Product1 publisher3 min readPublished
Meta's Muse decides for itself which actions need your consent
Meta's first consumer agent ships as its own app, with connectors for services like Google and Spotify, a Stripe-handled card link, and a permissions screen set to ask about only some actions. The model-training control starts selected.
The Product Desk · Product desk

What happened
- Meta's first consumer AI agent, Muse, ships separately from the Meta AI app with its own iOS and Android apps and website, requiring a Meta account but not a Facebook or Instagram one.
- The agent browses the web, shops online, fills out forms, plans trips, sends emails and schedules events, and connects to third-party services including Google and Spotify.
- The model-training control under "data controls" arrives selected, so a user who does not want Meta training on Muse conversations has to go and deselect "help improve our AI models".
- Purchases require a credit card linked in the wallet section of settings, and Stripe handles that connection so the agent never receives the full card number.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Each connector becomes a separate risk decision for the user, because Meta's software classifies which actions clear without a prompt.
- exposure Meta aimed the product at people with no technical experience, and those users can reach card and email access without ever opening the screens that govern it.
- constraint Signup and consent flows written for a human reader will now be completed by an agent, and nothing in this launch lets a site operator tell the two apart.
- precedent Since Meta says any public API is reachable, a service that never appeared on Meta's list and never agreed to anything with Meta can end up connected.
On the web, a phone number was enough to sign in, and Engadget reported that Muse already had the relevant Meta accounts linked [7]. The next thing it does is ask you to rename it, and let you change its avatar [8].
The two settings that decide your exposure arrive set Meta's way. Under "data controls" sits a checkbox called "help improve our AI models"; opting out of Meta training on your Muse conversations means deselecting it, so it is selected when you get there [9][10]. Under "permissions", the default is for the agent to "ask for some actions" that need the web or a third-party service, with "always ask" available if you go and find it [11].
Meta has said the internal safeguards are meant to ask permission in situations where "consent matters" and to act alone in "low-risk" scenarios [12]. That sorting judgement belongs to the same software the company warns can and will make mistakes [13]. Meta's own advice, in Engadget's account: "Muse may take unexpected actions. Monitor it carefully." [14]
The Stripe link means the agent never receives the full card number [15], and Meta says Muse is meant to check in before it completes a wrong purchase [16].
Meta built Muse to require "no technical experience", hoping to reach people who might not otherwise have access to this kind of tool [4], and Vishal Shah, Meta's VP of AI Products, told Engadget the agent can "build its own software" [5]. The review names four settings areas a cautious user has to work through before handing over anything valuable: data controls, permissions, connectors and wallet [20].
For anyone running a web property, the relevant capability is duller than the shopping demos. Muse browses the web and fills out forms [2], and Meta says it can reach any service with a public API, sometimes after manual steps; when Engadget asked about Notion, the agent walked through setting up the connection itself [18]. Engadget did not report any way for a site to tell Muse's form submissions from a person's [21]. So a consent box on a signup page can be ticked by software whose owner never read the page, and the log on the site side looks the way it always did.
The useful filter for a connector is two questions. Can the worst wrong action be undone, and what does it cost. Spotify and OpenTable sit in the cheap and reversible corner: Engadget granted both, reasoning that a batch of bad playlists or a reservation at the wrong restaurant would be contained [17]. Email and card payments sit in the other corner, and there the workaround is a separate identity. Engadget reported hearing of people who set up a dedicated Gmail account for the agent so it gets email access without the primary inbox [19].
The list worth writing down is the connectors that can spend money or send mail in your name. The second question is whether the permissions screen for those was left on Meta's default of asking about some actions [11].
What to watch
- Whether Meta publishes the rule that separates an action where "consent matters" from a "low-risk" one.
- Whether the "help improve our AI models" control stays selected by default as Muse reaches more markets.
- Whether services with public APIs start blocking agent connections they never agreed to with Meta.