For Matt Robb, the choice to try out an AI personal agent was easy. He's a tech reviewer. To test the latest innovation, downloaded Meta’s Muse to handle his Facebook Marketplace messages.
It didn't take long for the new tech to backfire. Within four days, the AI personal agent accepted offers below asking price, gave multiple prospective buyers his home address and told one buyer that Robb was at a pick-up location when he wasn’t even aware of the interaction.
As a YouTube technology reviewer with a degree in computer science, Robb is accustomed to quirks that come with new products, especially AI, but said that before his experience with Muse, his feelings about AI were mostly positive.
"Now I feel like, okay, I kind of get the concerns now,"
Robb told USA TODAY.
Meta released its personal assistant, an autonomous AI software that takes actions across apps on behalf of a user, on Sept. 8. The company touted it as "a secure, private personal AI agent that proactively helps with people’s goals and suggests ideas."
AI personal agents, sometimes called personal assistants, are distinct from chatbots like OpenAI’s ChatGPT or Anthropic’s Claude because they are not only capable of answering questions, but can also take action on a user’s behalf, like sending an email or making a purchase. And, experts say, they bring a new level of risk management.
A YouTuber's experience with an AI agent that gave out his home address
Robb decided to test Muse on Facebook Marketplace (a platform also owned by Meta) to handle incoming messages from prospective buyers. On Sept. 26, he got a bite from someone who wanted to buy his keyboard. That's when the issues began. The offer Muse accepted was $100 below asking and the agent sent Robb's address without notifying Robb of the interaction or telling the buying they were speaking with an AI agent.
In a later conversation addressing the issues, Meta told Robb that an error on their end caused the pricing issue, but that he had granted the agent permission to send messages on his behalf using a template it put together from information it asked during set up, which included the pickup address.
"The part that threw me off was, it didn't even admit that it's an AI. It was talking as if I was talking," he told USA TODAY, adding that it mimicked his "lowkey" tone and casual voice.
In one message reviewed by USA TODAY, Muse wrote, "Yep, I’m here! …Message me when you’re at the door."
The buyer responded that he was also there, sending a picture of the apartment to confirm the location. No one showed up and he left.
About two hours later, Muse — still imitating Robb — wrote, "Hey, really sorry about tonight, got tied up and missed you completely. My bad for wasting your time. The keyboards still here if you want to try again another day, lmk."
The buyer gave Robb a poor rating. And Robb was finally notified when Muse sent an apology.
"Muse actually popped up, like, 'Hey, Matt, I did something bad today,'" Robb said. The message informed him of the interaction — or lack thereof — that had taken place, taking full responsibility.
The encounter went viral when Robb posted about it on Threads. "Deleted Muse after seeing this post," one person responded. In a follow up post, Robb shared parts of a conversation he had with Meta to figure out what went wrong.
"I did go into this knowing it's new, it's experimental," he said. "It's not like I blindly went into it, but at the same time, I'm glad it happened to me, and not someone more vulnerable."
Personal agents are not chatbots
September has been a good month for the AI personal agent market. Around the same time Meta released Muse, three other AI assistant companies were also growing: Instinct announced a fundraiser valued at $2.5 billion, Town was reportedly in talks to raise $1 billion and Ollie raised $7.5 million.
And on Sept. 29, OpenAI announced its own version of a personal agent called "dots," meant to compete directly with Meta’s Muse.
The impact of this rise in personal agents can also be seen from consumers. A recent Visa survey found that 64% of respondents expect to use AI shopping agents within two years, and 56% would already let AI agents search and compare products.
According to Michael Reitblat, who runs an AI commerce platform called Forter, agentic traffic more than tripled in a month since Muse and Instinct launched. In its first week alone, Muse made up 48% of all agentic orders on Forter.
Personal agents are useful "because they can take an arbitrary input and act," said Ian Rogers, chief human agency officer at cybersecurity company Ledger. "But that's also exactly where the danger comes in."
This danger is sometimes referred to as the "lethal trifecta," according to Rogers. It is the combination of "access to secrets, input from the outside world and exfiltration risk." Exfiltration risk is the danger that comes with the ability for the agent to share personal information without authorization.
"We all know it's not possible for them to be useful if they don't have access to things like our email or our calendar, our contact list, like these kinds of things, right?" he added. "But those are inherently secrets that you don't want to be extracted and infiltrated. And so managing that is really important."
How are companies managing risk?
Each assistant is tailored to slightly different audiences, meaning risk-management looks slightly different across companies.
At Town, for example, the company is focused on assisting in the workplace, rather than personal life. Jean-Deniz Greze, the CEO and "Mayor" of Town, said their product emphasizes human approval at every step.
"It is more like a relationship between two beings," he told USA TODAY. "And as such, trust has to be earned in the relationship before you ask it to do more and more and more."
Meta’s Muse, tailored to assisting in personal life, emphasizes individual permissions for each app and access point. The company told USA TODAY that individuals can ask Muse to "forget" certain pieces of information and has audit trails of every action it’s taken.
Still, concern is natural, Greze added.
"If you're conservative about it, you should stand in the sidelines and see how it works." he said. "You'll be sold it enough that you will have plenty of opportunities to decide whether it's for you."
The future of personal agents
Despite his interaction with the agent, Robb said he will likely continue to use Muse, perhaps even purchasing a Muse Charm, a physical device of the AI agent.
"I kind of feel like Meta's gonna fix this," he said.
Personal agents may soon become ubiquitous, entirely replacing the way users currently search the web or access applications, Greze said.
"I think mostly you will interact with just one assistant that will do things for you on existing websites," he said.
Rogers voiced a similar prediction, comparing the place personal agents are in now to where email was in the 1990s.
"The notion that everybody would use some hosted email provider was like craziness in 1996, but that's where we've ended up," Rogers said.
"We're just moving into an entirely different era of what it means to secure things," he added. "And these things just take time to kind of catch up and sort themselves out and become true consumer products."
Greta Reich covers the artificial intelligence industry for USA TODAY through a fellowship from the Tarbell Center for AI Journalism. Funders do not provide editorial input.
This article originally appeared on USA TODAY: AI personal agents are having a moment. Are they safe to use?













