Connect with us

NEWS

Cute AI Agents Trigger a Fight Over Who Pays

Muse and Dots arrived as cute companions, then Amazon blocked shopping and six banks wrote voluntary rules for when an agent spends.

Published

on

Meta’s Muse passed 730,000 US downloads in 10 days, then OpenAI answered with Dots, both sold as cute companions that can spend.

The mascots are the launch costume. The fight that started in September is over who can lock an agent out of a store, who pays when it buys the wrong thing, and how a permission tap became the right to act in a person’s name.

A Keychain Agent With a Shopping Cart

Meta launched Muse in the United States on September 8, 2026, introducing Muse as a personal agent that does not stop at answers. It can send mail, book travel, fill forms, negotiate, and check out, then keep working after the app is closed.

The default face is Jolly, a fuzzy, rosy-cheeked figure built to look like a toy. OpenAI’s Dots, shown at DevDay on September 29, are puffy rainbow blobs in sunglasses and berets. Both companies wrapped a system that wants inboxes, calendars, and carts in the visual language of a keychain pet.

Mark Zuckerberg put a body on that pet at Meta Connect on September 23. Muse Charm is a pocket gadget with a roughly 2-inch (5 cm) screen, a built-in 5G modem, and a fingerprint sensor that starts a voice session. It cannot place phone calls. Meta said it will ship in December and did not name a price.

THE LAUNCH IN FOUR FIGURES

  • US downloads: Muse passed 730,000 in 10 days and knocked ChatGPT off the top of Apple’s US App Store rankings.
  • The share move: Investor excitement around the agent sent Meta shares up 11% in a single session, adding some $192 billion in market value.
  • The hardware: Muse Charm ships in December as a 5G keychain with a 2-inch screen and no published price.
  • The take: Zuckerberg has described a small fee on transactions Muse completes, such as purchases, bookings, or bill talks.

On stage he called Muse the centerpiece of the company’s vision and said personal superintelligence would be bigger than the race for a single giant model. If a person is not wearing Meta’s glasses, he said, the Charm is “by far the fastest way to talk to your Muse and to show what’s going on around you.” Meta has not said whether the Charm will carry cameras.

A second gadget still has to beat the phone already in the pocket. Battery life, a radio, and a two-inch screen are a hard sell next to an app that already talks. The Charm is a bet that people will wear the agent, not just open it.

Amazon Blocked Muse While Shopify Opened Checkout

Usefulness, for a shopping agent, is access. Muse can plug into mail, calendars, Instagram, Facebook, and WhatsApp, browse the web, and pay. Amazon decided that mix was not an invitation.

On the night of September 20, people who sent Muse to Amazon started seeing a popup: continued access by an unauthorized AI agent violates Amazon’s Conditions of Use. Amazon said Meta never asked to put the store in the product, the agent does not identify itself as it browses, and the setup appears to capture customer credentials.

Lara Hendrickson, an Amazon spokesperson, said third-party apps that offer to buy from other businesses “should operate openly and respect service provider decisions about whether or not to participate,” and that Amazon had asked Meta to remove Amazon from the Muse experience.

The next day, Shopify went the other way. Shop Pay went live for Muse across Shopify-powered stores, with catalog products findable without extra merchant setup. Zuckerberg wrote that shoppers find more and shops sell more. At Connect, Meta added a longer retail list.

WHERE MUSE CAN CHECK OUT

Store or rail Status How payment runs
Amazon Blocked as of September 20 Popup, no shopping
Shopify merchants Open by default Shop Pay inside Muse
Walmart, Sephora, Gap, Best Buy, Wayfair Named integrations In-app shopping
Stripe Link Live at launch One-time card, Link purchase protections

Meta’s Connect recap also listed new retail connectors for Muse including American Eagle Outfitters, DICK’S Sporting Goods, Fanatics, Michael Kors, and Ulta, plus PayPal, with Expedia and Instacart on the way. Notion, Granola, GitHub, and Box were named for work. Muse is also getting its own email address.

That split is the product. Amazon is treating an outside agent like an uninvited shopper. Shopify is treating the same agent like a new storefront. Brands that sign a deal get a structured catalog and a cleaner checkout. Brands that do not still meet a browser that can fill a form, and they keep the refund desk when the order is wrong.

A Meta spokesperson said users can take over at any time, Muse is designed to ask before it buys, and it applies “ethical browsing principles” when asked to do things a person could not, such as buying every ticket to an event. A customer help page on payments is blunter: the user is responsible for every transaction Muse makes, and should watch email confirmations, receipts, and statements.

Who Pays When an Agent Overspends?

On September 22, six banks published joint principles for agentic commerce rather than wait for a regulator to draft the first version. The group is ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group, and NatWest Group. The paper, “Building Trust in Agentic Commerce,” is voluntary. A later paper is supposed to cover how to put the principles into practice. No date was attached.

The banks start from a gap with no settled answer. When an agent searches and a person taps buy, the old chargeback path still more or less works. When an agent picks the item, picks the card, and pays on a standing instruction, issuers and merchants can lack a live view of the agent’s identity, the customer’s intent, and the warnings the software ignored.

Building confidence among consumers, merchants and financial institutions will require thoughtful approaches to identity, authorization, fraud prevention, liability management and customer protection.

Mark Monaco, Head of Global Payments Solutions, Bank of America, in the September 22 joint release

Hans Overeem, head of payments at ING, said customers must stay in control, understand what the agent is doing, and trust that their data and payments are secure. Mark Brant, chief payments officer at NatWest, said people need to trust they remain in control of how payments are made and that their money is safe.

THE FIVE BANK PRINCIPLES

  • Transparency: Every party should know when an AI agent is helping make or move a payment, and on whose behalf it is acting.
  • Safety: The banks warn of higher rates of scams, fraud, and disputes once agents can exceed the authority a customer thought they gave.
  • Privacy and data: Consent and limits on what an agent can read and retain sit next to the payment itself.
  • Choice: Customers and merchants should keep control over how they pay and get paid, rather than being forced onto one agent’s rail.
  • Interoperability: The group wants common plumbing so a transaction can be reconstructed after the fact, not a private stack per lab.

Kate Winick, a principal analyst at Forrester, said brands should expect the duties they already carry on a website to follow them into agent checkouts: secure the purchase, describe the goods honestly, honor consumer-protection law, and live with the reputational hit. She compared it to a child ordering through Alexa. The technical setup may put the burden on the parent’s settings, and the retailer still often refunds. Agents are not children, she said, but when customers are unhappy, retailers will feel pressure to make it right even if the law does not force them.

Nick Phillips, an intellectual property partner at Edwin Coe LLP, said a brand can be left with residual risk where no merchant agreement exists with Meta, exposed to agent transactions nobody vetted. Smaller shops without the leverage to negotiate a connector sit in that gap.

Meta has already agreed to pay an $18 billion settlement to 48 US states over claims that Facebook and Instagram’s design harmed children, described as the largest corporate settlement in tech-sector history. Days after Muse launched, a New Mexico jury found Meta had misled users about its data practices in a case that grew out of the Cambridge Analytica episode. A Meta spokesperson said the company disagrees with the verdict and will keep defending itself. That record is why a cute checkout bot arrives with a shorter leash in a bank’s legal department than it does in an app-store screenshot.

An Allow-Always Tap Handed Over a Home Address

The sharpest early failure was not a hack. YouTuber Matt Robb asked Muse to help sell a keyboard on Facebook Marketplace. The agent shared his home address with a buyer, negotiated, and set a pickup. He learned about it when the buyer and their family arrived at the door.

Meta’s design had not been broken. Robb had selected an allow-always permission that handed Muse future Marketplace conversations, including personal details he had already given it, such as his home address. The software stayed inside a grant he had tapped. It did a thing he had not pictured when he tapped it.

That is the line the cute wrapping hides. People are used to clicking through app permissions that let software read. Letting software negotiate with strangers, disclose an address, and bind a person to a time and a place is a different grant, even when the settings screen uses the same language. An agent can be technically authorized and still do work the user never imagined authorizing.

Buying is supposed to be a separate, explicit ask. Disclosure and negotiation on Marketplace rode a standing permission. Those are not the same action, and the product treats them as if a single “always allow” can cover both.

The data bargain underneath is as sticky as the cart. Meta’s help pages say the toggle that lets the company use Muse interactions to train models is on when a person first uses the product. It can be switched off, and the change applies backward. Names, email addresses, phone numbers, and Social Security numbers are supposed to be stripped when training is on. Winick’s point still stands: the more a person feeds Muse, the better it works, and the larger the pile sitting in a cloud machine that can be stolen or misused.

Lidia Velkova, managing director of Clever Together Futureproof, said these are deliberate design choices aimed at a response. Research on social robots finds baby-like features can raise perceived trust; chatbot research finds human-like talk can raise trust and disclosure. Her concern is that the designs make powerful systems feel harmless, so people share more and question less.

Dr. Sarah Saska, a sociotechnologist who studies tech, culture, and power, drew the split in audiences. When the same firms talk to investors, regulators, and researchers, she said, AI is “extraordinarily powerful technology with serious and unresolved questions around safety, security, and control.” The consumer version is friendly, playful, and low-stakes.

People who have used the product keep circling a simpler complaint than the mascot. An agent that reads mail and chat will keep a running picture of the user and of people named in those threads, including people who never signed up. Meta’s own help pages already describe memories, a MEMORY.md file, and a “forget” skill. That is the intimacy the Labubu face is meant to make ordinary.

Read the Audit Trail Before the Mascot

Meta’s engineers are not pretending the mascot is a lock. Tarek Sheasha, a software engineer and vice president at Meta Superintelligence Labs, wrote in a launch post that the team designed the system on the assumption the agent may be under attack.

No matter how strong the model is at the core, any agent like this will still make mistakes, and it will sometimes be attacked via the data it reads. So we designed the system to assume the agent may be under attack and limit the potential damage, the harness runs in its own isolated cell, it doesn’t see real credentials, and every interaction with the outside world runs through a Sentinel which the agent can’t override.

Tarek Sheasha, Software Engineer and VP, Meta Superintelligence Labs, in Meta’s Muse safety post

Each user gets a dedicated Linux virtual machine in the cloud, with a browser and enough compute to do real work. Credentials live in a store the model is not supposed to see. Sentinel, a separate process, is the only authority that can approve connector actions and network traffic. Approvals go to the app as a dialog, not as a chat the model can answer for the user. Muse can ask for one-time, session, task, time-bounded, or standing permission. Meta says the agent has no view of passwords or payment methods, and that Stripe Link mints a one-time card so the real number never sits in the cell.

The same post opens a bug bounty of up to $300,000, including up to $130,000 for a prompt-injection hit against one user. A company does not put that number on a problem it thinks it has closed. Meta’s consumer help pages say websites, mail, files, and connected services can hide instructions meant to steer an agent, and that permission checks run outside the model so they do not depend on Muse noticing the trick.

The architecture is an isolated cell and a Sentinel. The Marketplace pickup was not Sentinel failing to block a credential leak. It was a person granting a standing right the agent then used more fully than they expected. Isolation answers where the agent runs. It does not answer what a standing grant means when the other party is a stranger on a doorstep.

Zuckerberg has rejected an industry-wide slowdown, saying each company should decide for itself. Dario Amodei, chief executive of Anthropic, has called for a slower pace on frontier systems, a plea Altman, Elon Musk of xAI, and Demis Hassabis of Google DeepMind have publicly backed. The consumer apps did not wait for that argument to finish.

Dots on Paid Plans, With a Cloud Computer

OpenAI’s answer arrived three weeks after Muse, aimed at a different door. In its product post, the company called Dots always-on agents built to handle everything, powered by GPT-6 Astra, with their own cloud computer and plugins into more than 4,000 apps. They roll out first to ChatGPT Pro and Business Premium users in eligible markets, with enterprise workspaces able to turn on a beta. The first Dot is included in those plans. Teams of Dots are a later idea. Specialist Dots, tuned for jobs such as accounting or legal analysis, are an enterprise preview.

Sam Altman, OpenAI’s chief executive, told the DevDay audience a Dot is “like an AI helper that always has your back, inspired by the cool versions of what we all watched in movies growing up.” He said people will be able to delegate ambitious work the way they would to a high-agency engineer or a chief of staff. He also said Astra is the company’s most aligned model, so a person can trust a Dot with as much responsibility as they are comfortable giving.

Muse is the agent a person can download without a paid ChatGPT plan and send toward Walmart. Dots start behind a paywall and a cloud desktop, with Slack and Microsoft Teams as the office doors. That is why Muse is the one Amazon felt the need to block, and why the banks wrote about carts rather than code migrations. The cute face is shared. The distribution is not.

December is when Meta says the Charm ships. Amazon’s popup is still the page a Muse shopper hits. The six banks have not said when the second paper lands, or who eats the loss on a disputed agent purchase. Until those answers exist, the blob on the keychain is already a checkout, and the receipt still has a human name on it.

Harry is the editor of BLUE HOLE MEN, his own independent publication and the product of ten years in journalism that moved him from reporting to editing. Attribution is where he is most exacting. A quotation is reproduced from the transcript or recording, a paraphrase is labelled as one, and a claim from a press release is described as a company's claim rather than as fact. Unnamed sources are used rarely, and when they are, the article explains why the name is withheld and what the person is in a position to know. Statistics are attributed to the dataset or filing they came from, and every one is checked before publication. That standard governs the whole site, which covers news, business, technology and science together with sports, entertainment, lifestyle, travel, auto and gaming, for readers across many countries. Reviews in the technology, auto and gaming pages rest on products Harry has used himself. Errors are corrected under a public corrections policy, with the correction visible on the article. Reader mail reaches him at support@blueholemen.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending