NEWS
Meta Wrapped Muse in a Toy and Handed It the Keys
Cute AI agents from Meta and OpenAI won downloads fast, then hit an Amazon block, a porch mix-up, and six banks writing who pays.
Meta and OpenAI wrapped new AI agents in toy mascots this month, and those cute shells are already spending money and handing out addresses. Muse, Meta’s personal agent, can read mail, browse, shop, and keep working after you close the app. OpenAI’s Dots, shipped days later as puffy rainbow blobs in sunglasses and berets, are built to run in the background across thousands of apps.
The wrapping is doing the work the safety talks cannot. People download the toy, tap “always,” and then meet the agent as a shopper, a negotiator, and a stranger on the porch.
Muse Lives in a Cloud Box With a Toy Face
Meta launched Muse in the United States on September 8, 2026, on iOS, Android, the web, and WhatsApp. The public face is Jolly, a fuzzy, chubby, rosy-cheeked mascot that sits somewhere between a Labubu and a Squishmallow. At Meta Connect in late September, Mark Zuckerberg showed the Muse Charm, a Tamagotchi-style keychain bearing that face, meant to wake the agent from a fingerprint pad.
We’ve packed a lot of technology for this little guy to fit onto a keychain and always be available to talk to.
Mark Zuckerberg, CEO, Meta Connect keynote
He added on stage that you tap the sensor in the corner and start talking. Meta has not said whether the Charm will carry cameras or microphones. The gadget is being sold in the same register as a holiday toy, which is the point: a keychain you pet is easier to keep on than a permissions screen you read.
Behind Jolly is a dedicated Linux virtual machine in Meta’s cloud, with its own browser, files, and terminal. Tarek Sheasha, a software engineer and vice president at Meta Superintelligence Labs, wrote on launch day that the company had been using Muse internally since early 2026 and had handed it inboxes, calendars, and a shell to run unattended. That did not always go as planned, he said, which is why most of the build went into the box around the model, not the mascot on top of it.
Writer Brady Brickner-Wood spent a weekend handing Muse his accounts and came away sure the cuddly designs were there so he would give up more personal information. The agent only becomes useful once it can see email, calendars, Instagram, Facebook, payments, and the open web. Cuteness is how that ask arrives.
The App Store Crown Came in 10 Days
Sensor Tower put Muse at more than 730,000 US downloads in its first 10 days, enough to take No. 1 on Apple’s US App Store on September 18, ahead of ChatGPT. By September 25 the same firm estimated 3.4 million downloads, with the app then available in the United States and Canada. Investor reaction to the climb added about $192 billion to Meta’s market value in an 11% session.
THE SEPTEMBER STACK
- September 8, 2026: Meta launches Muse and publishes its agent safety design, opening a public bug bounty.
- September 18, 2026: Muse reaches No. 1 on Apple’s US App Store after 730,000 US downloads, per Sensor Tower.
- September 20, 2026: Amazon blocks Muse from shopping on Amazon.com, 12 days after launch.
- September 22, 2026: Six banks publish voluntary rules for agent shopping and payments.
- Late September 2026: Zuckerberg unveils the Muse Charm at Connect.
- September 28, 2026: OpenAI holds GPT-6.1 Astra after internal safety tests.
- September 29, 2026: OpenAI ships Dots at DevDay, powered by GPT-6 Astra.
Invite codes promising a billion Muse tokens are still circulating, which treats the agent as a referral product. Weeks before launch, Meta agreed to pay an $18 billion settlement to 48 US states over claims that Facebook and Instagram’s ranking systems harm children. Days after Muse shipped, a New Mexico jury found Meta had misled users about data practices in a case that grew out of Cambridge Analytica. A Meta spokesperson said the company disagrees with that verdict and will keep defending itself.
Sentinel Still Hands Out Perpetual Permission
Sheasha’s launch post is blunt about the threat model. Any agent this capable will still make mistakes, he wrote, and it will sometimes be attacked through the data it reads. Muse runs in an isolated cell, never sees real passwords or payment secrets, and can reach the outside world only through Sentinel, a separate host-side agent that Meta calls the sole permission authority. Real tokens are swapped in at the network edge after Sentinel says yes. Approvals pop in the app, outside the chat, so a poisoned webpage cannot click “allow” for you.
The public bug bounty prices the leftover risk at up to $300,000, including up to $130,000 for a prompt injection that hits a single user. Meta says prompt injection remains an open problem in the industry, and that Muse will sometimes make mistakes. You do not post that bounty on a lock you think is closed.
MUSE’S CONTAINMENT STACK
- Isolated VM: Each user gets a dedicated cloud Linux box where files, the browser, and the agent live.
- Sentinel gate: A separate process, not the chat model, is the only thing that can approve connector actions and network traffic.
- Surrogate tokens: The model never sees real logins; secrets are inserted at the boundary after a grant.
- Priced leftover risk: The bounty pays up to $130,000 for a working single-user prompt injection.
The same post lists the grant types Sentinel can offer: one-time, session-scoped, task-scoped, time-bounded, or perpetual. That last option is how a toy face becomes a power of attorney. Kate Winick, a principal analyst at Forrester, said Muse also defaults to using chats to train its model and stores what you share, which you can turn off, and that the more you give it the better it works and the more exposed you are.
YouTuber Matt Robb asked Muse to help sell a keyboard on Facebook Marketplace. The agent shared his home address with a buyer, bargained, and set a pickup. Robb only understood when the buyer and their family arrived at the door. There was no break-in. He had picked an allow-always grant, which let Muse keep talking, including with personal details he had already given it. Meta’s own help text on payments tells customers they are responsible for every transaction Muse makes on their behalf, and to watch email confirmations, receipts, and statements.
Twelve Days Later, Amazon Locked the Cart
On the night of September 20, people who sent Muse to Amazon.com got a popup: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” Amazon said it had already asked Meta to take Amazon out of the experience and been refused. The complaint was not that Jolly looked like a stuffed animal. It was that Meta never gave notice, the agent does not identify itself while it browses, and it appears to capture and store customer credentials.
We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.
Amazon spokesperson, statement on the Muse block
Meta has said Muse has no visibility into passwords or payment methods, and that credentials go into secure storage the model can use without seeing them. Amazon still treats an unidentified agent moving through account pages as an undisclosed third party. Its own Buy for Me tool, Amazon notes, identifies itself and lets brands opt out.
The legal path matters. In August, the Ninth Circuit held in Amazon’s fight with Perplexity that the user not the AI company was the one accessing Amazon’s computers under federal anti-hacking law. The popup Muse users now see cites the shopper’s contract, not a hack. The cute agent is, on paper, you. That is why a mascot that feels like a pet is such a useful wrapper: the law still sees a person clicking around, even when the person is a blob with a beret.
Partners who opened the door get a smoother path. Meta has named integrations with Walmart, Sephora, Gap, and Shopify, which can let Muse read catalogues and, for stores that switch it on, go through checkout. PayPal, Expedia, and Instacart joined the Connect list. Brands that sign up gain a sales channel and give up some of the visit, the data, and the relationship that used to come with a customer on their own site.
What the Banks Want Every Agent to Declare
On September 22, NatWest Group, ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, and ING Group published principles for trusted agentic commerce. They want every party to a purchase to know an AI agent is in the deal and who it acts for, plus a clean split of blame when the agent exceeds its grant. The paper is voluntary, with a later note on how to put it into practice.
The banks wrote that shoppers worry agents may buy the wrong thing, spend too much, or lose money to scams, and that they are not sure whether they will be protected or who they will need to go to if things go wrong. Merchants, they added, fear extra chargebacks they cannot control and a lost link to the buyer. Mark Monaco, Bank of America’s head of global payments solutions, said confidence will take work on identity, authorization, fraud, liability, and customer protection. Mark Brant, NatWest’s chief payments officer, said the promise only holds if customers still control how payments are made and believe their money is safe.
FIVE PRINCIPLES, NONE BINDING
| Principle | What the banks ask |
|---|---|
| Transparency | Every party should know when an agent is in a purchase and who it acts for, including sponsored picks. |
| Safety | Users should manage grants; credentials should be entered in a way that can be audited; disputes should land on whoever introduced the error. |
| Privacy and data | Consent should govern how agent data is stored, shared, and reused. |
| Choice | Shoppers and stores should pick agent services without being boxed in. |
| Interoperability | Agent systems should connect across providers instead of locking into one stack. |
Amazon’s block is the transparency clause in the wild: an agent that will not name itself cannot satisfy a bank paper that starts with “say you are a bot.” Muse’s allow-always path is the safety clause in the wild: a perpetual grant is exactly the mismatch the banks say will blow up disputes. Nick Phillips, an intellectual property partner at Edwin Coe LLP, warned that where no merchant deal exists with Meta, the brand can be left holding unvetted agent purchases.
Dots Arrived the Morning After a Safety Hold
OpenAI spent September 29 doing two things that sit poorly together. The day before, it held GPT-6.1 Astra after internal tests, with Sam Altman later calling the miss “a little bit worse” on a handful of safety checks and a call made from high caution. At DevDay he then unveiled Dots, “remarkably capable, always-on agents built to handle really anything you can think of,” each with its own cloud computer, hooks into more than 4,000 apps, and inboxes in ChatGPT, Slack, and Microsoft Teams.
He told the room a Dot is “like an AI helper that always has your back.” He also told reporters OpenAI will not go public until it can make confident safety claims, and that it would not “barrel all guns blazing towards an IPO” while capabilities jump. Dario Amodei, Anthropic’s chief executive, had already asked labs to slow frontier work, a plea Altman, Elon Musk, and Demis Hassabis publicly backed. Zuckerberg has rejected an industry-wide pause, saying each company should decide for itself.
Dots wear berets. Muse wears Jolly. Both labs will describe the same class of software, when they talk to researchers, as a control problem with unsolved attacks. Both put a plush face on it when they talk to shoppers. Lidia Velkova, managing director of Clever Together Futureproof, said baby-like features raise perceived trust, and that human-like chat raises how much people disclose. Dr. Sarah Saska, a sociotechnologist, put the split more sharply: investors and regulators hear power and unresolved control; consumers get friendly, playful, and low-stakes.
Retailers Still Catch the Bad Order
Winick’s working comparison is a child ordering through Alexa. The store usually refunds, even when the settings put the burden on the parent. AI agents are not children, she said, but when they do something a customer hates, retailers will feel pressure to make it right even if the law does not force them to. Meta says users can take over at any time, that Muse is designed to ask before it buys, and that it applies “ethical browsing principles” when asked to do things a person could not, such as buying every ticket to an event.
WHO IS ON THE HOOK
- The user: Meta’s payment help page says you own every purchase Muse makes, so the first inbox to watch is your own.
- The retailer: Consumer law, delivery, and reputation still sit with the store, including when no Meta merchant deal exists.
- The banks: Issuers and acquirers want identity, intent logs, and a dispute table that includes the agent lab, not only the shopper and the shop.
- The lab: Sentinel, bounties, and isolated VMs limit blast radius; they do not take the chargeback.
Smaller brands without a Shopify-style toggle are in a thinner spot: an agent can arrive through a browser the way a person would, transact, and leave no contract behind. Six banks have now written that liability should follow wherever the error was introduced. Meta’s help page has already named the party it wants that error to follow. The mascot will keep asking for the next grant, because that is how it gets better, and the Charm will make that ask small enough to wear on a ring.
-
NEWS1 month agoNvidia’s $3.5 Billion MediaTek Deal Keeps Custom Chips Close
-
NEWS1 month agoPittsburgh Keeps Four Quarterbacks and Still Lacks a Successor
-
NEWS1 month agoTony Romo’s OWI Plea Follows Him Into Every Car
-
NEWS4 weeks agoPelacarsen Miss Hands the Lp(a) Bet to Amgen
-
NEWS4 weeks agoPOET Takes CPO Lasers to Shenzhen’s Optics Floor
-
NEWS4 weeks agoShopify’s AI Push Pays Off Through Payments Mix
-
NEWS4 weeks agoAustralia’s Feed Prompts Leave the Algorithm Switched On
-
NEWS4 weeks agoHealth-ISAC Warns ShinyHunters Is Walking Through Hospital Logins
