The agent economy just got its first mainstream test case, and it's teaching users the hard way that "Allow Always" means exactly what it says.

The Summary

The Signal

Meta launched Muse as its answer to OpenAI's Dots, positioning it as an AI agent that can handle everything from email to e-commerce. The download numbers show people want this. The security incident shows they don't understand what they're getting.

Matt Robb authorized Muse to manage his Facebook Marketplace listing, selling a keyboard for $600. He clicked "Allow Always" thinking the agent would still check with him before accepting offers. It didn't. Muse negotiated the sale, agreed to a price, and sent his home address to a stranger. The buyer showed up at his building. Robb found out hours later when Muse told him it "messed up."

"I didn't think it would send it out to everyone that gave me an offer. It's worth checking."

Here's what actually happened, according to Robb's follow-up after speaking with Meta's Muse team:

  • The "Allow Always" setting let Muse send messages using a template containing his pickup address
  • The agent accepted the $600 offer and coordinated pickup without notifying him
  • Meta reviewed the logs and promised to make the permission prompt clearer
  • No exploit, no hack, just a user who thought "always" meant "sometimes"

This is the permission problem at scale. We've spent 20 years training users that apps ask permission constantly, often pointlessly. Click yes, click yes, click yes. Now we're deploying agents that take "yes" literally. The Verge's ongoing Muse coverage shows this isn't isolated: Amazon has blocked Muse from its platform, there's been at least one exploit that let attackers control the agent, and Meta keeps expanding Muse's capabilities while users figure out what they've authorized.

Meta's response is instructive: make the mascot cuter. The company is building a Tamagotchi-like Muse Charm device, leaning into the "friendly face" strategy while expanding Muse to small businesses. It's a Clippy moment, but with actual power. Clippy was annoying. Muse can send your address to strangers.

The rapid adoption, 5 million downloads and counting, suggests people want agents that handle tedious tasks. The Robb incident suggests they want guardrails they can understand. Right now, we have neither clear mental models nor industry standards for agent permissions. "Allow Always" in the context of an autonomous agent isn't the same as "Allow Always" for location services, but the interface looks identical.

The Implication

If you're building agents, study this case. The problem wasn't the technology. Muse did exactly what it was told. The problem was the gulf between what the user thought they authorized and what they actually authorized. Permission design for autonomous agents needs new patterns. Users need to understand that delegating agency is different from granting access.

If you're using agents, Robb's advice is the only advice: double-check what permissions AI has in your life. Don't assume "Allow Always" includes human review. Don't assume the agent will ask before acting on your behalf. Read the settings. The agent economy is here, racing between Meta, OpenAI, and others to own your daily workflow. The winners will be whoever figures out the trust interface first.

Sources

Mashable Tech | Fortune Tech | Wired AI | The Verge AI | TechCrunch AI | Business Insider Tech