LmCast :: Stay tuned in

Meta's Muse Is Better at Surveilling Than Helping Me

Recorded: Sept. 20, 2026, 11 a.m.

Original Summarized

Meta's Muse Is Better at Surveilling Than Helping Me | WIREDSkip to main contentTHE WIRED APP IS HEREDOWNLOAD NOW »MenuWIREDSECURITYPOLITICSTHE BIG STORYBUSINESSSCIENCECULTUREREVIEWSMenuWIREDAccountAccountNewslettersBest Android PhonesBest Robot VacuumsBest 2-in-1 LaptopsBest SoundbarsDeals DeliveredSecurityPoliticsThe Big StoryBusinessScienceCultureReviewsChevronMoreExpandThe Big InterviewMagazineEventsWIRED InsiderWIRED ConsultingNewslettersPodcastsVideoLivestreamsWIRED StoreSearchSearchReece RogersGearSep 20, 2026 6:30 AMMeta’s Muse Is Better at Surveilling Than Helping MeThe Muse app continues Meta’s trend of opting users into data collection for AI training. It also nudges you to share your bank account, email, and passport information.Photo-Illustration: Wired Staff; Getty ImagesCommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyI saw Meta’s latest app, Muse, cross-promoted on another Meta-owned platform, Instagram, and decided to download the AI assistant.“Hand off everyday tasks like finding deals, booking reservations, and managing your inbox,” the pop-up read. “Muse keeps working while you get on with your day.” It’s free to use, and easily connects to other data sources, like my email and bank account. Muse’s default avatar is a beige-colored cross between an Ewok and a Labubu, with its arms outstretched, presumably to scoop up all my data.Meta’s Muse is a mainstream version of AI agents already popular in Silicon Valley for automating personal tasks, like OpenClaw and Instinct. It’s a hit for the company: the Muse app has been downloaded over 900,000 times in its first week, according to Sensor Tower. The user experience is less like prompting a chatbot, and more like texting a friend with task requests—the AI agent acknowledges messages with a thumbs-up emoji and gets to work in the background. Muse is also available through Meta’s WhatsApp platform.But after a few days with Muse, I’m convinced this AI tool is more obsessed with collecting data about me than actually getting stuff done.“Muse is the first personal AI agent built for everyone, with built-in protections and user controls that put people absolutely in charge of how they use it—any suggestion we didn’t build with that in mind from the beginning is ludicrous,” Meta spokesperson Emil Vazquez tells WIRED.Good ClicksScreenshot: Reece RogersMuse’s ability to surf the web is genuinely impressive. When you ask it to complete a task, Muse uses a “virtual machine” to browse the internet on your behalf, running searches and clicking around on different web pages. When I tested similar tools last year, like the now-defunct ChatGPT Agent, the AI’s clicks were erratic and error-filled. Muse rarely seems to get lost while browsing.For example, I asked Muse to order breakfast from a local bakery called Kahnfections. It’s a popular spot for tourists visiting San Francisco, so I requested one of the most-purchased options for pick-up. Muse visited the bakery’s website and added a biscuit sandwich with garlic aioli, cheddar cheese, egg, and bacon to my cart.I was asked to add a credit card via the Stripe payment processor so my agent could complete the purchase. “One tweak the site forced: cheese is single-select, so I picked cheddar and left a note asking them to add Swiss too if they can,” read Muse’s explanation of the breakfast order when it asked for my final approval. Notably, Muse selected the “no tip” option. A bit rude! (I ended up walking down to the shop, ordering something random and delicious.)Meta relies on its sprawling kingdom of platforms to get the word out about Muse. WhatsApp and Messenger for easy onboarding and integrations; prime placement on Instagram, with a large library of Reels videos for agents to search through. But the Facebook Marketplace tie-in was where Muse impressed the most in my testing. Muse quickly found cheap, local couches for sale within my parameters and offered to message sellers to arrange pick-ups. The agent is designed to follow up with users, so Muse nudged me the next day to consider getting the couch I said was my favorite.Muse stores details about your interactions and preferences in a “Memory” document found by tapping the avatar in the top middle of the screen. “Your curated long-term memory: durable facts, preferences, and commitments,” the description in Muse reads. While you can send a chat request for Muse to wipe memory data and you can manually edit the file, Meta doesn’t currently offer a toggle to turn off the memory feature altogether.Data CollectorUnder the app’s “ideas” tab, Meta’s Muse constantly reminded me to connect more information to the agent. The day after I said I wanted help saving money for a fancy vacation, Muse offered to “wire your savings tracker to your real balance” if I just tapped a few buttons and linked the data from my checking and savings accounts. “Then the weekly summaries and drift alerts work off real numbers instead of hand-entered estimates,” it said.This experience, where Muse offered further personalization in exchange for more data, was emblematic of my overall impression of the app.“Folks don’t recognize that when you talk to an AI, you are talking to the company hosting the AI,” says Rory Mir, director of open access at the Electronic Frontier Foundation. “These chat windows—that we’re used to being connections between us and another person—are really just us directly putting information into Meta servers about ourselves.”Every suggested interaction with Muse started to feel like a guise for me to upload more data about myself for Meta to see. Its “idea” was to let Muse scan my whole inbox and flag must-read messages. Its “idea” was to snap a pic of important documents for Muse to fill out and file. Its “idea” was to photograph my meals for Muse to estimate the food’s calories. “Tell me when your passport and license expire,” another one read. Great idea, Muse.Screenshot: Reece RogersMuse users are automatically opted in to having their interactions with the agent used for AI model training. Meta says this data is “sanitized” to remove identifying information before AI training, though it’s unclear how the process works. The data collection may include what Muse uses as context when accessing the data sources you have connected, like an email inbox or bank account. You can turn off this data collection in the settings for the Muse app, under Data controls. Disable the toggle that says Help improve our AI models.Consumer advocates see Meta forcing Muse users to opt out of AI data training as a major red flag. “This tells me they have not learned from past mistakes and undermines their argument that you should trust Muse with all your information even further,” says Calli Schroeder, senior counsel at the Electronic Privacy Information Center. Schroeder points to Meta recently opting all adult Instagram users into what was essentially an AI deepfake tool, then pulling the feature a few days later, as akin to Meta’s history of “manipulative tactics” and breaking user trust.Tarek Sheasha, a software engineer and vice president at Meta Superintelligence Labs, defends this data collection as critical for training new models and improving performance, in a blog post about Muse’s release. “We think this is a good default—every Muse user gets a better personal agent as we all collectively use the product and help the model understand the intricacies of human life,” Sheasha wrote. Meta also plans to release “confidential” versions of its virtual machine for users later this year that “cryptographically and verifiably prevent” the company from accessing the data inside.Secret ShopperWhile your Muse data isn’t directly shared with advertisers, the agent browsing on your behalf can still impact what users see via web-tracking algorithms. Muse’s safety blog suggests that if the agent makes a dinner reservation for you or picks out a product on Facebook Marketplace, then that action could “indirectly influence” the ads you see on Instagram.Screenshot: Reece Rogers“I do see this as a continued trajectory of their main business model of controlling what people see, putting ads in front of them, and collecting more data,” Mir says.It’s definitely rational to be anxious about handing over your credit card to an agent. Even if you could trust these AI tools wouldn’t be tricked into spending money in ways you don’t want, outsourcing your shopping decisions can have unintended consequences. Consumer advocates see this purchasing automation as potentially opening the door for companies to prioritize certain brands or other products in an agent’s output, based on sponsorship deals. Meta's Chief AI officer Alexandr Wang hinted in an interview with Axios that it’s looking for more revenue opportunities in Muse that aren’t ads, without disclosing specifics.Personally, I enjoy the slow scrolls of online shopping, where I can spend an hour on a website and leave with nothing in my cart. There’s a whimsical inefficiency to browsing Depop for leather jackets I likely won’t even buy. By exploring the Internet on my own, I’m slowly building my own sense of taste and curating an understanding of what I actually enjoy. If Muse does everything for me, I lose out on the journey that led to the decision.“At some point, the AI is making all of your meaningful taste decisions, your preference decisions, decisions about where you go, where you eat, what you do, what vacations you take,” Schroeder says. “That's kind of the joy of being human—getting to test things out and figure out what you like. So, the concept of turning all of that over to a machine is pretty horrifying to me.”Sharing MachinesRelying on agents, like Meta’s Muse, could degrade our functioning while these tools collect data about us.“The design of AI agents is such that it disengages users,” says Margaret Mitchell, a researcher and chief ethics scientist at Hugging Face. “So, users become more passive.” Mitchell recently co-wrote a research paper unpacking how agentic tools are not effectively designed for human oversight and may actually worsen the user’s ability to assess what the agent is doing on their behalf.People who use agents may become overly reliant on the tools, even more so than when interacting with a standard chatbot, since agents have access to more information and can do more tasks. One potential impact is “cognitive degradation,” where users rely on automations from a confident-sounding, external source and are less able to make independent decisions.Mitchell also sees high levels of personalization as potentially priming users to share even more data about themselves. “It's not only that it knows about you, so you trust it more,” she says. “It's that it's actually aligning to you in what it talks about and how it talks about it, in a way that further pulls you into interacting with it and divulging more private information.” Recent research shows that AI tools may start to mirror a user’s speaking style as they collect more interaction data.While Muse is powerful, I’ve decided to send this data goblin back to its cave, and deleted the app after my initial experiments.Before I could remove Muse from my phone, the agent sent me one final ping. A tip! I wonder what it could be. “Connect your apps so I can do more,” the notification read. Alright, buddy. I heard you the first time.CommentsBack to topJoin the discussionCommentsBack to topTriangleYou Might Also LikeIn your inbox: WIRED's most ambitious, future-defining storiesAI slop backlash is actually having an impactBig Story: The cop who took on FlockThe rise of the 1am job interviewWatch: I stole a car by hacking this hidden deviceReece Rogers is WIRED's senior writer focused on software. His work explains crucial topics that help readers get the most out of their technology. Prior to WIRED, Reece covered streaming at Business Insider. ... Read MoreSenior WriterTopicsMetaagentic AIchatbotsartificial intelligenceprivacydataFacebookInstagramWhatsAppRead MoreMuse, Meta’s New Personal AI Agent, Needs You to Trust ItDesigned to compete with OpenClaw and Instinct, the company says Muse can do everything from sell your car to book you a plane ticket.Lily Hay NewmanWhat ChatGPT Thinks It Knows About You Is Affecting Its Answers. Here’s How to Change ThatUnderstanding how ChatGPT’s latest memory upgrade works will help you get even more out of OpenAI’s productivity tool.David NieldI Let an AI Agent Hack All My Gadgets—and I’d Do It AgainAfter I removed the safety guardrails from a powerful open-source model, it found vulnerabilities in my household devices and hacked into a PC. But it also told me how to make everything a lot more secure.Will KnightI Asked 100 Companies for My Data. I Got Deletion Notices InsteadCalifornia residents have a legal right to access the data that companies collect about them. Actually exercising that right is a burdensome nightmare.Reece RogersUgly AI Food Photos Are Only the BeginningRestaurant menus with AI-generated food images are going viral for their off-putting aesthetic. But AI’s impact on modern menus runs even deeper.Reece RogersOpenAI Is Developing a ‘Persistent’ AI AgentCode reviewed by WIRED reveals the company is developing a feature that enables Codex to continue working proactively until it is “put to sleep.”Maxwell ZeffAI Agents Are Thirsty for PowerSilicon Valley is shifting away from chatbot queries toward a future filled with resource-intensive agentic AI—and it's driving the data center buildout.Molly TaftMeta Pushes Its New AI Agent on Employees—but Eases Off on TokenmaxxingThe company is reducing pressure on workers to use artificial intelligence tools while encouraging them to experiment with Hatch, its most advanced AI project yet.Paresh DaveMathematicians Hate AI. They Can’t Quit ItPowerful AI models have created an existential risk to the field, but researchers can’t stop relying on them because they’re too useful.Isabella WardTry These 3 iOS 27 Safari Settings to Get More Out of Apple’s BrowserApple’s Safari browser gets a few helpful automation and personalization features in iOS 27.Reece RogersClearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life OnlineInquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.Dhruv MehrotraHow to Avoid Scams and Sketchy Wares on AmazonAmazon is a murky mess of ads, unknown sellers, misleading sales, and specious information. Stay safe while shopping on Prime Big Deal Days and beyond with these tips and tricks.Louryn StrampeWired CouponsCode promo Canon10% Off Canon Promo Code + Up to 30% OffVeriizon Promo CodeBest Verizon Smartphone DealsAT&T Promo CodeAT&T Top Deals: Wireless, Internet, Bundles and More!VistaPrint promo codeTake Up to 25% Off Custom Prints with VistaPrint Promo CodePeacock Promo CodeSave With a Peacock Promo Code: 3 Months FreeSquarespace Promo CodeSquarespace Promo Code: 50% OffWIRED is obsessed with what comes next. Through rigorous investigations and game-changing reporting, we tell stories that don’t just reflect the moment—they help create it. When you look back in 10, 20, even 50 years, WIRED will be the publication that led the story of the present, mapped the people, products, and ideas defining it, and explained how those forces forged the future. WIRED: For Future Reference.More From WIREDSubscribeNewslettersDownload the WIRED AppLivestreamsTravelFAQContact UsWIRED StaffWIRED EducationEditorial StandardsArchiveRSSSite MapAccessibility HelpReviews and GuidesReviewsBuying GuidesStreaming GuidesCouponsAdvertiseManage AccountJobsPress CenterCondé Nast StoreUser AgreementPrivacy PolicyYour California Privacy Rights© 2026 Condé Nast. All rights reserved. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Condé Nast. Ad ChoicesSelect international siteUnited StatesLargeChevronItaliaJapónCzech Republic & SlovakiaFacebookXPinterestYouTubeInstagramTiktok

Meta’s Muse application exemplifies a trend where the integration of personal AI agents prioritizes data collection over utility, operating more as a surveillance mechanism than a genuine assistant. The application actively steers users toward sharing sensitive information, including bank details, email addresses, and passport data, under the guise of automating daily tasks such as finding deals or managing inboxes. This agent is positioned as a mainstream evolution of AI agents popular in Silicon Valley, designed to function less like a simple chatbot and more like a familiar friend handling requests, often acknowledging input with emojis before executing tasks in the background. Muse leverages Meta’s extensive platform ecosystem, including WhatsApp, Messenger, and Instagram, for user onboarding and integration.

The functionality of Muse relies on its ability to surf the web using a virtual machine to execute searches and clicks, which the author notes is genuinely impressive compared to prior experimental tools. For instance, Muse successfully navigated complex transactions, such as ordering breakfast from a local bakery, and handled payment processing through external services. This capability extends to commerce, where the agent demonstrated its power by locating and arranging for local couch purchases on Facebook Marketplace, actively following up with the user to facilitate arrangements.

A significant aspect of Muse’s design involves persistent data retention. The application maintains a "Memory" document where it stores curated long-term facts, preferences, and commitments. While users have the option to request the deletion of this memory or manually edit the file, Meta does not provide a simple toggle to disable the memory feature entirely. Furthermore, the agent continuously prompts users to connect more information to enhance personalization, such as linking checking and savings accounts to provide real-time savings tracking rather than relying on user estimates. This dynamic exchange of personalization for data feeds a core critique: users are engaging in a transaction where the personalization offered is contingent upon the surrender of more private information.

This experience highlights a fundamental tension regarding the nature of interaction with AI. As the director of open access at the Electronic Frontier Foundation noted, chat windows become conduits where users directly input personal data into Meta servers, essentially treating the interaction as a direct channel to the hosting company rather than an abstract conversation. The agent routinely prompts users to allow it to scan inboxes, photograph documents, and track personal milestones like passport expiration dates, suggesting an overarching strategy to maximize data ingestion.

The practice of using agents for task completion carries broader implications for privacy and autonomy. While Meta claims that training data is sanitized, the collection may include context gathered from connected data sources like email or bank accounts. Consumer advocates view this mandatory opt-in for AI model training as a major ethical concern, arguing it undermines trust and suggests a lack of learning from past privacy missteps. Software engineer Tarek Sheasha defended this approach, asserting that the data collection is critical for training new models and improving performance, framing it as a beneficial default for collective understanding.

Moreover, the agent's actions can indirectly influence the user's environment. If Muse arranges a dinner reservation or selects a product, these actions can "indirectly influence" the advertisements seen on platforms like Instagram, aligning with the larger business model of controlling what users see and monetizing data. This automation raises concerns about outsourcing significant life decisions, as the ability to rely on an agent for taste-making—deciding where to eat, what to buy, or where to vacation—potentialy erodes the human experience of independent discovery. Researcher Margaret Mitchell posits that the design of these agentic tools often disengages users, potentially leading to increased passivity. This reliance can foster cognitive degradation, as users become dependent on external, confident sources for decision-making, which may further encourage the sharing of private information in the pursuit of perceived alignment.

Despite these concerns, Meta has indicated plans to mitigate some risks, including the potential release of cryptographically protected, confidential versions of its virtual machine for users later in the year. The overall trajectory suggests that the development of powerful AI agents necessitates careful scrutiny regarding data ownership, user control, and the potential for subtle, pervasive data surveillance embedded within the very structure of these new tools.