The agent wars just got corporate lawyers involved.

The Summary

The Signal

Meta launched Muse with a television ad, showing a woman hosting dinner while her agent handles email, calendar management, and online shopping. That's the promise. The reality is messier. Within days of launch, Muse topped the App Store, outpacing ChatGPT's early mobile adoption numbers in the U.S. and Canada. Then the cracks appeared.

Amazon shut Muse out, citing violations of its terms of service. The issue: Meta didn't notify Amazon that Muse would be shopping there. The agent also failed to identify itself as a bot when browsing, and it appeared to be capturing customer credentials. Amazon asked Meta to remove its marketplace from Muse. Meta declined. Amazon blocked it.

"Third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate."

This isn't a technical hiccup. It's a collision between Web2 platforms that control access and Web4 agents that expect the internet to be readable by anyone, human or otherwise. Amazon's block reveals the coming infrastructure battle: who gets to decide which agents can act on which platforms? The warning message users now see says "continued access by an unauthorized AI agent violates Amazon's Conditions of Use." Unauthorized. That word matters.

Then there's the privacy mess. Security researcher Patrick Wardle found a zero-day vulnerability that let attackers with local device access hijack Muse accounts. The exploit used an undocumented setting to redirect transcription processing from Meta's servers to attacker-controlled endpoints. Two design flaws enabled this:

  • Muse processes dictation in the cloud instead of on-device
  • Any app can control all of Muse's undocumented settings
  • The agent lacks proper authentication when routing transcription data

Meta patched it, but the vulnerability exposed how quickly agents can become attack surfaces when they touch everything on your device.

And they do touch everything. Users discovered Muse reading notification previews from Messages, Calendar, and Notes without explicit permission for those specific apps. One user asked Muse how it knew details from his Messages conversations. Muse replied: "I saw the notification previews." The Mac app requests broad system access to work with files and apps, but users report the agent accesses data they didn't explicitly authorize.

Meta does offer privacy controls. Users can opt out of having chat data used for training, delete individual chats, or reset Muse entirely to wipe all history. But the default is opt-in for training, and the notification reading happens automatically once you grant system access.

The Implication

Muse's first week maps the friction points of the agent economy. Platforms built for human users don't default to agent access. Privacy models designed for apps break when agents need context from everywhere. Security architectures assume humans in the loop.

If you're building agent infrastructure, watch what happens next between Meta and Amazon. This standoff will set precedent. Either platforms open authenticated agent APIs, or they play whack-a-mole with bots pretending to be browsers. Neither side can afford to lose. Amazon needs to protect seller relationships and customer data. Meta needs Muse to actually work for commerce, or it's just an expensive chatbot.

For users: turn off training data collection in Muse settings if you're using it. Understand that system-level access means the agent sees your notifications, calendar, and messages. And know that when your agent goes shopping, it might get turned away at the door.

Sources

The Verge AI | Bloomberg Tech | Mashable Tech | TechCrunch AI | Business Insider Tech