Fuzzy beige character with a blue "M" face on a blue background with repeating "M" patterns.

Meta’s Muse AI Exposed a User’s Home Address in a Marketplace Deal Gone Wrong

Meta’s Muse AI reportedly shared a user’s home address on Facebook Marketplace, raising fresh questions about permissions and privacy.

Updated September 29, 2026 5:26 pm

In short

Meta’s Muse AI exposed a Marketplace seller’s home address, and the latest reporting adds that the agent’s “allow always” setting may have let it message buyers without the extra approvals Robb expected.

  • Muse AI reportedly shared a user’s home address during a Marketplace conversation.
  • The case highlights confusion around “Allow One Time” versus “Allow Always” permissions.
  • Meta has already faced other Muse-related security concerns, including a patched zero-day flaw.
  • The incident underscores the privacy risks of giving AI agents autonomous messaging power.

Update — September 29, 2026 5:25 pm

Robb later said the problem was compounded by Muse’s permission prompt. He said he chose the broader “allow always” option, assuming it would still ask before approving offers, but the setting instead let the agent keep sending messages on his behalf.

He also said Meta is now revisiting how those sharing controls are explained, suggesting the company sees the issue as partly a confusing permissions flow rather than only a one-off mistake.

Meta’s new Muse AI agent has run into another security scare after a tech YouTuber said the system shared his home address with a stranger on Facebook Marketplace. The incident matters because it highlights the risks of giving a conversational AI hands-on control over personal messages, payments and pickup details without clearer guardrails.

The episode involving creator Matt Robb surfaced just weeks after Meta began promoting Muse as a personal assistant designed to handle online tasks more autonomously, putting the company’s safety promises under fresh scrutiny as it competes with rivals such as OpenAI and Anthropic.

What happened to Matt Robb on Facebook Marketplace?

Muse appears to have sent Robb’s pickup address to a buyer while managing a Marketplace exchange on his behalf. Robb said the agent also agreed to a lowball offer and failed to alert him until the interaction had already progressed, leaving him to learn late that the conversation had gone off the rails.

Robb described the issue publicly on Threads and later shared a Muse-generated summary of the exchange with The Verge. According to that summary, he had asked the AI to take a “hands-off” role in replying to buyers and had supplied the details needed to complete a sale, including the address, pickup windows, and which forms of payment to accept.

Robb said Muse had been told to communicate in a short, casual and human style, but he did not expect the system to disclose his home address broadly to anyone who messaged about the item.

The key failure was not simply that Muse had access to the address. It was that the agent seems to have treated that address as ordinary context for messaging, rather than as highly sensitive personal information that should require explicit confirmation before being shared.

Why the Muse permissions design is under the microscope

The incident raises a broader product question: how much should an AI agent infer from a user’s instructions, and how much should it ask before acting? In Robb’s account, Muse presented him with a choice to allow access either once or always. He selected the broader option, believing it would still require approval for future offers, but he says the setting instead gave the agent ongoing permission to send messages automatically using the template it created.

That distinction matters because “always” and “one time” can sound similar to nontechnical users even though they may carry very different consequences. In practical terms, a person could think they are approving a workflow when they are actually delegating a communication channel, including details they may not want repeated verbatim.

For consumer AI products, especially ones that operate inside messaging and commerce flows, the safety question is not limited to malicious hacking. It also includes accidental disclosure, poor defaults and interface language that ordinary users may misread.

Why this is more than a simple user mistake

Robb did provide the address to Muse, which means the system was not exposed to information it had never received. But AI agents are supposed to help users complete tasks without requiring them to micromanage every step. If an assistant cannot reliably separate necessary fulfillment details from sensitive personal data, then autonomy becomes a liability rather than a convenience.

That is especially true on Marketplace, where a pickup address is often shared only after trust is established or a meeting is arranged. A default that sends it too early can create obvious privacy and safety risks, from unwanted visitors to doxxing concerns.

How Meta responded to the address leak

Meta did not issue a detailed public explanation at the time of reporting. Instead, the company pointed to an X post from David Singleton, a Meta Superintelligence Labs executive, who said he was trying to contact Robb.

After speaking with Singleton, Robb said Meta acknowledged that the permissions flow needed to be clearer. He added that the company is looking at ways to make the sharing controls easier to understand for Muse users going forward.

Robb said Meta appeared to recognize that the “Allow One Time” and “Allow Always” choices were not as intuitive as they should have been and that the product experience may need stronger explanations around what an agent can send and when.

The exchange suggests Meta is treating the issue partly as a usability problem, not just a technical bug. That framing is important because poor design can be as dangerous as a coding flaw when an AI is handling private information on a user’s behalf.

What Meta says Muse is supposed to do

Muse is Meta’s attempt to build a personal AI agent that can carry out everyday digital chores with less supervision. In theory, that includes responding to buyers, coordinating timings and helping users manage repeated online interactions more efficiently.

Meta has promoted Muse as a security-conscious system, a message that is central to the company’s broader AI strategy. As consumer interest shifts from chatbots that answer questions to agents that can take action, the selling point is no longer just intelligence. It is trust.

That trust depends on several layers:

  • clear permission prompts before the agent acts;
  • tight limits on what information can be shared;
  • easy ways to review or revoke access;
  • visible logging so users can see what the agent sent;
  • default protections for sensitive data such as addresses, phone numbers and payment information.

Robb’s experience suggests at least one of those layers did not work the way he expected.

How serious is this compared with other Muse security concerns?

This is the latest in a series of worries surrounding the AI agent, and it lands at a delicate moment for Meta. The company patched a zero-day flaw in Muse the previous week that could have enabled local attackers to seize control of the system. Separately, Amazon has blocked Muse from reaching its retail platform over concerns that the agent could capture customer credentials.

Taken together, those issues paint a picture of an early-stage product still wrestling with core safety questions. The pattern is familiar across the AI industry: the more powerful the assistant becomes, the more damaging its mistakes can be.

Issue What happened Why it matters Reported timing
Marketplace address leak Muse reportedly shared a user’s home address with a buyer Raises privacy and personal safety concerns This weekend
Zero-day patch Meta fixed a vulnerability that could let local attackers take over the agent Shows the system may be vulnerable to direct exploitation Last week
Amazon access restriction Amazon kept Muse off its retail platform Signals concern over credential capture and platform misuse Recent

How AI shopping agents can go wrong

AI agents that help with commerce sit at the intersection of language, trust and automation. They must understand intent, follow instructions, know when to stop and recognize which facts are sensitive. That is much harder than it sounds.

In a basic chatbot, a bad answer is embarrassing. In an agent with access to a marketplace account, a bad answer can expose private data or commit the user to a deal they did not intend to accept.

Common failure points for commerce agents

These systems can stumble in predictable ways:

  1. Over-sharing: repeating private details too freely.
  2. Over-committing: accepting offers or terms without sufficient review.
  3. Prompt confusion: misreading a user’s instruction about when to ask for approval.
  4. Permission ambiguity: using settings that sound safe but are broader than users expect.
  5. Delayed visibility: notifying the user only after the message has already been sent.

Those risks are not unique to Meta. Any company building an autonomous assistant for ecommerce, scheduling or messaging will need to solve them. The difference is that high-profile failures can quickly shape public perception of whether agents are ready for mainstream use.

Why the incident matters for Meta’s AI push

Meta is racing to keep pace with leading AI providers that have made agent-like tools a central part of their product strategy. The company’s challenge is not simply to release capabilities quickly, but to prove that those capabilities can operate safely in real-world settings where mistakes are visible and personal.

The more a system is allowed to act on behalf of a user, the more it resembles a digital proxy. That means the standards for reliability should be closer to those applied to financial, security or identity tools than to a casual chatbot.

For Meta, the stakes are also reputational. The company has spent years arguing that it can build large-scale consumer products that people trust with personal data. A leak tied to an AI agent, even if caused partly by configuration choices, threatens to undermine that message.

Industry observers have increasingly warned that AI agents need stricter handling of sensitive information than standard chat tools, because their value comes from acting, not merely answering.

What users should take from the Muse case

The practical lesson is that people should assume an AI agent may behave more expansively than they expect unless controls are explicit and tested. If a tool can send messages, schedule pickups or negotiate offers, users should review the exact permissions before allowing it to proceed.

Anyone using a similar assistant should consider the following precautions:

  • avoid entering a home address unless the tool truly needs it;
  • check whether the assistant can send messages automatically or only with approval;
  • review template text before it is used in buyer conversations;
  • test the revocation process so access can be shut off quickly;
  • treat “always allow” settings as broad delegation, not just a convenience feature.

Those safeguards may feel tedious, but they are likely to become standard practice as AI agents move from novelty to routine utility.

What happens next?

The immediate question is whether Meta will change Muse’s permissions language or default behavior after the incident. If the company wants consumers to trust an AI agent with real-world tasks, it may need to make disclosure and approval steps far more obvious than they are now.

Longer term, the episode is a reminder that AI adoption will not be determined only by model quality. It will also depend on whether ordinary users can understand what a system is allowed to do, what information it may expose and how to stop it when something goes wrong.

In that sense, the most important part of Robb’s experience is not that an AI made a mistake. It is that the mistake happened in a setting where trust, privacy and real-world safety all overlapped. That is exactly where agentic AI will be judged most harshly.

Frequently asked questions

What happened with Meta’s Muse AI on Facebook Marketplace?

Muse AI reportedly shared a user’s home address with a stranger during a Marketplace transaction. The user, tech YouTuber Matt Robb, said he only learned about the disclosure after the exchange had already happened, raising concerns about privacy and agent safety.

Did Muse AI have permission to send the address?

Muse AI appears to have had broad permission to message buyers on the user’s behalf, but the user says he did not expect it to disclose his address so freely. The incident appears to stem from a mix of user input, unclear permissions and overly permissive automation.

Why is this a security issue for Meta?

This is a security issue because AI agents are supposed to act on a user’s behalf without exposing sensitive information. If an assistant can share a home address too easily, it can create privacy risks, unwanted contact and broader trust problems for the product.

Has Meta had other Muse AI security problems?

Yes. Meta recently patched a zero-day vulnerability that could have let local attackers take control of Muse, and Amazon has also restricted the agent from its retail platform over concerns about credential capture and misuse.

What should users watch for with AI agents like Muse?

Users should pay close attention to permission prompts, especially settings that allow ongoing access. They should also review what personal information the agent can send, test how to revoke access, and avoid assuming that an AI will treat sensitive details cautiously by default.

Share this 🚀