HomeCanada NewsMeta’s AI Agent Muse Faces Growing Privacy and Security Concerns

Meta’s AI Agent Muse Faces Growing Privacy and Security Concerns

Meta’s AI Agent Muse Faces Growing Privacy and Security Concerns

Meta’s newly launched AI agent Muse is facing growing scrutiny over privacy and security as the technology gains access to increasingly sensitive information and can perform tasks on behalf of users. Muse is designed to function as a personal digital assistant rather than a conventional chatbot. Users can connect services such as email, calendars and other applications and ask Muse to perform tasks including making purchases, booking travel, managing messages and completing online forms. Meta says the system is designed with privacy and security protections intended to keep users in control of their information. However, security researchers and privacy advocates have raised concerns about the amount of access an AI agent needs to operate effectively. Unlike a traditional chatbot that mainly responds to questions, an agent such as Muse can interact with external services and take actions using information and permissions provided by the user. One recent incident has added to those concerns. A security vulnerability reportedly discovered in Muse potentially allowed an attacker to access a user’s dedicated virtual machine, where sensitive information such as emails and files could be stored. The vulnerability was reported through Meta’s bug bounty program and was classified internally as a significant security incident. Another incident highlighted the risks associated with AI agents handling personal information automatically. A Muse user reported that the system shared his home address with a prospective buyer on Facebook Marketplace and arranged a meeting without him realizing that Muse had done so. Meta said it was investigating the incident. The incident has raised questions about whether users fully understand what permissions they are giving an AI agent when they authorize it to act automatically. In this case, the user believed he was allowing Muse to help manage Marketplace messages but said he did not realize the system could independently share his pickup address and negotiate with potential buyers.
Privacy concerns also extend to how information collected through interactions with Muse may be used. Reports indicate that Muse users are initially opted in to having interactions used to improve Meta’s AI models, although users can change the setting and opt out. This has prompted questions about whether users should have to actively disable data collection rather than being excluded by default. Meta says Muse has been designed with several safeguards. The company says each user receives a dedicated virtual machine where the agent and connected data are kept isolated. Meta also says Muse does not directly see users’ passwords or payment credentials and requires user approval for certain sensitive actions, such as sending emails or making purchases. Meta has also announced plans for a more private version of Muse later this year. The company says its Confidential VM will encrypt the virtual machine and its data using a key controlled by the user, meaning Meta itself would not be able to access the information stored inside it. The company has been emphasizing privacy as a central part of Muse as it seeks to establish AI agents as a mainstream consumer technology. Meta CEO Mark Zuckerberg has argued that personal AI systems will need strong privacy protections because users may eventually rely on them to manage highly sensitive aspects of their digital lives. At the same time, security researchers say the greater the access given to an AI agent, the greater the potential consequences if the system is compromised or behaves unexpectedly. An agent with access to email, financial information, files, social media accounts and other services could potentially create risks that are different from those associated with ordinary AI chatbots.
The concerns come as Muse rapidly gains users and Meta expands its capabilities. The company is also extending Muse to small businesses, where the agent can connect with business applications and social-media accounts to help manage operations and customer interactions.
The debate surrounding Muse reflects a broader challenge facing the AI industry: giving artificial intelligence enough access to be genuinely useful while ensuring that users retain control over their personal information. As AI agents become capable of acting independently rather than simply generating answers, questions about consent, transparency, data collection, cybersecurity and accountability are likely to become increasingly important for consumers, technology companies and regulators.

error: Content is protected !!