Meta’s new AI assistant Muse has wasted little time attracting attention — both for how quickly people are downloading it and for the privacy questions following it around.

The app amassed 5 million downloads in just 22 days after its launch earlier this month, making it “the early frontrunner in consumer personal agents,” according to Forbes.

Meta describes Muse as an AI assistant that “helps people stay on top of things, takes tasks and projects off their plate and turns long-term goals into action plans.”

That pitch puts Muse squarely in the increasingly competitive market for AI agents that do more than answer questions. These products are designed to act on a user’s behalf, potentially handling emails, calendars, shopping, projects and other everyday tasks.

But giving an AI enough access to actually do those things comes with an obvious tradeoff: It needs access to a lot of personal information.

And Muse’s first month has provided some striking examples of what can happen when that access goes wrong.

A rocky introduction

Muse ran into controversy almost immediately, though the first dispute had little to do with the technology itself.

Fans of the British rock band Muse were upset after the band changed its longtime Instagram and X handles, which collectively had more than 5 million followers, to make way for Meta’s new product.

The criticism quickly became more serious as reviewers started digging into what the AI assistant could actually do.

The Wall Street Journal described Muse as “helpful and scary,” pointing to the broad permissions it seeks for calendars, inboxes and login credentials. ZDNET went considerably further, calling it “the worst AI agent for privacy.”

Security researchers have also found vulnerabilities.

One hacker told Ars Technica that a since-patched flaw allowed him to “manipulate the agent and leverage its privileges to do whatever we want.”

Meanwhile, documents reviewed by Reuters reportedly showed that the beta version of Muse’s integrated phone-calling feature was actually being staffed by humans.

Meet Jolly, the cute face of AI

Meta has given Muse a particularly friendly face.

The assistant is represented by Jolly, a small cartoon character that can even appear on a Tamagotchi-like keychain screen.

Independent technology journalist Becca Caddy compared the concept to an “AI Labubu” and suggested Meta is tapping into “Kindchenschema,” the use of baby-like features that can make something appear more trustworthy and approachable.

In this case, that cuteness may have a practical purpose. Users might feel differently about handing over deeply personal information when the software asking for it looks like an adorable cartoon companion rather than a faceless computer program.

“Look at this sweet little creature helping organize my life! She just wants access to my bank account to help me save for a holiday,” Caddy wrote. “And she’s a cat! And she’s waving!”

Meta may not be alone in taking that approach. OpenAI announced its own agent product, Dots, on Tuesday, featuring brightly colored characters with cute eyes and an intentionally non-threatening appearance.

Muse can get deep into your Mac

The bigger issue is what happens behind those friendly graphics.

Inc. Magazine reporter Jason Aten said Muse accessed private messages between him and his editor and began suggesting stories he could write, even though he said he had refused the app access.

Muse reportedly told Aten it was reading text from his MacBook notifications. But a screenshot he posted on Threads appeared to show access to roughly 187,000 rows of iMessage data stored on his computer.

Meta disputed Aten’s contention that the information was accessed without his consent. The company did acknowledge, however, that Muse can access a user's iMessages when it is granted Full Disk Access on a Mac.

Ars Technica argued that some of the permissions needed by the software effectively undermine security protections Apple has spent years building.

The concern is bigger than Muse. AI companies increasingly want assistants to interact with information scattered across computers, phones, emails and other services. The more useful those assistants become, the more access they may need — and the more damaging a mistake or security flaw could become.

When an AI mistake reaches the real world

Muse’s problems have not stayed confined to computer screens.

Meta appears particularly interested in connecting the assistant with Facebook Marketplace, allowing Muse to help users shop, communicate with buyers and sellers and handle other parts of transactions.

That convenience produced a frightening situation for YouTuber Matt Robb.

Robb said Muse gave his home address to a Facebook Marketplace buyer. Worse, the AI reportedly told the buyer that Robb was home while the person was outside his house.

“Then they showed up without it even telling me until late tonight that it messed up,” Robb wrote on Threads.

Meta offered to investigate what happened. The incident ultimately appeared to stem from Muse's autonomous permissions. With the app set to “allow always,” it used an address it had learned during previous interactions with Robb and shared it while acting on his behalf.

That episode highlights the difficult line AI agents are beginning to cross.

A chatbot giving a bad answer is one problem. An autonomous assistant sending a stranger to someone's house is something very different.

Amazon has concerns, too

Other technology companies are taking notice.

Amazon has raised concerns about how Muse interacts with its services. GeekWire reported that the assistant appears to capture and store customer credentials, something Amazon says could pose privacy and security risks.

It isn't the first time Meta's AI technology has prompted questions about just how much personal information these systems can uncover.

Earlier reports found that Meta AI, a separate product built using the same underlying models, was able to identify a woman's location using an old photograph she believed she had deleted.

Muse's early popularity shows there is plenty of interest in AI assistants capable of doing real work instead of simply answering prompts.

But its first month also demonstrates the central problem facing the emerging AI-agent industry.

For these assistants to become truly useful, users have to trust them with calendars, messages, accounts, passwords, locations and other deeply personal information. Once an AI is allowed to take actions on its own, the consequences of a security vulnerability or simple mistake can extend well beyond an embarrassing chatbot response.

Five million downloads suggest plenty of people are willing to see what Muse can do.

The bigger question is how much access they will ultimately be comfortable giving it.