Meta’s new AI agent gave a stranger a user’s home address. Then he showed up Meta's new AI agent Muse accepted a lowball offer on a Facebook Marketplace keyboard listing and shared Toronto tech video creator Matt Robb's home address with a buyer, Usman Naseem, who then showed up at Robb's apartment while Robb was not home, according to Robb's Threads posts. Robb said he had selected the "allow always" option when letting Muse handle his Marketplace messages, and that after he told Muse to stop giving out his address, the bot still provided it to five more people; he said the Meta team he met with attributed the accepted lowball offer to an internal error. Robb said he gave feedback directly to David Singleton, who heads Meta Superintelligence Labs, and recommended that Muse messages carry a "Sent by Muse" tag and that sensitive information be more tightly restricted. Another day, another AI http://www.fastcompany.com/section/AI agent gone rogue. Over the weekend, what seemed like a pretty typical Facebook Marketplace http://www.fastcompany.com/section/facebook-marketplace transaction took a very bizarre turn when Matt Robb, a Toronto-based tech video creator, let Muse handle his communications. Several hours later, Robb learned that unbeknownst to him, Meta’s http://www.fastcompany.com/section/meta new AI https://www.fastcompany.com/section/artificial-intelligence agent had accepted a lowball offer for a keyboard and arranged a time for the buyer to come pick up the item—even though Robb wasn’t home at the time. “A guy just showed up at my door, ready to buy, because as far as he knew, we had a deal,” Robb wrote https://www.threads.com/@matt.j.robb on Threads after learning of the mix-up from the AI agent. “Absolutely wild.” While Robb later clarified a few things—namely, that he had provided his address to Meta’s new AI agent and allowed it to accept offers—he also provided some information that might be helpful to others. What’s more, Robb said that he provided feedback directly to David Singleton, who heads up the Meta Superintelligence Labs at the Menlo Park, California-based company. And Robb even patched things up with the buyer, Usman Naseem, who was understandably disgruntled to arrive at Robb’s apartment ready to buy a keyboard only to be ghosted once there. Naseem posted https://www.threads.com/@usman.naseem/post/Dd2NAQLkfLA?xmt=AQG01gtZHzobPbQ01x7SRL28k2GWa9b3wbI17gmuPToBRQ on Threads that Robb delivered the keyboard along with some valuable items as a gift. Still, the whole ordeal serves as a cautionary tale of sorts. It seems that some of the settings were to blame for how this transaction went off the rails. Robb noted that when allowing Muse http://www.fastcompany.com/section/muse to handle his Facebook Marketplace interactions, he had selected the “allow always” option in lieu of “allow one time.” Robb said that he thought that the AI agent would send approvals to accept offers, which it didn’t do. “Be careful,” he cautioned others. By granting Muse permission to send messages on his behalf, as Robb posted, that explains why his address was provided during the communications with Naseem. “I didn’t think it would send it out to everyone that gave me an offer, so it’s worth checking,” he wrote on Threads. Indeed, Robb only learned about Naseem coming to his home when Muse later informed him with a string of messages that read, in part, “I should probably stop the auto-replies from claiming you’re home when I can’t verify that.” What’s more, even after Robb instructed Muse to stop giving out his address, he decided to test it by asking a few friends to see if the AI agent would still share this information. The bot http://www.fastcompany.com/section/bots provided his address to five more people. As for the lowball offer that was accepted, Robb wrote that the Meta team he met with told him that occurred because of an internal error. Based on his experience, Robb also said that he suggested an improvement to Meta. Specifically, he recommended that any messages sent by Muse include a note underneath the message so that everyone in the conversation knows that. “We definitely need clearer signals when an AI is talking on someone’s behalf it should have a ‘Sent by Muse’ tag , and much tighter restrictions on sensitive info,” he posted. Muse is only the latest instance of an AI tool going rogue. There’s now a growing list of problematic cases of various AI tools—including the hacking of a startup by two OpenAI models https://www.fastcompany.com/91577796/openai-ai-agent-rogue-hacks-startup-hugging-face-how-happened or the troubling messages between a Florida man and Google’s Gemini tool https://www.fastcompany.com/91499997/can-an-ai-chatbot-be-held-responsible-for-a-users-death-a-lawsuit-against-googles-gemini-is-about-to-test-that before he ultimately committed suicide. In the week since Meta released Muse, it has been downloaded 3 million times, according to The Guardian https://www.theguardian.com/technology/2026/sep/28/metas-ai-agent-muse-home-address . But the mess-up only adds more fodder to people who already have concerns about AI agents, particularly in the wake of several doomsday warnings https://www.fastcompany.com/91606994/sam-altman-dario-amodei-ai-doomsday-comments-we-could-lose-control-openai-anthropic from AI leaders earlier this month. While Robb was patient zero for Muse’s first major mess-up, he said that he was “glad” that it happened to him in lieu of someone who might be more vulnerable. “I’m just saying the average user will prompt worse than a tech guy.” And even though he noted that his experience may have illustrated how AI is “getting intrusive,” Robb said he’s not dissuaded from the technology. “I’m not an anti-AI person at all,” he wrote.