Meta Tests Human-AI Hybrid for Muse Agent Amid Privacy and Security Risks
Meta is quietly testing a 'human concierge' feature for its Muse AI agent, blending contractor support with automation to handle user calls. The trial, which includes half of Meta’s employees, aims to shape safety and privacy protections—but internal concerns and a recently disclosed security flaw highlight the challenges of scaling such a system.
LazyFounders

Meta is quietly testing a 'human concierge' feature for its Muse AI agent, blending contractor support with automation to handle user calls. The trial, which includes half of Meta’s employees, aims to shape safety and privacy protections—but internal concerns and a recently disclosed security flaw highlight the challenges of scaling such a system.
30 SEC SUMMARY
- Meta is testing a 'human concierge' feature for its Muse AI agent, where contractors handle some calls placed through the agent.
- The trial involves half of Meta’s employees, with privacy concerns raised internally about sensitive data reaching contractors.
- Muse, launched on September 8, has reached 2.5 million downloads and recently topped the U.S. App Store.
- Meta’s Muse AI was inspired by the open-source project OpenClaw, with similarities in configuration files and design.
- A zero-day vulnerability in Muse could allow attackers to hijack Mac devices, prompting Amazon to block Muse from purchasing on its site.
TABLE OF CONTENTS
- Meta tests hybrid human-AI calls for Muse
- Muse’s rapid adoption and privacy promises
- Inspiration from open-source project OpenClaw
- Security vulnerability raises concerns
- Background: Meta’s AI experiments
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Meta is testing a 'human concierge' feature for its Muse AI agent, where contractors handle some calls placed through the agent.
- The trial includes half of Meta’s employees, with privacy concerns raised about sensitive data reaching contractors.
- Muse was launched in the U.S. on September 8 and has reached 2.5 million downloads, topping the U.S. App Store.
- Meta’s Muse AI was inspired by the open-source project OpenClaw, with nearly identical configuration files.
- A zero-day vulnerability in Muse could allow attackers to hijack Mac devices, leading Amazon to block purchases via the agent.
Meta tests hybrid human-AI calls for Muse
Meta is beta-testing a 'human concierge' feature for its Muse AI agent, where contractors take over some calls placed through the agent, according to The Next Web. The trial, announced internally last week, was enabled for half of Meta’s employees, who could opt out.
The goal of the test is to refine safety and privacy protections before a broader release. However, some employees have reportedly raised concerns about sensitive user information unintentionally reaching contractors, as Muse forwards requests like appointment bookings or stock checks to businesses and provides transcripts.
Daniel Roberts, a Meta spokesperson, stated that feedback on the trial has been 'overwhelmingly positive,' though specific details about the feedback were not disclosed.
Muse’s rapid adoption and privacy promises
Muse launched in the U.S. on September 8 as an AI agent capable of sending emails, making purchases, and booking travel on behalf of users. According to data from Sensor Tower, it has already reached 2.5 million downloads and recently climbed to the top of the U.S. App Store, outperforming ChatGPT’s launch metrics in comparable areas.
At its launch, Meta emphasized privacy, stating that each Muse agent operates in its own virtual machine. This follows a 2018 experiment with Messenger’s assistant, M, which was discontinued due to low automation levels and reliance on human trainers.
Inspiration from open-source project OpenClaw
Meta’s Muse AI drew inspiration from OpenClaw, an open-source project created by Peter Steinberger, according to TechCrunch. Nat Friedman, head of product at Meta’s Superintelligence Labs (MSL), acknowledged that while Muse was built from scratch, its design was heavily influenced by OpenClaw.
Friedman reportedly purchased hundreds of Mac minis for the MSL team after testing OpenClaw in January. The similarities between Muse and OpenClaw extend to configuration files, including a SOUL.md file that defines the AI’s personality, tone, and behavior. Some files in Muse and OpenClaw share nearly identical content and naming conventions.
Steinberger, OpenClaw’s creator, was hired by OpenAI earlier this year, reportedly due to the project’s success.
Security vulnerability raises concerns
A zero-day vulnerability in Meta’s Muse AI assistant could allow attackers to hijack a user’s Mac, as reported by Mashable. The flaw, disclosed by macOS security expert Patrick Wardle, exploits Muse’s cloud-based transcription feature, enabling attackers to redirect or access sensitive data.
Muse requires extensive permissions on users' devices, making it a potential target for exploitation. Meta designed Muse to run on a secure virtual machine called Muse Secure VM, which the company claims offers 'first-of-its-kind' privacy and security protections.
Amazon has blocked Muse from purchasing products on its e-commerce platform following the vulnerability disclosure. Meta has not yet addressed the reported security flaw.
Background: Meta’s AI experiments
Meta’s approach to blending human and AI assistance is not new. In 2015, the company launched M, a Messenger-based assistant supported by human trainers. The project was shut down in 2018 due to low automation levels and scalability challenges.
Muse’s launch comes as competition in the AI assistant space intensifies, with companies like OpenAI and Snapchat also rolling out advanced AI agents.
What this means
LazyFounders analysis — our interpretation, not reported fact.
Meta’s beta test of a human-AI hybrid for Muse reflects a pragmatic approach to balancing automation with human oversight, especially for complex or sensitive tasks. However, the privacy concerns raised by employees—and the potential for sensitive data to reach contractors—highlight the challenges of scaling such a system without robust safeguards.
The similarities between Muse and OpenClaw also raise questions about innovation versus iteration. While Meta claims Muse was built from scratch, the near-identical configuration files suggest a strategy of leveraging existing open-source work to accelerate development. This may appeal to users seeking proven functionality, but it could also draw criticism from developers who contributed to OpenClaw without direct benefit.
The zero-day vulnerability in Muse is a stark reminder that rapid adoption and ambitious features come with risks. For founders and operators, this underscores the importance of prioritizing security and transparency, especially when dealing with sensitive user data or integrations with third-party platforms. The fact that Amazon blocked Muse from purchasing on its site shows how quickly trust can erode when vulnerabilities emerge—and how costly it can be to regain it.
Key takeaways
- Meta is beta-testing a hybrid human-AI system for its Muse AI agent, blending automated and contractor-supported interactions.
- Privacy risks are a key concern, with employees warning about potential exposure of sensitive user data.
- Muse’s rapid adoption reflects strong market interest, but its similarities to OpenClaw raise questions about originality.
- Security flaws in Muse have led to operational restrictions, such as Amazon’s block on purchases via the agent.
- Meta’s approach mirrors past experiments like Messenger’s M, which was discontinued due to low automation levels.
FAQ
What is Meta’s 'human concierge' feature for Muse?
Meta is testing a feature where contractors take over some calls placed through its Muse AI agent. The goal is to refine safety and privacy protections before a public release.
Why are employees concerned about the Muse trial?
Some Meta employees have warned that sensitive user information could unintentionally reach contractors handling calls, raising privacy risks.
How successful has Muse been so far?
Muse launched on September 8 and has reached 2.5 million downloads, recently topping the U.S. App Store.
What is the connection between Muse and OpenClaw?
Meta’s Muse AI was inspired by OpenClaw, an open-source project. Configuration files and design elements in Muse closely resemble those in OpenClaw.
What security issue has been reported in Muse?
A zero-day vulnerability could allow attackers to hijack a user’s Mac by exploiting Muse’s cloud transcription feature. Amazon has blocked Muse from purchasing on its site as a result.
Has Meta addressed the reported vulnerability?
As of now, Meta has not publicly responded to or resolved the zero-day vulnerability in Muse.
Related on LazyFounders
Sources
- The Next Web · 2026-09-23
Meta is testing human callers behind its Muse AI agent, Reuters reports - TechCrunch · 2026-09-22
Meta admits Muse’s likeness to OpenClaw isn’t a coincidence - Mashable · 2026-09-22
Meta’s Muse reportedly has a shocking one-click vulnerability
This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.


