Meta has launched Muse, an AI assistant aimed at everyday productivity tasks: managing email, shopping, trip planning, generating media, and creating interactive documents and webpages. A hands-on test from *The Verge* suggests the agent can complete some of those tasks effectively. It also illustrates the central challenge for consumer—and eventually workplace—agents: users may value automation while remaining deeply uncomfortable with the data access required to make it useful.
What changed
Muse operates through a cloud-based virtual computer and can connect to third-party services. In the test, it cleared thousands of promotional emails from a Gmail inbox after receiving permission to read and delete messages. It also completed an Amazon purchase after being given product constraints and asking whether unrelated items already in the cart should be removed.
Those are meaningful examples of agentic behavior. Rather than merely drafting an answer or recommending products, Muse navigated accounts and carried out actions. Meta says Muse exchanges with third-party apps only the data needed to work for the user, and says it does not share users’ information with advertisers.
Muse also offers generative features, including AI podcasts, images, video and interactive “artifacts.” Its safeguards appeared inconsistent in the test: it declined prompts for some well-known cartoon characters, but generated Apple-branded product-launch imagery—including recognizable logos and app-like icons—while refusing a request for an “Apple CEO.”
The trust gap is the product problem
The more consequential finding involved personalization. After the reporter connected Instagram and Facebook accounts, Muse identified highly specific interests, including anime, CrossFit, Labrador retrievers, Florida wildlife and nostalgia for the 1990s and 2000s. Muse said it had read this information through Instagram API data, rather than from the consumer-facing interface.
It also produced local news based on the shipping address attached to an Amazon order. The reporter found the granularity of Muse’s inferred interests exceeded what was visible in Instagram’s ad-topic settings. *The Verge* sought clarification from Meta on the data available inside Instagram and Facebook, but did not receive an immediate response.
That distinction matters. Users may knowingly grant an agent access to an inbox or a shopping cart for a defined task. They are less likely to accept an agent drawing on broad, opaque context from across an ecosystem—especially when it can surface information they cannot readily inspect themselves.
For Meta, this is a particularly high bar given its history of privacy controversies. But the issue extends beyond one company. An AI agent that can execute valuable tasks needs identity, permissions, memory and access to services. Each additional connection can improve results, while increasing the blast radius of an error, a misunderstood authorization or an unwanted inference.
What operators and builders should take from it
The near-term practical use case for agents remains bounded, low-stakes workflows: clearing marketing email, comparing products, preparing drafts or tracking routine tasks. Those uses create tangible value and are easier to review. High-consequence actions—purchases, account changes, sensitive communications and access to financial or health information—need more than a generic consent screen.
Teams building or procuring agents should look for controls that make data use legible and reversible:
- **Task-scoped permissions** that limit access by service, data type and duration.
- **Action previews and approval gates** before deletion, purchases or external messages.
- **Clear data provenance**, showing which connected source produced a recommendation or personalization.
- **Auditable activity logs** and simple ways to revoke access or delete stored context.
- **Policy testing for generated content**, particularly around brands, copyrighted characters and public figures.
The product lesson is not that agents must be less personalized. It is that personalization has to be explainable enough for users to decide whether its benefits justify the access.
What to watch next
Muse’s performance on mundane tasks indicates Meta has entered the productivity-agent race with a product that can do more than chat. The next test is whether Meta can explain its data boundaries with enough specificity to make users comfortable linking the accounts that make the agent most capable.
For the wider market, adoption will likely hinge less on impressive demos than on permission design. The winners may be the agents that make their autonomy visible: what they can see, what they inferred, what they plan to do, and how quickly a user can say no.
