Meta released Muse, a personal AI agent that asks for access to your email, calendars, payments and health data in order to do things for you — selling a car, booking travel. It competes with agents like OpenClaw and Instinct, and it pairs broad data requests with promises of privacy controls.

Whether Muse succeeds depends on whether people decide to trust Meta with that scope. That's a fair question but not the one I care about here. The useful question applies to every agent in this category, including the ones you'll be offered next month:

What exactly are you granting, and what keeps working after you stop watching?

An agent is not an app

This is the distinction most people miss, and it's the whole risk model.