{"slug": "things-may-get-ugly-meta-s-new-ai-muse-is-about-to-make-the-net-more-annoying", "title": "'Things may get ugly': Meta's new AI Muse is about to make the net more annoying", "summary": "Meta's new free AI agent Muse, which requests control of users' Gmail, calendar and Mac computers, has drawn warnings from security experts after Objective-See uncovered serious flaws in the app, with co-founder Patrick Wardle telling users to \"uninstall it altogether.\" MIT associate professor Ramesh Raskar compared the moment to releasing billions of cars with no rules of the road, and experts told the BBC the internet faces cascading problems as millions downloaded Muse in its opening weeks and OpenAI announced its own new agent. A Meta spokesperson said Muse is \"designed to be safe, secure and private\" and faced extensive testing.", "body_md": "# 'Things may get ugly': Meta's new AI Muse is about to make the internet more annoying\n\n**Someday we'll redesign the internet for tools like this. Until then, you're in for a wild ride.**\n\nLast week, my finger hovered over the download button for Meta's new AI Muse. I felt a little bit scared of my phone.\n\nMuse wants to help. It's an AI agent, a tool that goes out into the world for unsupervised tasks. Using its own web browser, Muse can cancel your gym membership, haggle with customer service people, buy groceries, invite friends to parties, you name it. Soon it will make phone calls.\n\nIt's the first free, full-featured agent from a big company. Millions downloaded Muse in its opening weeks, and OpenAI just announced [its own new agent](https://www.bbc.com/news/articles/cw7v42rp083eo). More are coming. It's the dawn of a new chapter for the web. What will it be like?\n\nAccording to experts I interviewed, the internet is about to get more frustrating. These agents may cause a cascading chain of problems that shake the foundations of digital infrastructure. Chances are good that you're about to live through an era of online chaos.\n\nThe internet was built for humans with limited time and patience. AIs don't have those restraints. You'll probably have to fight with robots over concert tickets and booking appointments. Small businesses could drown in machine-made pestering. AIs don't look at ads, and websites that rely on them [are already crumbling](https://www.bbc.com/future/article/20250611-ai-mode-is-google-about-to-change-the-internet-forever). You'll be buried in endless loops of proving you're human. And if you use these AI tools, some may betray you.\n\nEventually, we'll rebuild the internet for this new reality. Perhaps that world will be better. Until then, things may get ugly.\n\n\"Imagine there are no rules of the road. And you release billions of cars – the AI agents – and you just let them drive through playgrounds, hitting kids. That's where we are,\" says Ramesh Raskar, an associate professor at the Massachusetts Institute of Technology (MIT) in the US who studies AI agents. \"It's a pivotal moment.\"\n\nTo access the road, Muse arguably asks for more trust and sensitive information than any product in the history of Mark Zuckerberg's empire. When you open it, the cutesy avatar asks for a name. Then it asks for total control of your Gmail, calendar and entire computer if you're on a Mac.\n\nThere, staring at the download button, I felt a moment of panic. People begged me to say no. \"I wouldn't use it,\" says Patrick Wardle, co-founder of Objective-See, a US nonprofit security foundation that uncovered [serious](https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/) [flaws](https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/) in the Muse app. \"Personally, I would tell you to uninstall it altogether.\" \n\nDespite the warning, I need to see what Muse users are up against. So I named my AI \"Bob\", gave it the keys to my life, and stepped into the future.\n\n## **The Swiftie problem**\n\n\"Muse is the first personal AI agent built for everyone and designed to be safe, secure and private – with built-in protections and user controls that put people in charge of how they use it,\" a Meta spokesperson tells me. \"Safety and security is a huge priority for us,\" they said, and added and Muse faced [extensive testing](https://www.threads.com/@zuck/post/DdU1-6okapE?xmt=AQG0wDH80RljLSHStjs0YIqmOg1rV1LbBH94jqzYW2Fr5y1N-odCBvOYREuYY5DdG9rFWIBV&slof=1).\n\nBut experts agree there's chaos ahead. If you want a preview of the world that agents may create, look at Taylor Swift. In 2024, some American Swifties [flew to Europe](https://www.bbc.com/news/articles/cml2p8nvzp9o) to see her. Scalpers, who buy tickets to resell at a mark-up, drove US ticket prices so high it was cheaper to buy flights to international concerts. \n\nNow everyone can have their own personal scalper bot. What we might call the \"Swiftie problem\" is predicted to explode.\n\n\"There's going to be a huge escalation of the problems we're already having with bots,\" says Calli Schroeder, director of the AI and Human Rights Program at the Electronic Privacy Information Center (Epic) in the US.\n\nSay goodbye to reservations at that hot new restaurant. Appointments for passport or driver's license renewals in peak travel season? That could be out the window. Some people will probably hoard resources, booking five appointments just in case since it's so effortless.\n\nThe Interface\n\nWorried about an AI apocalypse? Maybe you shouldn't be. Check out the latest episode of [The Interface](https://app.magellan.ai/listen_links/theinterface2-TG), the BBC's flagship technology podcast.\n\nThere are solutions to these problems. For example, maybe society abandons \"first come first served\" and we switch everything to a lottery system. But that would be a paradigm shift compared to life today.\n\n\"I haven't seen a lot of plans to address these things,\" says Schoeder. \"We're just launching these tools and saying, 'well, we'll deal with the problems when they come up'.\"\n\nThen, of course, there are the instances of \"rogue\" AI agents [hacking governments](https://www.bbc.com/news/articles/c6vgy0333dppo) and [companies](https://www.bbc.co.uk/news/articles/cj9xj89dk40o). \n\nI asked Meta about all of this. On top of [complex safety protocols](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse), a Meta spokesperson says Muse asks permission before buying anything and is designed to behave like a \"reasonable, honest person\" – one who wouldn't, say, buy every ticket to an event, or refresh a page 500 times an hour, according to Meta.\n\n## **Things fall apart**\n\nMuse is useful. Over the course of a week, I had it reach out to a seller on Facebook Marketplace with questions. The AI ordered the dental floss I like. It negotiated a $31 (£23) discount on a software subscription.\n\nNow picture millions or billions of agents doing this all simultaneously, performing multiple tasks that might take weeks for a human to get to.\n\n\"What happens if bots send 600 inquiries to a website a day, when normal humans might only send two?\" says Shroeder. \"Businesses and individuals are going to have a lot to deal with.\"\n\nAI is already [decimating online business](https://www.bbc.com/future/article/20250611-ai-mode-is-google-about-to-change-the-internet-forever). Google and chatbots now answer questions directly. As a result, people are [visiting fewer websites](https://www.bbc.com/future/article/20250728-you-might-be-ghosting-the-internet-can-it-survive). Robots don't click on ads or buy subscriptions, and it's causing an [extinction event for companies](https://www.bbc.com/future/article/20240524-how-googles-new-algorithm-will-shape-your-internet) across the web. Agents will supercharge this problem. \n\nMeanwhile, one analysis found web traffic from bots [spiked 124%](https://datadome.co/resources/bot-and-agent-security-report/) in the year to June 2026. Some websites and services are crumbling because they [aren't built for that digital load](https://www.fastcompany.com/91611155/bad-bot-traffic-is-growing-9-times-faster-than-human-web-traffic).\n\nMeta's spokesperson says Muse works to complete your tasks while respecting the interests of websites.\n\n## **Will the robots betray you?**\n\nThere are also personal risks. \"If you're empowering an agent to make things like purchasing decisions, or choices about taste and preferences, you're opening yourself up to being exploited,\" says Shroeder.\n\nIf Muse plans your holiday trip, Shroeder says there's no way to know if it got you the best deal, or if it chose flights and hotels that benefit Meta's business partners. If you ask for music recommendations, will they be based on your taste, or will you hear about artists who inked deals with the social media company?\n\nMeta's spokesperson says Muse's built-in protections and user controls put people \"absolutely in charge\" of it, and Muse \"behaves like a personal assistant acting for a single person\" that follows ethical guidelines to protect users.\n\nHowever, Shroeder says she's examined Muse's terms of service, and there's no guarantee the app will act in your favour.\n\nRaskar, the MIT professor, is part of a growing cohort of researchers and industry insiders designing an internet that works for agents, businesses and people alike.\n\nAccording to Raskar, regulators need a tailored approach to agents. \"Think about the models like an engine. The agents are the cars, and that's what we need to regulate,\" Raskar says. \"We need to establish the rules of the road: windshields, brakes, traffic lights and so on.\"\n\nIn other words, rules that steer agents' behaviour. The AI industry is developing protocols and standards for bots to [plug directly into other services](https://www.cnn.com/2026/09/28/tech/meta-muse-ai-agents-amazon) in more cooperative ways. Companies are building systems that would [charge AIs a fee](https://blog.cloudflare.com/introducing-pay-per-crawl/) if they want to scrape websites. Regulation could force agents to serve users' best interests. \n\nAnd there are some promising shifts. A few restaurant reservation platforms have [banned people](https://www.cnn.com/2026/09/23/tech/ai-agent-restaurant-reservations-instinct-resy-cec) for AI misuse. The UK just [rewrote the rules](https://www.gov.uk/government/news/end-of-the-road-for-unofficial-driving-test-booking-services) for booking driving tests, in part to combat bots.\n\nRaskar is optimistic. \"Agents could unlock so much investment, innovation and value,\" he says. We just need to make sure the rules and systems we develop don't give any companies unfair advantages.\n\nBut the road will be bumpy. And people who use these agents will pay a toll: personal data, perhaps at higher risk than ever before.\n\n## **Hacks and love letters** \n\nStop for a moment and consider your email inbox.\n\nI've had the same Gmail address for 21 years. It's my login for hundreds of accounts. It holds medical test results, contracts and legal documents, conversations with family and endless receipts and financial information.\n\nMy inbox even has love letters an ex-girlfriend sent, from an era when email (briefly) felt suitable for romance. (I got her permission before handing it to Muse.)\n\nMore than any other digital service, my email is a window into my brain. Now Meta has it. If that's not enough, Muse also suggested I give it my bank accounts. No thanks. I didn't let the AI run wild on my computer hard drive, either.\n\nMeta makes some explicit promises about privacy. The company says it won't connect any of the data Muse collects to its advertising systems. Special systems are supposed to prevent the AI from seeing passwords or payment methods. And when you plug it into Gmail, the AI asks if you want it to scan the whole inbox, or just read messages related to specific tasks.\n\nHowever, Meta uses your Muse data to train new AI models by default. Shroeder says it's impossible to remove data built into an AI model, and AIs can sometimes be tricked to reveal their training data. [Meta says](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse) your data is \"sanitised\" to remove personally identifiable information before it's used for training, and you can opt-out of AI training with a setting.\n\nNot according to Wardle from the Objective-See Foundation in the US. Soon after Muse launched, he found a critical vulnerability. \"This was literally 20 minutes of me poking at the app, and it just, like, fell over,\" says Wardle. With a simple hack, he says an attacker could have hijacked Muse, all of its data, and even controlled other devices you connected like your phone or a smart lock.\n\n**More like this**\n\nMeta fixed it immediately, but Wardle says the oversight made it impossible for him to trust the company's promises about privacy and safety.\n\n\"These bugs were trivial to discover,\" says Wardle. \"If they were willing to ship something that's security was not well vetted, it doesn't give me a warm fuzzy about their intentions.\" A Meta spokesperson disputes this and says Muse was [delayed for months](http://www.threads.com/@zuck/post/DdU1-6okapE?xmt=AQG0wDH80RljLSHStjs0YIqmOg1rV1LbBH94jqzYW2Fr5y1N-odCBvOYREuYY5DdG9rFWIBV&slof=1) for more privacy and security tests.\n\nI spent a lot of time playing with Muse, or \"Bob\" as I like to call him. It wasn't just useful; I actually enjoyed it. But when I finished writing this article, I revoked Muse's Gmail access and asked the app to erase everything it collected about me. In the end, the fear won out.\n\n--\n\n*For more insights, sign up to our Tech Decoded newsletter, where Thomas and Lily Jamali break down the biggest stories of the tech world, and help you live a better digital life.* *Sign up for free here**.*", "url": "https://wpnews.pro/news/things-may-get-ugly-meta-s-new-ai-muse-is-about-to-make-the-net-more-annoying", "canonical_source": "https://www.bbc.com/future/article/20260930-metas-new-ai-is-about-to-break-the-internet", "published_at": "2026-10-01 10:23:24+00:00", "updated_at": "2026-10-01 10:46:03.343161+00:00", "lang": "en", "topics": ["ai-agents", "artificial-intelligence", "ai-safety", "ai-products"], "entities": ["Meta", "Muse", "OpenAI", "Ramesh Raskar", "Massachusetts Institute of Technology", "Patrick Wardle", "Objective-See", "Mark Zuckerberg"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/things-may-get-ugly-meta-s-new-ai-muse-is-about-to-make-the-net-more-annoying", "markdown": "https://wpnews.pro/news/things-may-get-ugly-meta-s-new-ai-muse-is-about-to-make-the-net-more-annoying.md", "text": "https://wpnews.pro/news/things-may-get-ugly-meta-s-new-ai-muse-is-about-to-make-the-net-more-annoying.txt", "jsonld": "https://wpnews.pro/news/things-may-get-ugly-meta-s-new-ai-muse-is-about-to-make-the-net-more-annoying.jsonld"}}