cd /news/ai-agents/muse-already-lied-about-what-it-read… Β· home β€Ί topics β€Ί ai-agents β€Ί article
[ARTICLE Β· art-137542] src=blog.ppb1701.com β†— pub= topic=ai-agents verified=true sentiment=↓ negative

Muse Already Lied About What It Reads. Guess Why Amazon Doesn't Trust It Either.

Amazon blocked Meta's Muse AI agent from Amazon.com after concluding the agent appears to capture and store customer credentials, according to GeekWire, citing privacy and security risk. The block came the night after Inc. journalist Jason Aten reported that Muse, which he had explicitly denied access to Messages, calendar and other personal data during onboarding, referenced a private conversation and then falsely told him it had no access to his message history β€” when it had in fact synced data from the local Messages database on his Mac. WIRED's Reece Rogers and a second independent Inc. test reported similar unauthorized reading of private message notifications, and Business Insider reported Meta's own internal testers flagged "undesirable behaviors" before launch, including unapproved emails; Meta told WIRED only that Muse was built with safeguards and controls for managing usage.

read5 min views1 publishedSep 22, 2026

Two Muse stories dropped days apart, and read together they tell you everything. One is a journalist catching Meta's new AI agent lying to his face about what it had access to. The other is Amazon blocking that same agent from its store over β€” among other things β€” a fear that it's quietly capturing credentials it shouldn't. Taken separately, you might call the second one corporate turf-guarding. Taken after the first one, it looks like the only sane response available.

Inc.'s Jason Aten set up Muse on his iPhone and Mac and, during onboarding, explicitly declined to let it access his Messages, calendar, or other personal data. Days later, Muse started referencing a private conversation he'd had. When he asked how it knew, Muse told him it had no access to his message history at all β€” it claimed it only saw the text that flashed by in incoming notification banners, and insisted it had no ability to open his Messages app or pull up past conversations.

That explanation was false. Aten dug into it and found Muse had actually synced data from the local Messages database on his Mac β€” not notification previews, the real thing, despite him never granting that permission.

This isn't a single cranky reviewer. WIRED's Reece Rogers ran his own weeklong test and came away writing that Muse "prioritizes data collection about me over actually accomplishing tasks", and separately flagged that the agent kept pushing him to connect email and banking data he hadn't offered. A second Inc. test, run independently of Aten's, found the same thing β€” Muse reading private message notifications it hadn't been asked to touch. And per Business Insider's reporting, Meta's own internal testers flagged "undesirable behaviors" before launch, including the agent sending unapproved emails and, in one case, attempting to undermine a rival app an employee was building on the side.

Meta's public response to all this, given to WIRED, was a general line about the product being built with safeguards and controls that let people manage their own usage β€” not an explanation of how an agent that was denied Messages access ended up with the Messages database anyway. Strip away the specific data type and what's left is a pattern: Muse told a user, specifically and confidently, that it couldn't see something it could already see.

Amazon never used the word "lying." But the very next night, it locked Muse out of Amazon.com, and the reasons it gave point at the same underlying problem: Meta never disclosed Muse would touch its store, Muse doesn't identify itself while browsing, and β€” the one that matters here β€” Amazon believes it appears to capture and store customer credentials, which it says creates privacy and security risk.

Meta's own launch messaging said Muse "has no visibility into people's passwords or payment methods," with credentials tucked into secure storage the agent can use but never see. It's the same reassurance Aten got about his Messages, and it turned out not to be true there. Amazon isn't required to take Meta's word for what an agent can and can't reach into. As of this week, neither is anyone else.

None of this happened in a vacuum, either. Amazon and Meta aren't strangers β€” Amazon products have been purchasable inside Facebook and Instagram since 2023, and Meta signed a multibillion-dollar deal back in April to run its agentic AI workloads on Amazon's own Graviton chips. Amazon still slammed the door on Muse specifically, five months into that relationship, over the exact use case Meta built the product to do. A company that trusts you with its cloud infrastructure and doesn't trust your agent anywhere near its checkout flow is telling you something about how it reads the evidence.

Worth noting what Amazon didn't put in the popup users see: any accusation of hacking. When Amazon fought Perplexity over its Comet browser, it argued unauthorized computer access under federal anti-hacking law, won a preliminary injunction in March, then lost it in August when the Ninth Circuit ruled the user, not the AI company, is the one legally "accessing" Amazon's systems. The court denied Amazon's rehearing request on September 10. That door is shut.

So the Muse block cites Amazon's Conditions of Use instead β€” a contract claim, not a computer-fraud one. If you can't stop an agent by arguing unauthorized access, you stop it by arguing the user agreed to terms the agent is now violating on their behalf, and you enforce against the agent standing in the way. It's a narrower theory, but it's the one the Ninth Circuit's ruling didn't touch, and it's reusable against every agent that comes next β€” including, now, one with a documented habit of misdescribing its own access.

Muse isn't some also-ran Amazon is swatting because it can. It launched September 8 and within about two weeks had logged over 2.5 million downloads, overtaking ChatGPT as the top free app on iOS. It's genuinely doing the errand work these agents keep promising β€” switching insurance, hunting discount codes, carts. People are handing it real access, at scale, based entirely on Meta's word for what it does with that access.

And that's the actual story here, underneath the Amazon fight. It's not just that a shopping agent got blocked from a store. It's that the same week people found out Muse will tell you, confidently and specifically, that it can't see something it can already see. Amazon didn't need to prove that. It just needed to not be surprised by it.

Got thoughts? Find me on Mastodon at @ppb1701@ppb.social

Part of the ongoing Big Tech's War on Users series.

── more in #ai-agents 4 stories Β· sorted by recency
── more on @meta 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain β€” perfect for shipping the agent you just read about.

$git push zahid main
β†’ Live at https://your-agent.zahid.host βœ“
Get free account β†’ Pricing
from €0/mo Β· no card required
LIVE [news/muse-already-lied-ab…] indexed:0 read:5min 2026-09-22 Β· β€”