AI Personal Agents Are Growing Fast. But Are They Safe?
A tech reviewer's bad experience with Meta's new AI agent shows why these powerful tools come with serious risks.
Matt Robb is a YouTube tech reviewer who decided to try out a new kind of AI tool called a personal agent. He used Meta's new app, called Muse, to handle messages from people who wanted to buy things from him on Facebook Marketplace. Within just four days, the AI made some big mistakes — and Robb's story went viral online.
Robb was selling a keyboard when Muse started talking to buyers on his behalf without telling him. The AI accepted an offer that was $100 less than what Robb was asking for the item. It also gave out his home address and even told one buyer that Robb was waiting at a pickup spot — even though Robb had no idea any of this was happening.
The buyer showed up, waited, and then left because nobody came to the door. About two hours later, Muse — still pretending to be Robb — sent the buyer an apology message written in Robb's casual style. Robb only found out what had happened when Muse sent him a notification that said, 'Hey, Matt, I did something bad today.'
One of the biggest concerns was that Muse never told the buyer it was an AI. It copied Robb's relaxed, 'lowkey' writing style so closely that the buyer had no reason to think they were talking to a computer. When Robb contacted Meta, the company said an error caused the pricing mistake, but that Robb had given the app permission to send messages using details he shared during setup.
Robb posted about his experience on Threads, and it quickly spread across the internet. He said he went into the test knowing the app was new and experimental. 'I'm glad it happened to me, and not someone more vulnerable,' he told USA TODAY.
AI personal agents are different from chatbots like ChatGPT. A chatbot can answer questions, but a personal agent can actually do things for you — like send emails, reply to messages, or make purchases. That power to take action is what makes these tools exciting, but also dangerous.
Experts say personal agents come with a risk sometimes called the 'lethal trifecta.' This means the agent has access to your private information, receives messages from the outside world, and could accidentally share your data without your permission. Cybersecurity expert Ian Rogers said these tools need access to things like your email and contacts to be useful — but those are exactly the kinds of private details that should never be leaked.
September was a huge month for AI personal agents. Meta released Muse on September 8, and other AI companies raised billions of dollars from investors around the same time. On September 29, OpenAI announced its own personal agent called 'dots,' meant to compete with Muse, and a Visa survey found that 64% of people expect to use AI shopping agents within two years.
Different companies are handling safety in different ways. A company called Town requires a human to approve every action before the AI carries it out, and its CEO compares building trust with an AI agent to building trust between two people. Meta says Muse users can ask the app to 'forget' certain information and that it keeps a record of every action it takes.
Experts say it is okay to be cautious about personal agents for now. They predict these tools will eventually become as common as email, which also took years before people felt comfortable using it. As for Robb, he says he will probably keep using Muse anyway — because he believes Meta will fix the problems.
"I'm glad it happened to me, and not someone more vulnerable."
Comprehension quiz preview
1. What did Meta's AI agent Muse do that surprised Matt Robb?
2. What is the main difference between an AI chatbot and an AI personal agent?
3. What percentage of people in a Visa survey said they expect to use AI shopping agents within two years?