The Hidden Cost of an AI Assistant That Does It All
By Michael Willms
In September, Meta launched Muse, a personal AI "consumer agent" that can answer your email, book travel, fill out forms, and even make purchases on your behalf. Other tech companies are building similar tools, and I'll admit the pitch is appealing. Who wouldn't want someone else handling the tedious parts of their day?
Unfortunately, upon closer examination, the risks appear to outweigh the benefits, at least for now.
A New York Times reporter recently spent two weeks handing his life over to Muse. His overall assessment was quite positive, and he called it the most useful AI app he has ever used. It tracked his spending, caught and canceled duplicate subscriptions, and even called his dental insurer and waited on hold for him. But to get there, he had to connect Muse to his bank accounts, credit cards, email, and social media.
And that's the catch. These agents are only useful once you connect them to the places your life happens, which means handing over the keys to nearly everything you do online.
Meta says Muse runs in its own secure, isolated environment and never sees your actual passwords or payment details. But within two weeks of launch, a security researcher found a flaw that could let an attacker take control of the assistant, and with it, everything the user had connected. Meta patched the problem within a day, but it showed exactly what's at stake: break into the assistant, and you may be able to break into everything else.
There's a broader problem too. These agents read web pages, emails, and documents as they work, and a bad actor can hide instructions in that content in the hope that the agent will follow them. For example, a scam email could quietly tell the agent to forward your financial statements or make a purchase, and the agent may not be able to tell the difference between your instructions and a stranger's. Meta acknowledges that this kind of attack remains an unsolved problem across the entire AI industry.
Even without an attacker involved, mistakes happen. When an assistant negotiates, shops, or communicates for you, it can misread what you wanted or agree to something you would have pushed back on. Either way, it's your name on the result.
An even bigger concern is what happens when you're no longer in the room. Meta says Muse checks with you before sensitive steps like sending an email or making a purchase, and that's a sensible safeguard. But an approval screen is only as good as the attention you give it, and a lot can happen between check-ins.
There's a quieter cost as well. So much of what makes people good at managing their affairs comes from doing it themselves: negotiating with a vendor, reading the fine print, getting that gut feeling that a deal isn't quite right. Those skills get sharper with use, and I think they fade when you stop using them.
These tools will get better, but for now, using an AI consumer agent is like Matt LaFleur handing the play-calling at Lambeau to someone in the stands. Even if most of the calls are right, a terrible call still ends up on the scoreboard.