Meta's Muse AI agent collects more data than it gets things done

Meta's Muse AI agent collects more data than it gets things done

Meta's Muse is a free AI agent, cross-promoted on Instagram and also reachable through WhatsApp and Messenger, that handles everyday requests like ordering food, booking reservations and shopping Facebook Marketplace. It has been downloaded over 900,000 times in its first week, according to Sensor Tower, and works less like a chatbot and more like texting a friend: it acknowledges a request with a thumbs-up emoji and works in the background using a "virtual machine" to browse the web on the user's behalf.

A Wired reporter tested it hands-on. Muse successfully ordered a breakfast sandwich from a San Francisco bakery, adding a credit card through Stripe to pay and picking the "no tip" option without asking; the reporter ended up buying something else in person instead. On Facebook Marketplace, Muse found cheap local couches and offered to message sellers, then followed up the next day about a couch the reporter had liked. But nearly every other prompt inside the app pushed toward connecting more personal data: linking bank accounts to power a "savings tracker," scanning the whole email inbox for must-read messages, photographing documents or meals, or reporting a passport's expiration date. Muse also keeps a persistent "Memory" document of the user's interactions and preferences; a user can ask it to wipe the memory or edit the file by hand, but Meta does not offer a toggle to turn the memory feature off altogether.

Muse users are automatically opted in to having their chats used to train Meta's AI models, with opting out requiring a manual settings change; Meta says the training data is "sanitized" to remove identifying information but has not explained how. Muse's own safety blog states that while user data is not shared directly with advertisers, an agent's actions, such as booking a reservation or picking a Marketplace item, can still "indirectly influence" the ads a user sees on Instagram. Meta's Chief AI officer Alexandr Wang told Axios the company is exploring other revenue paths for Muse besides ads, without giving specifics.

Privacy advocates interviewed for the piece were skeptical. Rory Mir of the Electronic Frontier Foundation argued that talking to an AI agent means talking directly to the company that hosts it, and framed Muse as an extension of Meta's ad-and-data business model. Calli Schroeder of the Electronic Privacy Information Center called the default opt-in for AI training a red flag, pointing to Meta's recent rollout, then swift retraction, of an opt-in AI deepfake tool on Instagram as a pattern of eroding user trust. Hugging Face researcher Margaret Mitchell, who has co-written a paper on agentic tools and human oversight, said such agents can make users more passive and less able to judge what the agent is doing for them, and that heavy personalization can pull users into sharing even more. The reporter deleted the app after the test, getting one last notification urging them to "connect your apps."

Key facts

  • Meta's free personal AI agent Muse, cross-promoted on Instagram and also available via WhatsApp, was downloaded over 900,000 times in its first week, according to Sensor Tower.
  • Muse browses the web through a "virtual machine" to complete tasks like ordering food and shopping Facebook Marketplace, but its in-app "ideas" repeatedly pushed the reporter to link a bank account, scan an entire email inbox, and photograph documents, meals or a passport.
  • Muse keeps a persistent "Memory" document of user interactions; it can be wiped or hand-edited on request, but Meta offers no toggle to disable the memory feature entirely.
  • Users are automatically opted in to having their Muse interactions used for AI model training, and must manually disable a settings toggle to opt out; Meta says the data is "sanitized" but has not detailed the process.
  • Privacy figures quoted include EFF's Rory Mir, EPIC's Calli Schroeder and Hugging Face's Margaret Mitchell, who warned that such agentic tools can make users more passive and increase how much personal data they share.

Why it matters

Muse is Meta's attempt to make a personal AI agent mainstream, distributed across WhatsApp, Instagram, Messenger and Facebook Marketplace, and it already has real reach: over 900,000 downloads in its first week. That scale, combined with default settings that route users' data into Meta's AI training pipeline and its advertising system, makes Muse a test case for how much data collection a consumer AI assistant can bundle into a helpful-seeming interface.

Who it affects

Muse users on Meta's platforms, including anyone who links an email inbox, bank account or payment method to the agent; and, more broadly, WhatsApp, Instagram and Facebook Marketplace users whose ad experience can be shaped by what the agent does on their behalf.

How to use it

Muse is free and reachable through the standalone app or WhatsApp; it can browse the web, place orders (via a linked card through Stripe) and negotiate Marketplace purchases. Users can ask it to wipe its "Memory" file or edit it by hand, and can opt out of having their interactions used for AI training by disabling the "Help improve our AI models" toggle in Data controls, though that setting is on by default and there is no way to turn off the memory feature itself.

How solid is it

The account is a single Wired reporter's multi-day, hands-on test, backed by on-record quotes from Meta's own spokesperson and a Meta Superintelligence Labs executive, plus outside comment from named specialists at the Electronic Frontier Foundation, the Electronic Privacy Information Center and Hugging Face. It is a first-person review rather than a systematic study or an audit of Muse's code or data practices.

Risks and caveats

Data-collection defaults are opt-out rather than opt-in for AI training, and Meta has not detailed how it "sanitizes" that data. There is no setting to disable Muse's persistent memory outright. The agent's purchasing and booking decisions can indirectly shape the ads a user sees, and Meta's Chief AI officer has hinted at further monetization paths for Muse without specifics. Researchers separately warn that agentic tools of this kind can make users more passive and less able to evaluate what the agent is doing on their behalf.

“Folks don't recognize that when you talk to an AI, you are talking to the company hosting the AI.”

— Rory Mir, director of open access at the Electronic Frontier Foundation