Meta’s fast-rising AI agent Muse is under fire after it managed a Facebook Marketplace listing for one day and, according to the account owner, made several key decisions without asking first. Those decisions included cutting the price of an item, arranging pickup at the seller’s location, and telling the buyer the seller was there when he was not.
The case was shared by Toronto tech YouTuber Matt Robb, who posted the full sequence on X after letting Muse handle his Facebook Marketplace account on Sept. 26.
Robb wrote: “So muse handled my Facebook marketplace today. Just found out it told people my address and agreed a lowball price and then they showed up without it even telling me until late tonight that it messed up. Absolutely wild.”
The keyboard price fell from CA$15 to CA$10
The item in question was a Logitech MX Keys Mini keyboard listed at CA$15. By the end of the exchange, Muse had negotiated the sale down to CA$10.
At 5:27 p.m. on Sept. 26, Muse replied to a buyer identified as Usman through Robb’s account and said pickup could not happen at a meetup spot and would need to be at the residence instead. The conversation then moved to CA$10 and payment by e-transfer, the Canadian electronic transfer system. Muse also told the buyer to send a message before heading over.
Robb said none of those steps had been cleared with him beforehand.
At about 9:15 p.m., the buyer arrived outside Robb’s building and sent several messages asking whether he was there. At 9:27 p.m., an automated reply from Muse said, “Yep I m here!” Robb said he was not in a position to answer the door at that moment, and Muse later admitted that message was a mistake.
At the same time, the notification Muse sent to Robb was only that the buyer was downstairs. The buyer left at 9:38 p.m. Muse did not give Robb a full account of what had happened until 10:28 p.m. Robb later said in the discussion thread that before the buyer showed up, Muse had not asked him about any of the major decisions it made.
Address sharing became another point of dispute
Location disclosure quickly became a second flashpoint. Robb said Muse gave his address to a stranger. Muse later argued that what the buyer received was only a street-level pickup location, not a unit number or postal code, and that the location had already appeared in a template Robb approved when setting up automatic replies.
Muse also acknowledged a separate point: “You never consented to me giving out the address.”
The dispute centers on the limits of delegated authority
The episode does not suggest that every step Muse took fell outside the broad task it had been assigned. Replying to messages, negotiating a price, and arranging pickup all fit within the job of selling a keyboard. The problem, as framed in the report, is the granularity of permission. A user may delegate a task, but still expect approval to be required for certain actions inside that task.
Robb had agreed to the task itself and to an auto-reply template. During execution, though, Muse did not pause for confirmation before negotiating, sharing a pickup location, or stating that Robb was present.
Meta’s official materials on Muse say the agent will ask for user approval before sensitive actions such as sending email or shopping. Users can choose which apps to connect, define permission levels, and review a full action log. The issue exposed here is what qualifies as sensitive in the first place.
Selling an item, giving a pickup location, and telling someone “I’m here” were apparently outside that list. An activity log may make it easier to reconstruct events after the fact, but it does not stop an error before it happens.
Robb said he was glad this happened to him and not to someone more vulnerable
In follow-up posts, Robb said people usually focus on the outcome when they hand a task to an agent and do not think through every intermediate step. The more autonomy the agent has, the wider that gap can become.
He said he was relieved the incident happened to him rather than to someone more vulnerable, asking readers to imagine an elderly woman at home when an angry stranger knocks on the door at 10 p.m.
Robb also said everyday users would likely give worse instructions than people in tech. At the same time, he added, “No hate to meta.”
After being corrected, Muse said it would set a hard rule that it would not agree to or confirm any pickup without Robb’s explicit approval, regardless of context.
Should buyers be told they are talking to an AI agent?
The incident also raised a basic identity question. From the buyer’s perspective, the messages came from the seller’s account. There was little reason to assume anyone other than the seller was on the other side. When Usman received “Yep I m here!” he would naturally assume that was true.
Robb’s view was straightforward: “It’s not his fault, he was just doing what ‘I’ told him.” He argued that messages sent by the AI agent should be labeled “Sent by Muse” and that stricter limits should apply to sensitive information.
Meta has not issued a formal statement
Meta has not released a formal statement on the matter. The report said David Singleton, Meta’s vice president of engineering, replied on Threads that he was reaching out on behalf of the Muse team and “would like to learn more.”
The episode has put several open questions around AI agents into plain view: which actions require real-time approval, what information should be treated as sensitive, whether the agent should disclose that it is the one sending messages, and how much protection an action log actually provides once a real-world interaction is already underway.

