from the the-future-will-look-a-lot-like-the-past dept
After burning $80 billion on the failed metaverse pivot — and billions more on desperate “me too” offerings in the AI space — Meta is looking to leverage its massive ad dominance to colonize the agentic AI (or personal assistant) market. So they recently introduced Muse, an AI agent represented by cutesy and personalized avatars, capable of doing semi-complex tasks like booking appointments and shopping.
The capabilities and novelty of the agent, as usual, tend to overshadow the potential privacy threats of giving unethical companies access to even more personal accounts and data. And right on cue, security researchers found a massive zero-day flaw in Muse that allowed any app or terminal command to gain access to the authentication token linking users to their Muse account.
That not only created potential access to the Muse account (and everything it had access to in turn), it allowed for user surveillance that wasn’t transparent to the Muse user. Great stuff!
Meta marketing had spent a lot of time claiming they’d kept security and privacy at the forefront of Muse’s design so it was a bit of an embarrassing launch. And it certainly didn’t assuage fears about giving big companies like Meta access to even more personal information and login data:
“To me, the bar is infinitely higher in terms of the security of these apps. They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome,” Wardle said. “At the very least, they should be thinking about security from the very start, and they are just not.”
Meta’s adventure in mass-appeal agentic AI also ran into a roadblock when Amazon announced it was banning the agent from shopping on Amazon. Amazon’s announcement, made about 12-hours before Wardle discovered the vulnerability, claimed Muse was an “unauthorized AI agent” that “violates Amazon’s Conditions of Use:”
“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate. This helps ensure a safe, secure, and reliable customer experience, and it is how others operate including food delivery apps and the restaurants they take orders for, delivery services apps and the stores they shop from, and online travel agencies and the airlines they book tickets with for customers. Agentic third-party applications such as Muse have the same obligations, and we’ve requested that Meta remove Amazon from the experience.”
Amazon had already sued Perplexity over its comet browser (though unsuccessfully so far), and taken steps to block shopping agents from both Google and OpenAI. You can see how this could steadily devolve into an annoying walled-garden arms race that erodes the functionality of everybody’s agents.
There’s obviously interesting potential in agentic AI (aka software), but like so many other arenas, our failure to enforce antitrust law, and obsession with lobotomizing our regulators, means the market is likely to be dominated by the biggest companies. Companies that already spent the last decade making it clear they have very little ethics. And are keen to anti-competitively ratfuck their way to market domination.
Which is to say that Amazon’s blockade of Muse is likely only the beginning. In that sense, the future is going to, in a lot of ways, look very much like the past. It’s also another reason why you’d like to see the sector disrupted by cheaper, on-device, open source, open weighted AI alternatives where ideally the end user gets more transparency, better potential security, and more control.
Instead, I suspect 2027 is going to be heavily dominated by companies like Meta (and Amazon) scaring the government about China, resulting in terrible, protectionist, new AI legislation ghost written by its own lawyers.
Filed Under: [agentic](https://www.techdirt.com/tag/agentic/), [ai](https://www.techdirt.com/tag/ai/), [anticompetitive](https://www.techdirt.com/tag/anticompetitive/), [bots](https://www.techdirt.com/tag/bots/), [competition](https://www.techdirt.com/tag/competition/), [muse](https://www.techdirt.com/tag/muse/), [privacy](https://www.techdirt.com/tag/privacy/), [security](https://www.techdirt.com/tag/security/), [shopping](https://www.techdirt.com/tag/shopping/)
Companies: [amazon](https://www.techdirt.com/company/amazon/), [meta](https://www.techdirt.com/company/meta/)