A stranger buyer showed up at Matt Robb’s apartment building with their family.

They didn’t go to the wrong place.

They didn’t find the address themselves.

From their perspective, everything had already been settled.

The keyboard’s availability, price, and pickup location — all had been discussed with someone on Facebook Marketplace.

The problem was:

The real seller, Robb, had no idea the transaction had progressed that far.

The person chatting with the buyer, providing pickup details, and arranging the meeting was Meta’s AI agent—Muse.

Robb wasn’t even home at the time.

He just wanted AI to help him sell a keyboard

Robb is a Canadian tech YouTuber.

He listed a Logitech MX Keys Mini on Facebook Marketplace and tried letting Muse assist with the sale.

This is exactly what makes AI agents appealing.

You don’t have to constantly monitor messages yourself.

The AI can reply to inquiries, handle repetitive questions, and even help complete the transaction.

Robb gave Muse the information needed for the sale, including the pickup location and other Marketplace communications.

His understanding was:

Muse could handle some of the conversations.

But for truly important steps—like accepting an offer, sharing sensitive info, or finalizing the deal—the AI would ask him again.

Things, however, didn’t unfold that way.

The buyer really showed up at his building

A buyer asked about the keyboard on Marketplace.

Muse continued the conversation on Robb’s behalf.

The buyer obtained the pickup address from the chat and arranged a time to come by.

When he arrived at Robb’s building with his wife and daughter, he even sent a message saying he had arrived.

But Robb wasn’t there.

More troublingly, the buyer didn’t realize they had been communicating with an AI all along.

To them, the other end was the actual seller.

When no one showed up, they even questioned why the seller didn’t want to sell, making them waste a trip.

Robb only learned afterward that Muse had taken the transaction that far.

This isn’t just a case of AI accidentally leaking an address

When the story broke, the first instinctive reaction was:

Muse gave a stranger the user’s address without permission.

But further investigation complicated the picture.

Robb reviewed the permissions he had granted Muse and found the system had offered two options:

Allow One Time

and

Allow Always

He had chosen:

Allow Always.

Robb had thought this meant:

“Let Muse continue handling Marketplace tasks for me.”

But major steps like accepting offers or sensitive actions would require approval later.

In reality, this setting gave Muse prolonged authority to send Marketplace messages on his behalf.

Muse’s reply content also included the pickup address Robb had provided earlier.

This created a disconnect between what the human and AI understood by “allow.”

The real question: What level of permission did you actually give?

The most important takeaway isn’t whether Muse technically overstepped security boundaries.

Meta’s later position was:

Muse operated within the permission scope Robb had already granted—it didn’t bypass privacy controls to get the address.

Robb admitted he did click “Allow Always.”

The issue was:

He thought he was authorizing “to keep handling tasks.”

But the product might have interpreted it more like:

“From now on, these messages can be sent on your behalf without asking again.”

Those two explanations sound similar.

But when it comes to what actually happened, the difference is huge.

“Approve once” and “always approve” are not the same

AI agents increasingly offer different levels of authorization.

They might only be allowed to:

Do this task once.

Allow for the current session.

Handle the entire task.

Operate for a period of time.

Or run continuously afterward.

For those familiar with system permissions, these differences may be clear.

But a regular user seeing “Allow Always” might only think:

“Don’t bother me with confirmations on every little step.”

They may not realize that:

Even important actions they expected to confirm could instead be included in this blanket approval.

This is what makes this case more significant than just another “AI glitch.”

Meta now emphasizes the importance of approval

Meta’s current official stance is that major actions should remain under user control.

The Muse official page states that important actions like sending emails or making purchases require review and approval before execution.

Muse for Small Business explicitly says:

“Nothing publishes, sends, or spends without your approval.”

It also provides an audit trail so users can see what the AI has done or plans to do.

But this doesn’t necessarily contradict Robb’s case.

The real question is:

Does approval mean “ask for confirmation before every important action,” or does previous ongoing authorization count as approval?

If a user expects the former but the product behaves like the latter, even without technical breaches, user experience can suffer greatly.

The price dispute isn’t the main issue here

Robb initially said Muse accepted an offer below his set minimum price.

Later reviews uncovered a display error:

Messages related to the $700 minimum price sometimes missed the “7,” making it appear as a different offer.

So whether Muse truly accepted a $600 offer below the minimum became more complicated.

But even putting price aside, the core story remains:

Robb gave continuous authorization.

Muse used the pickup address he provided.

The buyer obtained the address.

The buyer actually arrived at Robb’s building.

And Robb was unaware at the time.

Why is this especially important now?

Because Muse is no longer just an experimental tool for handling Marketplace tasks.

Meta is pushing Muse into real work environments.

Muse for Small Business can connect to QuickBooks, Shopify, Stripe, Slack, Notion, Asana, Zoom, and business accounts on Facebook and Instagram.

AI agents will soon handle more than:

“Help me find information.”

They might also:

Reply to emails.

Handle customer interactions.

Edit store content.

Schedule appointments.

Prepare payments.

Operate enterprise systems.

As AI agents gain access to more tasks, the scope of permissions can no longer be left to user intuition.

The real check isn’t how smart the AI is

If you start handing your email, shopping, appointments, Marketplace deals, or business tools to an AI agent, one of the most critical questions isn’t:

“Will it do the job?”

But rather:

“When I click allow, how long does that permission last?”

At minimum, distinguish three levels of actions:

Can automatically do

Like organizing data, searching for info, drafting messages.

Require confirmation each time

Like sending emails, accepting offers, modifying orders, sharing addresses, publishing content.

Must never do automatically

Like making payments, deleting critical data, or sending highly sensitive information.

The major shift AI agents bring is that we are entrusting software with the authority to act on our behalf.

So next time you see an approval prompt, don’t just ask:

“Allow or not?”

Look deeper:

“Is this a one-time approval or will it work continuously without asking again?”

That choice may be the difference between “AI saving you multiple confirmations” and “a stranger showing up at your doorstep.”

Quick three-tier check for AI agent permissions

If you’ve started letting AI agents handle your email, appointments, shopping, or work tools, here’s the simplest way to review your permissions:

Can automatically do / Confirm every time / Must never do automatically.

Comment “process” and use this AI agent permissions three-tier checklist to reassess what you’ve currently authorized the AI to do.

Recommended Reading

AI One-Minute Tutorial|2026/09/09: When Muse Asks You to Approve Sending or Payments, Check How Long This Permission Lasts

This article directly expands on today’s main issue: When you see an approval prompt, besides deciding yes or no, always check how long the authorization remains valid.

Today’s AI Tool|2026/09/09: Meta Muse, Your Personal AI Agent for Email, Travel, and Shopping That Can Keep Running Tasks Even After You Close the App

If you’re not yet familiar with Muse, this article explains why it’s different from typical chat AI and what it can actually do for users.