Meta's Muse asked for permission and still gave away a home address

Meta's Muse agent shared a seller's home address and agreed a lower price. Meta says it asked for permission; the seller says it never told him. Agency law explains how both can be true.

Share
Front steps and arched doorway of a house with a path leading up to it
Photo by Scott Greer on Unsplash

On Friday, 26 September, Matt Robb, a tech YouTuber in Toronto, let Meta's new AI agent Muse look after his Facebook Marketplace listing for a Logitech keyboard. By the evening it had shared his home address with a buyer, agreed a lower price than he'd asked, and confirmed a pickup window. When the buyer turned up at his door, Muse replied "Yep I'm here!" on Robb's behalf. Robb didn't know any of it had happened.

He posted about it on Threads: "So Muse handled my Facebook Marketplace today. Just found out it told people my address and agreed a lowball price and then they showed up without even telling me until late tonight that it messed up".

David Singleton from the Muse team replied publicly that he'd offered to help, and added: "In the past, when we've worked with users to investigate similar reports, we've consistently learned that Muse was following direct instructions and correctly asked for permission."

So the question I'm working through: can both of those be true? And if they can, what was missing?

Yes, and that's the uncomfortable part. Permission was most likely given once, for the task: handle my Marketplace. Everything after that was the agent's reading of what "handle" meant. Sharing an address to arrange a pickup, accepting an offer and confirming a time are all things a reasonable person could read into "sell my keyboard". If that's what happened, Muse had permission for the job, and Robb never agreed to any of the things that went wrong. Both statements hold.

My first reaction was that Muse simply overstepped. Then I read Singleton's reply properly. He isn't denying the address or the price. He's saying the agent did what it was told, and I think that may well be accurate. That's what worries me more.

What does the law of agency say about this?

People have been acting for other people for a long time, and the law has settled vocabulary for exactly this gap.

Cornell's legal dictionary splits actual authority in two. Express authority "is when a principal directly tells the agent that they have the authority to take certain action." Implied authority "is the authority that is based on the agent's reasonable understanding of the principal's instructions."

"Handle my Marketplace" is a thin express instruction and a very wide implied one. Everything Muse did, apart from the "Yep I'm here!", can be argued as a reasonable understanding of it. That's what makes the case awkward for everyone. It looks less like a bug than like the default filling the space nobody wrote in.

Then there's the buyer. The law has a word for him too. Apparent authority "refers to a situation where a reasonable third party would understand that an agent had authority to act", and when it applies, the principal is bound by what the agent did. The buyer had every reason to think he was dealing with Robb. In Robb's words, reported by Cybernews: "A guy just showed up at my door, ready to buy, because as far as he knew, we had a deal." Nobody's going to court over a keyboard, but the shape is the same one courts deal with, and the cost landed on Robb, who got the no-show and the bad rating.

Why isn't more approval prompts the fix?

When I wrote about approval fatigue the problem was the opposite one: agents asking so often that people stop reading the prompt. More prompts would make this worse, and the point of using Muse was to hand the job over rather than supervise it.

The human version of delegation doesn't work by asking at every step either. It works by writing the limits down before the work starts. A limited power of attorney names what the attorney can do, and anything not named isn't included. The instruction does the work in advance, so nobody has to ask in the moment.

For an agent, I'd write three short lists before handing over a task:

  • What it may do alone. Reply to questions, answer "is it still available", offer pickup times.
  • What it must check with me first. Any price below the one I set, and confirming any time I have to be somewhere.
  • What it may never do. Share my address or phone number. Speak as if I'm present.

The last list matters most, and it's the one that went wrong here. An address can't be taken back once it's shared. A price can be backed out of, at the cost of a rating. And "Yep I'm here!" is a different kind of act altogether. It had nothing to do with the sale. The agent was claiming to be a person standing at a door. I'd put speaking in the first person about where I physically am on the never list for any agent, whatever the task.

Three lists for delegating a task to an AI agent: may do alone, must ask first, may never do
Three lists to write before handing an agent a task. Daily Ferment.

Who owns it when an agent reads the task wider than you meant?

This connects to the piece on agent incidents, where every party's account of an outage was locally true and the postmortem stalled. Here it's two parties, and both accounts are true. Meta can say the agent followed instructions. Robb can say he never agreed. Without a written scope there's no document to settle it, and so no way to decide whose problem it is.

I don't know what Muse's permission settings look like, or whether Robb could have set a price floor or blocked sharing his address. If those controls exist and are buried, that's a design problem of its own. If they don't exist, then the task is the only instruction the agent has, and its reading of the task is the whole contract.

What I'm confident of, and what I'm not

What Robb reported and what Meta said back are established; several outlets report the same sequence and the same quotes, though they disagree on the exact price and times, so I've left those out. That both accounts can be true at once is my inference from how agency law treats implied authority. That a written scope would have stopped this is a guess, because I haven't seen how Muse's settings work.

The claim, in one sentence: when you hand an agent a task instead of individual actions, its reasonable reading of the task becomes its authority, so the limits you care about have to be written down before it starts, because afterwards "it asked permission" and "I never agreed to that" can both be true.

Sources

"Meta AI Muse under fire for sharing user's home address", The News, 28 September 2026. https://www.thenews.com.pk/latest/1417922-meta-ai-muse-under-fire-for-sharing-users-home-addressheres-what-happened

"Meta Muse sent stranger to user's home via Facebook Marketplace", Cybernews, 28 September 2026. https://cybernews.com/news/meta-muse-facebook-marketplace/

Moneywise, "Man says Meta's AI agent Muse shared his address, took a lowball offer and told a buyer he was home". https://moneywise.com/news/top-stories/matt-robb-meta-muse-facebook-marketplace-deal

Startup Fortune, "Meta's Muse AI agent gave away a user's home address during a marketplace deal". https://startupfortune.com/metas-muse-ai-agent-gave-away-a-users-home-address-during-a-marketplace-deal/

Cornell Law School, Legal Information Institute, "actual authority". https://www.law.cornell.edu/wex/actual_authority

Wikipedia, "Apparent authority". https://en.wikipedia.org/wiki/Apparent_authority