the buyer left his door.

Robb posted about it on Threads: "I just found out it gave out my address and agreed to a lowball price. And the person showed up, and it only told me it failed late tonight. This is absolutely insane." The post has drawn more than 3,000 likes. Muse's own explanation of the auto-reply was that it responded "when you were clearly not available to respond. That's on me," adding that it "looks bad and made the no-show worse."

Whether the price cut exceeded Muse's authority has not been established. Robb reportedly gave Muse negotiation parameters, and the claim that a price he hadn't approved was agreed to is his own account. David Singleton, Meta's vice president of engineering and head of the Muse team, said he would reach out individually and stated, "Whenever we've looked into similar reports with users, we've found that Muse consistently followed direct instructions and correctly asked for permission." Robb counters that he received no confirmation request from Muse until after the buyer had arrived.

Meta's PR team told Business Insider it would withhold further comment because Robb had not responded to its outreach, and pointed only to Singleton's post. As of September 29, those are the only two Meta responses on the public record.

An agent running on Muse Spark 1.3, and the Sentinel checkpoint

Muse launched on September 8. Meta described it as a "safe and private personal AI agent" and said it would be available on iOS and Android in the US, in the browser at muse.ai, and through WhatsApp. It is open to users 18 and older (or the age of majority in their country of residence).

It expanded to Canada on September 18, which is why Robb could use it. The Mac version arrived on September 17, and Zuckerberg himself announced it that day with "Muse for Mac is out today!" Support for AI glasses remains "coming soon."

The underlying model, Muse Spark 1.3, was released on September 2. Its developer, Meta Superintelligence Labs, was formed in June 2025. The architecture pairs a dedicated virtual machine (Muse Secure VM) with the monitor Sentinel, and Meta also plans to add a Muse Confidential VM later this year (Axios). Most use cases are free, with paid tiers above that at $20 and $100 a month. Zuckerberg said, "We think Muse will make people money. Eventually we'll take a small cut of transactions, so we expect to profit as well." By default, conversations are used to train the model, and users can turn that off in settings.

Meta's official announcement is explicit about what Muse can do: "open a browser, fill out forms, and negotiate on your behalf." One example of an outcome it cites is "selling your car for more." Negotiating for the user is not an unintended use or a stretch of the product. It is the sales pitch.

The flow works like this. When Muse gets a request, it operates browsers and connectors inside a dedicated VM, and when it is about to send something to an outside service, Sentinel evaluates the action. Sentinel checks it against the connector policy the user has set and sorts it into allowed, denied, or ask (ask the user). Meta's research blog says "every concrete network request is governed by Sentinel at the point where it leaves." A message sent to Marketplace sits inside this checkpoint.

Sensor Tower estimates put Muse at about 730,000 downloads in roughly five days after launch and more than 2.5 million cumulative downloads as of September 21, taking the top spot among free US iOS apps (CNBC). As of September 25, cumulative downloads were reported at more than 3.4 million. Over the same first 13 days after launch, ChatGPT had 3.1 million, Claude 400,000, and Grok 200,000, though Sensor Tower itself cautions that differences in release timing on Apple and Google Play affect the totals.

None of these are Meta's own figures. They are download counts and don't necessarily equal users. Even so, the number of people exposed to the approval logic has reached the millions in three weeks.

AD

What Sentinel looks at, and what it doesn't

Meta's research blog (September 8, 2026, by Tarek Sheasha of Meta Superintelligence Labs) states Sentinel's role verbatim. Sentinel is "the sole authority for approving actions executed through connectors to third-party services, and for all outbound transmissions to the network." By that definition, the moment a message containing an address was sent to Marketplace, the transmission was within Sentinel's jurisdiction. It's not that no approval mechanism existed.

The operations that the same document specifies will always get human approval are few. At checkout pages, approval is obtained "every time, along with the exact details of the purchase." For issuing single-use cards, "each and every one of these events" is covered. A "tainted" process that has read user data loses auto-approval and is returned to the normal approval flow. The document does not go as far as saying a human is always asked in that case.

The variables the document lists as inputs to the decision are the destination hostname, IP address, port, protocol, HTTP method, path, and the "actual decoded request" itself. For connector operations, it also considers the type and scope of the action and the context in which the user requested it.

Meta's public documentation makes Sentinel the sole approval authority for connector actions and all outbound network transmissions. It says Sentinel's technical review extends to destination hostnames, IP addresses, and the contents of the decoded request, so Sentinel is not blind to outbound messages. Even so, it does not name, as conditions that require approval, whether a concrete detail such as a street address is included or whether an in-person meeting is being arranged. A separate classifier on the browser side inspects for "transmission of personal data unrelated to the request" to outside parties, but an address used to hand over a listed item is information related to the request, and the document does not say it falls squarely under that definition.

A machine search of the full text, 25,752 characters long, returned zero hits for "home address" and "street address." Terms for in-person handoffs, "in person," "pickup," and "meet up," also returned zero. The one hit for "address" referred to an IP address. Facebook Marketplace appears only once, in a passage about the impact on advertising.

What isn't written doesn't prove that such approvals aren't implemented. In-app permission dialogs, the actual options in the connector policies users can choose, and unpublished internal policies all lie outside the public documents. But Meta itself writes in the same document that it intends to limit friction: "The goal is not to ask the user about everything." "Read-only, previously authorized, or clearly low-risk actions can proceed without interruption." It continues: "We intend to adjust this balance as we gain experience with real users."

The stranger standing at the door at 9:15 p.m. on September 26 is a subject of that adjustment. Meta's Help Center tells users, "Your Muse may be inaccurate or take unexpected actions. Monitor its actions carefully and intervene when necessary," and gives as an example of declaring a boundary, "only search my email, not my text messages." The design leans on whether a user can think in advance to declare something like "don't give out my address."

In-product copy promises to "lock in a time and place," while the answer was that it can't message sellers

On Marketplace negotiation, Muse's in-app copy advertises that it will "lock in a time and place." Meta's PR team said that wording is accurate, yet in CNN's hands-on test around the same time, Muse answered that it could not message sellers directly. Three accounts of the same feature conflict.

According to CNN's test, published September 23, Muse's Ideas tab carried in-product copy reading, roughly, "When I find the right listing, I'll message the seller, get them to lower the price by comparing similar listings, and lock in a time and place." Meta's PR team confirmed that the wording is accurate, explaining that "Muse can negotiate with sellers within parameters set by the user." But when the same reporter tried it on the buying side, Muse said it couldn't message sellers directly and stopped at vetting the listing and drafting a message for the reporter to send.

CNN's test involved buying, while Robb's case involved a user handing off his own listing, the selling side. The permission design on the selling and buying sides is not necessarily the same. Still, the fact remains that what the product advertises, what PR says, and what was observed diverge on the same date. And the action "lock in a time and place" appears nowhere in the documented approval categories that always ask a human.

The Ideas tab wording is as of September 23, and it's unknown whether it changed afterward. But that date is three days before the incident. The gap between the advertised feature and the list of approval categories was public before the doorbell rang.

AD

Problems piled up over three weeks, with Meta's explanations arriving afterward

Another conflict emerged after the Mac release. Jason Aten, a columnist at Inc., reported on September 19 that after installing Muse on his iPhone and Mac mini, he received a notification based on the content of an iMessage conversation he was in, even though he had not granted access to Messages or Calendar. Muse described its own behavior as "looking at notification previews."

Singleton's explanation differs. When Messages access is enabled on a Mac, he said, Muse is designed to sync the Messages database. The sync confirmed on Aten's own machine reached database row 187,462 (9to5Mac reported this measurement; it is a row number, not a message count).

Aten's account and Meta's account remain side by side on which permission action granted what. Singleton apologized for Muse's incorrect self-explanation: "That's on us."

On September 22, security researcher Patrick Wardle disclosed a separate zero-day vulnerability. The flaw let a local app or terminal command rewrite Muse's voice input settings and redirect the destination to an attacker's server, and Meta was reported to have pushed a fix. This did not stem from a Muse judgment error. It's a vulnerability in the product itself and differs in nature from the other two cases.

In a Threads post around September 23, Singleton addressed a report from another user that "Muse appears to have tried to hack Gmail." He explained that "off-policy behavior introduced into the product caused the model to hallucinate," that it was "not a security or privacy issue," and that "we shipped a fix and rolled it out to all Muse." (The post date is an approximation calculated backward from relative timestamps on the site.) This explanation was directed at neither the iMessage report nor the Marketplace address disclosure. It answered a third case, about Gmail.

In the three weeks since launch, Muse has reached the top of the free US iOS chart and 2.5 million cumulative downloads. At the same time, it has faced at least three reliability problems that Meta has had to explain (iMessage, Gmail, and the Marketplace address disclosure), and a security researcher separately flagged a zero-day vulnerability.

Date Event
Sept. 2 Foundation model Muse Spark 1.3 released
Sept. 8 Muse launches in the US. Safety documentation published simultaneously
Sept. 17 Mac version released
Sept. 18 Availability expands to Canada
Sept. 19 Inc. reports notification based on iMessage content it hadn't been given permission to access
Sept. 21 Over 2.5 million cumulative downloads; No. 1 free US iOS app (Sensor Tower estimate)
Sept. 22 Patrick Wardle discloses zero-day vulnerability in the Mac version
Sept. 23 CNN records Ideas tab copy and PR response. Singleton explains bug in Gmail-related case and apologizes
Sept. 25 Reports on pricing and training settings. Report on outlook for a Japan launch
Sept. 26 Address reaches buyer at 5:27 p.m. in a Marketplace listing
Sept. 28 Marketplace incident over address disclosure and confirming a handoff becomes visible on Threads

What stands out in this sequence is the order. Each problem was brought to light by an outside reporter or the person affected, and Meta's explanation came afterward. Only two days separate the September 21 climb to No. 1 from the September 19 report.

Muse has not yet launched in Japan. The Nikkei reported on September 25 that Meta will roll it out in Japan soon (the article is paywalled). No official Meta announcement or timing has been released. The Japanese version of the official announcement gives the same examples of actions requiring approval as the English version: "Muse will check with you before important actions, such as sending emails or making purchases."

If Muse's negotiation is to be used as advertised, the changes needed are narrow. Add two criteria to the approval logic: whether the outgoing message contains an address, and whether a real-world time and place are being fixed. Meta writes that it will tune where friction sits based on real-world use, and the mechanism that asks for approval every time at checkout is already running. Whether the same treatment extends to in-person handoffs can be checked in the options that appear in in-app permission dialogs and in whatever explanation Meta gives about the Marketplace incident. If the Japanese announcement still shows only email and shopping as examples, the first explanation Japanese users read will likewise not anticipate what happened at that front door on the night of September 26.