SACHA PFEIFFER, HOST:
Meta has a vision for the future. It's launched an AI agent that can act like your own personal assistant. It's called Muse.
(SOUNDBITE OF ARCHIVED RECORDING)
ALEXANDR WANG: Just before I came up today, I saw somebody who broke their mother-in-law's favorite china set, then had Muse scour the internet - eBay, vintage sellers in Japan, everybody - to try to find an exact match. Found it, got it delivered - mother-in-law relationship saved.
PFEIFFER: Alexandr Wang is chief AI officer for Meta. The idea is that you can give Muse access to your accounts and apps, and it will start assisting.
JOHN HERRMAN: One of the first ones I tried was just having it do triage on my inbox.
PFEIFFER: Thousands of unready emails - how do I get through? Yeah (laughter).
HERRMAN: Yeah, exactly. It did a pretty good job at pulling together important-seeming things.
PFEIFFER: John Herrman is a tech columnist for New York Magazine. He tried Muse for a couple of weeks, and he found it surprisingly capable.
HERRMAN: These are things that I mostly hadn't missed, but that when Muse sent them to me - you know, like, oh, there's an upcoming movie night at your daughter's school, but there's a rain forecast - would you like help making that decision? That kind of thing is potentially useful.
PFEIFFER: Muse is popular. It shot to the top of Apple's app chart. OpenAI just announced its own competitor called dots. Other companies are expected to follow.
We called Herrman because we wanted to understand what it could look like if these AI assistants go mainstream. He says for one thing, for Muse to work, you have to hand over a lot of data - like, give it access to your email, your bank accounts, your credit cards. And the autonomy that gives the app its power has the potential to backfire.
HERRMAN: This is kind of new territory. There's been plenty of stuff in the news about AI agents behaving in unpredictable ways, even within the AI companies.
PFEIFFER: Sure.
HERRMAN: So we can expect these agents acting on our behalf to behave in all kinds of unexpected ways.
MATT ROBB: It pops up with a message on my phone from Muse, saying, like, hey, Matt, I made a mistake today. I want to apologize for that.
PFEIFFER: Matt Robb does YouTube reviews of consumer tech products. He took Muse for a test run by selling stuff on Facebook Marketplace. He listed a phone and a keyboard, set a minimum price, and put Muse on the case. All seemed well until he got a ping on his phone late Saturday night.
ROBB: And it says so I arranged for a guy to come to your apartment and buy a product. My bad, because I didn't check with you that you were available. And it says turns out the guy got pretty mad because he was standing outside for, like, a long time.
PFEIFFER: Robb says that Muse accepted an offer below his minimum price, confirmed a pickup time and sent the buyer to his address, all without telling Robb.
ROBB: The worst part was Muse actually sent the guy a message saying I'm here. Like, I'm here right now, after the guy sent a photo of my door. You know, it's almost pretending to be me, rather than being like, you know, Matt's not available.
PFEIFFER: He posted about his experience on social media. Then Meta got in touch, and they walked through what happened. Robb says it turns out he'd given Muse permission to send messages with his address, but he had expected it to check with him before sending a stranger to his door. Meta's David Singleton posted, quote, "glad that we were able to confirm together that there was no breach of privacy controls."
ROBB: I agreed for it to always control my marketplace, which it did, right? But I still feel like it is a breach of my privacy not to confirm with me.
PFEIFFER: I talked about Muse with John Herrman, the New York Magazine columnist who's covered Meta for years. We discussed some safety measures that Meta says it's implementing.
Tell me if I understand this correctly. It says it has built security into the tool. It's something called Sentinel. It's a separate AI agent that needs to give Muse permission before it acts. Meta says credentials are stored securely. It's also saying it's offering up what it calls a bug bounty of up to $300,000. It's basically paying hackers who find a vulnerability so Meta can fix it. Does that make you feel more assured?
HERRMAN: I mean, it is good that they are attempting to have, you know, good security practices around Muse. And I don't want to downplay what they're doing here, which is building a system that has all these different angles of attack. It's very porous in a way that is as responsible as possible. They're hiring, you know, industry heavyweights in privacy. However, practically speaking, if you back up a little bit and just consider what you're doing - you know, you are feeding your entire digital life through an app made by Meta.
PFEIFFER: So given all those concerns about security and privacy, what would you, as a tech columnist, recommend to someone who's interested in the promise of this app, but they don't want to end up with someone draining their bank account or extracting private information from their emails?
HERRMAN: I would say it is OK to wait a little bit. Everyone is building these agents. The concept is kind of incomplete right now. You can see some of the ways it might go, but you can also see, very obviously, the many ways that it's still kind of broken. Your life isn't going to be dramatically improved by using Muse now. But soon, I think it's worth understanding that most of the biggest companies in tech are trying to build something similar. So treat it like a research project.
PFEIFFER: Something quite interesting you noted is that some companies benefit from consumer inertia. You know, you may know that you're paying for recurring subscriptions on your credit card, but you can't be bothered to track them down, and companies benefit from that. They get money for services you're not using anymore. But you wrote that some companies have seen their stock price drop because if Muse helps correct that, they may make less money.
HERRMAN: Yeah. There are a couple stories playing out in markets right now that are really interesting and I think hint at much bigger things to come. One is that, yeah, there's a lot of friction out in the world that is basically part of a business model for a different sort of company. I mean, I work in media. It's pretty hard to cancel subscriptions to a lot of publications now.
PFEIFFER: They make it very difficult. Yes.
HERRMAN: Yeah. And that's actually the kind of thing that Muse, and tools like Muse, are good at. You can extend that to all sorts of different things. Like, oh, you know, make sure I'm not paying too much for my car insurance. Let's check in on that phone bill. That kind of thing, I think, would really hurt some companies' bottom lines. Amazon, for example, was approached by Meta, which asked, can our tool buy things on our users' behalf? And Amazon was like, no. We're not doing that. In fact, Muse is blocked. Do not even try to send your customers'...
PFEIFFER: Yeah. I think you wrote that...
HERRMAN: ...Agents our way.
PFEIFFER: ...Amazon says it violates the conditions of use that everybody, when they check the fine print, has agreed to.
HERRMAN: Yes. They have taken an aggressive stance toward tools like this. Earlier this year, they sued a company called Perplexity that was - it's an AI browser that has some similar kinds of features. And they went so far in court as to liken this to hacking. But it's early days. Muse is popular as these things go, but it's minuscule. I mean, no one really uses it yet. If you have a million people playing around with this kind of thing, you might learn something about your future business model, and also, your investors might get a little spooked or excited, depending. But if you have 500 million people using a tool like this, then everyone else in the world on the other side of this army of agents has to recalculate what they're doing and has to strategize, 'cause it's a whole different thing.
PFEIFFER: That is John Herrman. He's a tech columnist for New York Magazine. John, thank you.
HERRMAN: Thanks for having me on.
PFEIFFER: NPR reached out to Meta for comment. A spokesperson sent an email that read, in part, quote, "we take privacy and security extremely seriously and have built Muse accordingly. Muse has no visibility into people's passwords or payment methods. Any credentials a person shares go into secure storage so Muse can use them without seeing them, including passwords a person types into the browser themselves. People can change access or disconnect a service whenever they want."
(SOUNDBITE OF CIEL'S "RAIN DANCE") Transcript provided by NPR, Copyright NPR.
NPR transcripts are created on a rush deadline by an NPR contractor. This text may not be in its final form and may be updated or revised in the future. Accuracy and availability may vary. The authoritative record of NPR’s programming is the audio record.