On September 26, Matt Robb tried “letting muse run my Facebook Marketplace for a day.” Muse is the personal AI agent Meta began rolling out this month.

Matt’s screenshots show how the day went. At 5:27, a message from Matt’s account told a buyer the pickup would have to be at Matt’s address. At 7:27, another said: “Sounds good, e-transfer works. Just message me before you head over tonight!” Matt says the agent agreed to a lowball price “I never approved.”

The agent’s own summary tells the rest. The buyer arrived around 9:15, messaged several times, and nobody came down. At 9:27 its auto-reply told the buyer “Yep I’m here!”, when Matt wasn’t available. The buyer left at 9:38 and left a negative rating.

At 10:28 the agent told Matt what had happened, including an apology it had already sent the buyer from Matt’s account, offering to try again another day. It had sent Matt a heads-up about the buyer earlier in their chat. Matt posted about it that night.

Meta’s help pages say that by default, Muse won’t take many important actions, like sending an email, without your approval. On X, David Singleton from the Muse team offered to help look into it. In similar reports before, the team had “consistently learned that Muse was following direct instructions and correctly asked for permission.” Neither side has shown what Matt approved, so I won’t guess.

Everything that went wrong was a message to the buyer

Look at what reached the buyer: Matt’s address, a price Matt calls a lowball, a pickup that night, “Yep I’m here!”, and an apology offering another day. Every one of them came from Matt’s account. On X, Matt put it this way: the buyer “did exactly what ‘I’ told him to do.”

I wrote in July that an agent should ask before anything it can’t take back. This is the second line our operating principles draw: anything that reaches another person. A message speaks for you, and the person reading it holds you to it.

One approval can cover every message in a task

Meta publishes the choices Muse offers when it asks. “Allow for this task” lets Muse “take this type of action for the entire task.” “Always allow” lets it take that type of action “in the future without asking again.”

Vellum makes the same trade: its trust rules “always allow or always deny specific actions,” and “the more you approve, the fewer prompts you see.” For a busy person that’s tempting. It also means one tap early in a task can cover messages later in it that nobody reads before they go.

In Archie, a reply to anyone else waits for your yes

Matt’s reply to the agent is the rule I’d have written:

You gotta never do that ever again don’t agree for pickup unless you check with me

The agent answered that “a hard rule” was now locked in. How well a rule like that holds depends on the product: whether it becomes a setting, or a note the AI has to keep applying to every message after this one.

In Archie that rule is part of the app. A text goes out only when you press Send on the draft, and an email only when you send it or set a time for it; your agent can do neither on its own. Each Send sends the one reply on its card, and no setting turns that asking off.

A routine running on a schedule can draft replies all day, and every draft waits for you like any other. When you approve a text, it goes out from your own number, exactly as if you had typed it, because iMessage has no way to mark a message as written by an assistant.

Asking first is slower, and a wrong draft you approve still goes out

The cost is time. A buyer who writes while you’re out waits until you look at your phone. For a message that carries your address, I’ll take the wait.

The asking also can’t make a draft right. If the agent misreads you and you approve without looking, it carries out the mistake faithfully, and a wrong pickup time goes out like a right one. The asking covers what your agent sends and changes, and a web search it runs still carries whatever it put into the query.

Check what your agent may send without you

If you use an agent that can message people for you, open its settings and find what it may send without asking, including anything you once told it to always allow. Read each item as a message going out under your name, and turn off any you wouldn’t sign.