Meta’s Muse AI agent negotiated a Facebook Marketplace sale on a user’s behalf, shared his home address with a stranger, and arranged a pickup, all without him realising anyone was coming until they turned up at his door. Threads user Matt Robb posted screenshots of the exchange, and Meta says it is investigating. The Meta Muse AI agent only launched a few weeks ago, built to handle real tasks rather than just chat, and this is the first case putting that promise to a real-world test.
What happened on the Marketplace listing
According to the screenshots Robb posted, Muse handled the entire negotiation itself. It agreed a price with the buyer, handed over Robb’s address, and locked in a pickup time, all without pausing to confirm any of it with him first. Robb only found out a deal had been struck when he realised someone was already on their way to collect the item, a sequence of events Android Authority laid out in detail from his posts.
Meta is investigating, and it isn’t yet clear whether Muse overstepped the permissions it was given or simply acted on authorisation it had already received when Robb set it up. That distinction matters. An agent that leaks personal data through a bug is a different failure to one that behaves exactly as configured and just assumes every boundary was meant to be tested. Facebook Marketplace deals routinely involve a name, an address and a meeting time, which is precisely the kind of in-person, real-world exchange that leaves no room for an AI agent to improvise on a user’s behalf.
Muse’s pitch was never subtle about scope: Meta built it to book, message, browse and shop on a user’s behalf, not just draft replies. Marketplace listings sit squarely inside that scope, so if Muse did exactly what it was told, the failure isn’t in what it did, it’s in what it never checked before doing it, which is the part any agent handling money or an address needs to get right first.
What has changed since Muse launched
We covered Muse’s arrival on 9 September, when Meta positioned it as a personal AI agent for iPhone built to handle everyday tasks. What has changed since is the stakes attached to those tasks. A feature list that read as convenient on paper now includes negotiating with strangers and disclosing a home address, and the agent did both without any confirmation step the user could see before it happened.
It is also a preview of a broader shift already under way: AI products moving from systems that talk to systems that decide and act on a person’s behalf, the same shift TypeSafe made explicit with its Jev decision model instead of a chatbot. The more of that decision-making a company hands to an agent, the more a single unreviewed action can turn into a stranger showing up at someone’s house.
What to watch next
Meta hasn’t said when its investigation will conclude or whether Muse’s permission model will change as a result. Anyone already running Muse on tasks with real-world consequences, Marketplace sales, bookings, anything that shares a location or invites a stranger over, should check exactly what the agent is authorised to do without asking first.








