Meta Tests ‘Human Concierge’ for Muse AI Amid Privacy and Security Concerns
Meta is testing a 'human concierge' feature for its Muse AI agent, where contractors handle some calls to refine safety and privacy before a broader rollout. While the trial has drawn praise internally, it has also sparked concerns about data privacy—and a separate zero-day vulnerability has raised serious questions about the AI’s security.
Editor, Lazyfounder

Meta is testing a 'human concierge' feature for its Muse AI agent, where contractors handle some calls to refine safety and privacy before a broader rollout. While the trial has drawn praise internally, it has also sparked concerns about data privacy—and a separate zero-day vulnerability has raised serious questions about the AI’s security.
30 SEC SUMMARY
- Meta is testing a 'human concierge' feature for its Muse AI agent, where contractors handle some calls to improve safety and privacy before a public release.
- The trial, enabled for half of Meta’s employees, has sparked privacy concerns about sensitive data reaching contractors.
- Muse has reached 2.5 million downloads since its U.S. launch on September 8 and recently topped the U.S. App Store rankings.
- A zero-day vulnerability in Muse allows attackers to hijack user accounts, prompting Amazon to block the AI from purchasing on its platform.
- Meta released a hotfix for the vulnerability more than 12 hours after its public disclosure but has not addressed design choices like cloud-based transcription.
TABLE OF CONTENTS
- Meta’s ‘Human Concierge’ Test for Muse AI
- Privacy Concerns and Past Precedents
- Inspiration from Open-Source Project OpenClaw
- Security Vulnerability and Industry Reactions
- What This Means for AI Agents
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Meta is internally testing a 'human concierge' feature for its Muse AI agent, with contractors handling some calls to shape safety and privacy protections.
- The feature was enabled for half of Meta’s employees, but some have warned about potential privacy risks involving sensitive data.
- Muse has reached 2.5 million downloads since its U.S. launch and recently topped the App Store rankings, outpacing ChatGPT’s launch metrics.
- A zero-day vulnerability in Muse allows attackers to hijack user accounts, prompting Amazon to block the AI from purchasing on its platform.
- Meta released a hotfix for the vulnerability but has not explained its use of cloud-based transcription instead of macOS’s on-device options.
Meta’s ‘Human Concierge’ Test for Muse AI
Meta is testing a new feature for its Muse AI agent that involves contractors acting as a 'human concierge' for certain calls, according to reporting by The Next Web. The trial aims to refine safety and privacy protections before a broader release.
The feature was enabled for half of Meta’s employees last week, with an opt-out option available. While the test is framed as a way to improve the AI’s performance, some employees have raised concerns about the potential for sensitive user information to unintentionally reach contractors.
Meta spokesperson Daniel Roberts stated that feedback on the trial has been 'overwhelmingly positive' and emphasized that the test is designed to shape protections for users.
Privacy Concerns and Past Precedents
This isn’t Meta’s first foray into human-AI hybrid systems. In 2015, the company tested a Messenger assistant called M, which relied on human 'trainers' to handle complex requests. The project was shut down in 2018 due to low automation levels, a challenge Meta may face again with Muse.
Muse, launched in the U.S. on September 8, is positioned as an AI agent capable of tasks like sending emails, making purchases, and booking travel. Its calling feature forwards requests to businesses for tasks like appointment scheduling or inventory checks, providing users with a transcript afterward.
Despite reaching 2.5 million downloads and topping the U.S. App Store rankings, the integration of human contractors into its workflow has reignited privacy concerns similar to those faced by M.
Inspiration from Open-Source Project OpenClaw
Meta’s Muse AI was heavily inspired by OpenClaw, an open-source project created by Peter Steinberger, according to TechCrunch. Nat Friedman, head of product at Meta’s Superintelligence Labs (MSL), acknowledged the influence but clarified that Muse was built from scratch.
Comparisons between Muse and OpenClaw reveal striking similarities, including identical file names and nearly identical content in configuration files like SOUL.md, which defines an AI agent’s personality and behavior. These matches suggest a strong conceptual and structural overlap.
The success of OpenClaw also led to Steinberger’s hiring by OpenAI earlier this year, underscoring the project’s impact on the AI agent space.
Security Vulnerability and Industry Reactions
Muse has faced significant security scrutiny. A zero-day vulnerability, disclosed by macOS security expert Patrick Wardle, allows attackers to hijack a user’s Mac by exploiting the AI’s extensive permissions. The flaw enables malicious actors to redirect sensitive data—such as transcriptions—to their own servers.
The vulnerability stems from Muse’s use of cloud-based transcription, which Wardle argues could have been handled securely using macOS’s built-in on-device capabilities. Instead, Meta designed Muse to run on a secure virtual machine (VM) called Muse Secure VM, which the company claims offers 'first-of-its-kind privacy, safety, and security protections.'
Wardle demonstrated proof-of-concept attacks that could write malicious files to a user’s disk or take photos without their knowledge. Meta released a hotfix for the vulnerability more than 12 hours after its public disclosure but has not addressed broader questions about its design choices.
Amazon responded to the vulnerability by blocking Muse from purchasing products on its platform, citing violations of its conditions of use. The move reflects growing wariness among tech platforms about integrating AI agents with potential security risks.
What This Means for AI Agents
Meta’s approach to AI agents reflects a broader industry trend of combining automation with human oversight to improve reliability. However, the reliance on contractors introduces privacy risks, particularly when handling sensitive user data.
The rapid adoption of Muse—now the top app on the U.S. App Store—demonstrates strong consumer interest in AI agents. Yet, its security flaws and similarities to open-source projects like OpenClaw highlight the challenges of scaling such tools while maintaining trust and originality.
Cybersecurity concerns, such as the zero-day vulnerability, underscore the importance of robust security architectures for AI products. Meta’s use of cloud-based transcription, despite available on-device alternatives, raises questions about its commitment to user privacy and security.
What this means
LazyFounders analysis — our interpretation, not reported fact.
Meta’s testing of a 'human concierge' for Muse is a pragmatic approach to refining AI agents, but it also reintroduces old challenges. The blend of human oversight and automation can improve functionality, but it risks exposing sensitive data—especially if contractors are involved. For founders, this serves as a reminder that hybrid systems require robust safeguards, not just after launch but during internal testing.
The similarities between Muse and OpenClaw also highlight a common tension in tech: innovation vs. imitation. While building on open-source projects can accelerate development, transparency about inspiration and implementation is critical to maintaining trust. For startups, this is a lesson in balancing speed with originality, especially in crowded markets like AI.
The zero-day vulnerability in Muse is a wake-up call for AI security. Meta’s slow response and reliance on cloud-based transcription—despite macOS offering on-device alternatives—suggest a disconnect between its security promises and execution. Founders should take note: security isn’t just a feature; it’s a core part of product design. Ignoring it can lead to platform restrictions, like Amazon’s block on Muse, and erode user trust.
Key takeaways
- Meta’s Muse AI agent is undergoing internal testing with a 'human concierge' feature to refine safety and privacy protections.
- Privacy concerns have been raised internally about sensitive information being handled by contractors.
- Muse’s rapid adoption—2.5 million downloads and a No. 1 App Store ranking—highlights its popularity but also its security challenges.
- A zero-day vulnerability in Muse exposes users to potential hijacking, raising questions about Meta’s security practices.
- Meta’s reliance on cloud-based transcription, despite macOS offering on-device options, has drawn criticism from cybersecurity experts.
FAQ
What is Meta’s 'human concierge' feature for Muse?
It’s a test feature where contractors handle some calls placed through the Muse AI agent to improve safety and privacy protections before a public release.
Why are employees concerned about the 'human concierge' feature?
Some employees worry that sensitive user information could unintentionally reach contractors, raising privacy risks.
How popular is Meta’s Muse AI agent?
Muse has reached 2.5 million downloads since its U.S. launch on September 8 and recently topped the U.S. App Store rankings.
What is the zero-day vulnerability in Muse?
The vulnerability allows attackers to hijack a user’s Mac by exploiting Muse’s permissions, potentially redirecting sensitive data to malicious servers.
How did Meta respond to the zero-day vulnerability?
Meta released a hotfix more than 12 hours after the vulnerability was publicly disclosed but has not addressed broader questions about its design choices, such as cloud-based transcription.
Why did Amazon block Muse from purchasing on its platform?
Amazon blocked Muse after the zero-day vulnerability was disclosed, citing violations of its conditions of use.
Related on LazyFounders
Sources
- The Next Web · 2026-09-23
Meta is testing human callers behind its Muse AI agent, Reuters reports - TechCrunch · 2026-09-22
Meta admits Muse’s likeness to OpenClaw isn’t a coincidence - Mashable · 2026-09-22
Meta’s Muse reportedly has a shocking one-click vulnerability - WIRED · 2026-09-23
Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


