Meta Muse Wants Your Data With Your Errands
Meta's Muse looks like the next step in consumer AI agents: a chatty helper that can browse the web, shop, book, and follow up while you do something else. WIRED's hands-on test found the more important story in the permissions screen: memory, email, bank links, passport reminders, and AI training turned on unless users opt out.
Quick Take
- Fact: WIRED senior writer Reece Rogers tried Muse after seeing it promoted on Instagram. The pitch is ordinary-life automation: find deals, book reservations, manage an inbox, and keep working in the background. Muse is free, works as a standalone app, and is also available through WhatsApp.
- Why it matters: Muse is a useful preview of the consumer agent fight. The hard problem is not whether agents can click. The hard problem is who controls the trail of data created by those clicks.
For users, a personal agent is not only a chatbot. It can become a browser, shopper, reminder system, inbox reader, form filler, memory keeper, and payment assistant. Each added s
- Who cares: Builders shipping agents with browsing, payments, memory, or inbox access should study Muse closely. The task UX sounds better than many early agent demos, but the trust UX is where the story gets messy.
- Judgment: Fairly hyped as a mainstream personal agent with real browser-based task ability and Meta-scale distribution; overhyped if you treat it as a pure helper that puts users fully in charge by default. Fact: WIRED's hands
What happened
WIRED senior writer Reece Rogers tried Muse after seeing it promoted on Instagram. The pitch is ordinary-life automation: find deals, book reservations, manage an inbox, and keep working in the background. Muse is free, works as a standalone app, and is also available through WhatsApp.
According to Sensor Tower data cited by WIRED, Muse passed 900,000 downloads in its first week. That matters because this is not just a lab demo for AI obsessives. It is a Meta-distributed agent with Instagram, WhatsApp, Messenger, and Marketplace gravity behind it.
The useful part is real. Rogers reports that Muse uses a virtual machine browser to search and click around the web on the user's behalf. In a bakery test, it found a San Francisco shop, selected a biscuit sandwich, handled a required cheese choice, and asked for Stripe card approval before payment. In a Facebook Marketplace test, it found local couches under budget, offered to message sellers, and nudged Rogers the next day about the favorite option.
That is the good agent story: less prompt lab, more delegated web work.
Then the data story takes over.
Muse keeps a long-term Memory document with facts, preferences, and commitments. WIRED says users can edit the file manually or ask Muse to wipe memory data, but Meta does not currently offer a simple switch to turn memory off entirely.
Muse also pushes users toward deeper data connections through an Ideas tab. After Rogers mentioned saving money for a vacation, Muse suggested connecting real checking and savings balances so the agent could track progress. Other prompts encouraged full inbox scanning, photos of documents for form filling, meal photos for calorie estimates, and reminders to log passport and license expiration dates.
Training defaults follow the same pattern. WIRED reports that Muse users are automatically opted in to having interactions used for AI model training. Meta says the data is sanitized before training, but WIRED says the process is not fully clear. The collection may include context Muse uses when accessing connected sources, such as email or bank accounts. Users can opt out in Data controls by turning off Help improve our AI models.
Meta pushed back on the surveillance framing. Spokesperson Emil Vazquez told WIRED that Muse was built with protections and user controls from the beginning. Tarek Sheasha of Meta Superintelligence Labs defended training opt-in as a useful default because collective use can improve the agent for everyone. Meta also plans confidential virtual machine modes that it says will cryptographically and verifiably prevent company access to data inside the machine.
Privacy advocates were not comforted. EFF's Rory Mir warned that talking to an AI means talking to the company hosting it. EPIC senior counsel Calli Schroeder called opt-out training a red flag and tied it to Meta's broader record of pushing users into AI features, then retreating after criticism.
Ads are the quieter risk. WIRED reports that Muse data is not directly shared with advertisers, but Meta's safety material says agent actions like dinner reservations or Marketplace choices can indirectly influence ads users see on Instagram. That is not the same as handing advertisers your bank account. It is still a reminder that agent behavior can feed the ad graph.
Why it matters
Muse is a useful preview of the consumer agent fight. The hard problem is not whether agents can click. The hard problem is who controls the trail of data created by those clicks.
For users, a personal agent is not only a chatbot. It can become a browser, shopper, reminder system, inbox reader, form filler, memory keeper, and payment assistant. Each added skill creates a new permission question. Each permission can make the agent better. Each permission can also make the company behind it know more.
For builders, Muse shows the consent stack that every serious agent product now has to explain:
- What sources can the agent connect to?
- What memory does it keep?
- Can memory be fully turned off?
- Are interactions used for model training by default?
- What happens to context pulled from email, finance, shopping, or documents?
- Can agent actions affect recommendations or ads elsewhere?
- Does the product make opt-out obvious, or does it bury the work in settings?
That last question is the Bandwagon one. A product can have controls and still steer users toward the house preference. If the agent keeps asking for bank data, inbox access, document photos, and passport dates, the default experience is not neutral. It is a data ladder.
Who should care
Builders shipping agents with browsing, payments, memory, or inbox access should study Muse closely. The task UX sounds better than many early agent demos, but the trust UX is where the story gets messy.
Security and privacy teams should care because agent connectors collapse several sensitive domains into one assistant surface. Email, banking, IDs, photos, shopping, and ads do not feel like separate systems once the same helper is asking for all of them.
Operators on WhatsApp, Instagram, and Marketplace should care because Meta has distribution few companies can match. If Muse works well enough, agent habits could spread fast.
Regular users should care because free helper is not the same thing as low-cost helper. If an agent saves you ten minutes but trains on your interactions by default, remembers more than you expected, and nudges you to connect more of your life, the price is not zero.
What to do this week
If you test Muse or any connector-heavy agent, start narrow.
Pick one task before linking broad accounts. If the job is finding a couch, do not connect banking, inbox, documents, and passport details just because the Ideas tab asks nicely.
Open data settings first. If training is on by default and you do not want your interactions used, turn it off before a long history builds up.
Read the memory file. If there is no full off switch, treat edit and wipe as regular maintenance, not a one-time cleanup.
Keep human approval on spending. WIRED's test still required Stripe approval before payment, and that is the right line to keep.
If you build agents, publish a one-screen map of connectors, memory, training, payment approval, and ad-adjacent effects. Do not make users play scavenger hunt with consent.
Bottom line
Muse can browse and act better than the clunkiest early agents. That is exactly why its defaults matter. The more useful a personal agent becomes, the more dangerous it is to treat memory, training, bank links, inbox access, and ad effects as small-print settings.
Ride the agent wave with the settings panel open.
Bandwagon Check
Fairly hyped as a mainstream personal agent with real browser-based task ability and Meta-scale distribution; overhyped if you treat it as a pure helper that puts users fully in charge by default. Fact: WIRED's hands
Sources
- Meta's Muse Is Better at Surveilling Than Helping Me
- Meta's Muse Is Better at Surveilling Than Helping Me (WIRED, Reece Rogers)
By Sean Smith · AI Bandwagon
