> ## Content Index
> Fetch the complete content index at: https://macanorak.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# A Wolf in Terrycloth Clothing
- URL: https://macanorak.com/a-wolf-in-terrycloth-clothing/
- Published: 2026-10-03T12:10:01.000Z
- Updated: 2026-10-05T16:49:33.000Z
- Description: Muse, Dots and the new generation of always-on agents are changing what it means to give software access to your life.
- Author: MacAnorak
- Tags: Field Notes, Beyond the Garden

I have an aversion to anything related to Meta, formerly known as Facebook, but given this site covers Apple and wider tech, I probably have to get down in the dirt and talk about Muse, whether or not I really want to.

According to the Cambridge English Dictionary, the word “muse” means: *“to think about something carefully and for a long time”.*

It's also the name of Meta’s new AI Agent.

When Meta [introduced Muse](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/?ref=macanorak.com) on the 8th of September 2026, they called it the world's first personal AI agent “*built for everyone*” (except me, it seems, as I will never use it, and this is a hill I’m willing to die on).

Meta tells us that Muse doesn't just answer questions, it actually does work for you. Yep, Muse is an *AI agent*. It helps you stay on top of things. It assists with tasks and projects. It turns your long-term goals into action plans! Muse will learn from your conversations; it will reflect on what matters to you, the user. And it will become better at what it does.

Meta tells us that Muse was built from the ground up to be safe, secure, private — yada yada yada. To back this up, they tell us it runs on Muse Secure VM, a dedicated virtual machine that houses both the agent and the person's data, and works on a user’s behalf across the apps they use daily. Meta says a second agent, kept apart from Muse, approves anything Muse does that reaches the internet, and asks the user when needed (more on this later).

What does Meta mean when they say Muse is “*built for everyone*” in a way that other AI agents aren't? Well, Meta claims there's no learning curve to use Muse — anybody can use it out of the box, you don't need any technical experience at all.

And because Meta is a brand that in many respects is synonymous with cynicism, Muse features a [customisable character](https://fortune.com/2026/10/02/meta-openai-ai-agent-mascots-jolly-dots-trust/?ref=macanorak.com) to represent the AI agent. This is called “Jolly” and it looks a bit like what you'd imagine a newborn Wookie might look like if all the fur on its face had been chewed off (or is yet to grow). It also looks like a harmless children's cuddly toy. Justin Joseph, a Boston University PR professor, says a cute character may lead consumers to infer an agent is "*approachable, safe, trustworthy, easy to use*”.

I assume Muse’s mascot is called “Jolly” because it's happy — happy to serve you, and happy that it's inserted itself into your life, because let's be honest, “Jolly” is likely a way to seduce hapless individuals into using Meta's product. A Pied-Piper of sorts. It looks cute and harmless. Had Meta designed it to look like a Trojan horse, or a ‘wolf in Terrycloth clothing’, it would have given the game away.

Talking of seduction, Muse also has its own logo, which no doubt Meta paid an exorbitant amount for somebody to design. It’s a cleverly scribbled ‘M’, that also happens to look like a snake. Make of that what you will, but a serpent offering you something tempting does have a certain history.

![Muse Logo.jpeg](https://macanorak.com/content/images/2026/10/Muse-Logo.jpeg)

Jolly has been a hit. Muse has reportedly passed [3 million weekly users](https://thenextweb.com/news/meta-muse-3-million-weekly-users-information?ref=macanorak.com) and 5 million downloads. It's said that more than 1 million people prompt Meta's Muse every day. How could Muse not be a success? Look how cute Jolly looks!

But cute or otherwise, Jolly is causing lots of trouble. The agent can request broad and extensive access to the user’s personal data — Messages, financial information, precise location, health information, browsing history, contacts, even “Full Disk Access” on a Mac (again, more on that later). Interactions with Muse are used to train its AI models by default — you have to ‘opt out’ under settings (although to be fair this is also the same with ChatGPT, but that’s hardly saying much).

VPN company [Surfshark](https://surfshark.com/research/chart/meta-muse-ai-chatbots?ref=macanorak.com) evaluated how Muse compared with other widely used AI chatbots in terms of data collection. It found that Muse is collecting, or attempting to collect, 31 out of 35 types of data. Incidentally, Meta AI, a separate Meta product, collects 33 of 35 types of data, making it the worst in Surfshark’s analysis, with Muse coming second. Well done, Meta — that's Gold and Silver medals for you.

Then, it emerged that a technology reviewer from Toronto called Matt Robb had [let Muse handle](https://x.com/MattRobbt/status/2104798102037074212?ref=macanorak.com) a Facebook marketplace listing for him. Muse happily shared his home address with a buyer who subsequently [turned up at his apartment](https://www.fastcompany.com/91614998/metas-new-ai-agent-gave-a-stranger-a-users-home-address-then-he-showed-up?ref=macanorak.com). After going through the logs with Meta, Robb explained that when Muse asked for permission, he'd chosen "*allow always*” rather than "*allow one time*", assuming it would still send him approvals before accepting offers. Muse didn't. What Robb subsequently discovered was that he’d given permission for Muse to send messages on his behalf going forward, using a template built from the details he'd given it, including his home address.

Meta's own [launch post](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/?ref=macanorak.com) says Muse checks with the user before taking sensitive actions. A Meta Superintelligence Labs[\[1\]](#fn1) executive, David Singleton, offered to investigate, although he also said that earlier similar reports found Muse was “[following direct instructions and correctly asked for permission](https://www.dexerto.com/youtube/meta-responds-after-muse-ai-gave-stranger-youtubers-home-address-on-facebook-marketplace-3414057/?ref=macanorak.com)”. In other words, Meta’s explanation seems to be that the user said “yes”. This is true as far as it goes. But the "yes" Robb gave he likely thought meant "*keep going, but check with me before accepting anything*”, which turned out to mean: *"message strangers with my address in them”.*

This is the glorious future we are now living in.

[Jason Aten](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202?ref=macanorak.com), a columnist at Inc., reported that his Muse agent synced his Apple Messages database up to row 187,462 without his consent, even though he says “Full Disk Access” was turned off. Meta's VP of Communications, Andy Stone, disputed this, saying the Messages integration on Mac is "*entirely opt-in*" and needs both Full Disk Access and Muse's own Messages connector. David Singleton from Meta Superintelligence Labs added that macOS protections can't be bypassed even if Muse had a bug. Aten maintains Full Disk Access was off. This is a live, unresolved dispute between a journalist and the company. Take your pick of who to believe.

Then, a few days ago (September 29th) OpenAI introduced [dots](https://openai.com/index/introducing-dots/?ref=macanorak.com), which are described as “*remarkably capable, always-on agents built to handle everything*”. OpenAI assures us that *“Security safeguards built into dots help defend against malicious instructions and monitor for potentially harmful behavior”*. Dots are currently rolling out to selected Pro, Business Premium and Enterprise users in eligible markets, while Muse has a free tier and millions of users.

Like Meta, OpenAI have also designed these agents to look cute and colourful — blob-like characters with eyes that can be customised with different accessories and appearances.

![Dots.png](https://macanorak.com/content/images/2026/10/Dots.png)

They resemble something out of a children's TV show, and a bad one at that. They also remind me of a knock-off version of [Mr Men](https://mrmen.com/?ref=macanorak.com) (a fantastic series of children’s books by the late English author Roger Hargreaves), for anyone familiar with that reference.

![Mr Men.jpg.webp](https://macanorak.com/content/images/2026/10/Mr-Men.jpg.webp)

*Image: MrMen.com*

M.G. Siegler of [Spyglass](https://spyglass.org/openai-dots-chatgpt-ai-assistant/?ref=macanorak.com), who is rather more relaxed about all this cuteness than I am, feels that *“cute AI is better than say, ‘we’re going to end the world’ AI”*, and Siegler is broadly positive about Muse. John Gruber of Daring Fireball observes that [Muse looks cute, but looks are deceiving](https://daringfireball.net/linked/2026/09/25/aten-muse?ref=macanorak.com) and wonders if *“people realise how powerful — and thus dangerous — Muse is, especially if it's running on your Mac.”*

In what looks like a direct response to Muse, Dots, et al., Apple announced on its [developer news website](https://developer.apple.com/news/?id=p6zjojqw&ref=macanorak.com) that it will introduce additional controls for the "Full Disk Access" setting on macOS due to new risks posed by AI agents. Apple say:

> *Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.*

> *Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.*[\[2\]](#fn2)

Elsewhere, Amazon [blocked Muse](https://www.geekwire.com/2026/amazon-blocks-metas-muse-ai-assistant-in-new-standoff-over-agentic-shopping/?ref=macanorak.com) from shopping on Amazon.com entirely. According to Amazon, Meta never told them Muse would be accessing their store and that the agent “*appears to capture and store customer credentials*." The agent reportedly doesn't identify itself as an AI agent while it's browsing (the more I think about it, maybe 'Jolly' does seem more like a person wearing a terrycloth suit to avoid detection). Users trying to shop on Amazon through Muse now get a popup telling them access "*violates Amazon's Conditions of Use*." Meta disputes the allegations: they say Muse "*has no visibility into people's passwords or payment methods*," and that login details go into a separate secure store the agent merely borrows access to.[\[3\]](#fn3) Take your pick of who to believe.

It seems like the AI industry has invented agents before properly working out the social and technical rules governing them. I said at the beginning of this article that the word “muse” means *“to think about something carefully and for a long time.”* It's hard to know whether Meta really did think about Muse carefully and for a long time, or not. If it did, that means its dubious behaviour may be intended and deliberate. If it didn't, then it's just a sloppy product. Again, take your pick of which explanation you prefer.

After all of this, I think I need to go and take a shower.

---

1. Created in June 2025 by CEO Mark Zuckerberg to pursue advanced AI and "personal superintelligence”. Incidentally, Trump [recently ordered](https://www.theguardian.com/us-news/2026/sep/29/trump-ai-deal-tech-ceos-superintelligence?ref=macanorak.com) the US executive branch to replace “artificial intelligence” and “AI” with “Super Intelligence” and “SI” in its official communications. [↩︎](#fnref1)
2. [John Voorhees](https://www.macstories.net/linked/apple-announces-plan-to-impose-new-full-disk-access-controls-on-mac-developers/?ref=macanorak.com) at MacStories points out that the changes Apple appear to be gearing up for could impact many other, more benign apps - Alfred, Hazel and the like. [↩︎](#fnref2)
3. To be fair — and I do try to be fair, even when writing about Meta makes that genuinely difficult — Amazon did more or less the same thing to *[Perplexity's shopping agent](https://tech.yahoo.com/ai/perplexity-ai/articles/amazon-sends-cease-desist-perplexity-225532124.html?ref=macanorak.com)*, Comet, when it was disguising itself as a human browser, acting without disclosure. Perplexity's response was to call it "*legal bluster*" and “*completely unfounded*”. So this isn't just a Meta problem — it might be a "*we built agents that shop for you before working out how they're supposed to behave*" problem, industry-wide. That's not especially reassuring either. [↩︎](#fnref3)