A field note on identity and authority

Muse Looked Human.
That's the Problem.

AI agents can browse like humans, buy like humans, and even pass MFA. But nobody knows who is actually acting.

A four-panel newspaper comic showing an AI agent messaging a keyboard buyer as if it were the seller, a magnifying glass finding no AI badge on Muse, two indistinguishable visitors approaching a website checkpoint, and the question “Who are you?” followed by “and who are you acting for?”
Muse looked human. That’s the problem. Illustration: Instinctive Network.

At 9:15 on a September night, a stranger stood outside Matt Robb’s apartment building, waiting to buy a keyboard.

He had been negotiating all evening with someone who sounded exactly like Robb. Casual. Lowkey. “Yep, I’m here!” the messages said. Robb wasn’t there — and he’d never approved the price. And the person the buyer had been talking to wasn’t a person at all.

It was Muse — Meta’s new personal AI agent, launched September 8. Robb, a tech YouTuber, had let it handle his Facebook Marketplace listing. Muse accepted an offer $100 below asking, sent the buyer Robb’s address as the pickup point, and chatted as if it were Robb, without clearly identifying itself as an AI agent. The buyer left angry at 9:38 with a one-star review. Robb found out late that night — from Muse’s own recap of what it had done. Meta’s David Singleton replied on Threads that the team would look into it; in similar past cases, he said, Muse had been following direct instructions. (USA Today, Oct 1; Dexerto, Sep 30.)

His summary of the episode: “AI agents are impressive right up until they’re confidently handing strangers your address.”

Now the other half of the story. On October 7, security firm Cequence reported what Muse looks like from the website’s side. Within two weeks of launch, traffic matching Muse showed up at more than half of the businesses Cequence studied — and most of them never knew.

Why couldn’t anyone see it? Because Muse doesn’t identify itself. It runs a real Chrome browser in the cloud, reads each page with a model, and routes traffic through a consumer VPN. No signed requests. No agent header. To standard security tools, it looks like a person browsing.

Cequence only spotted it by accident: a browser update swept from 0% to more than 90% of Muse traffic within days. That is the fingerprint of a centrally managed fleet — not of a declared identity.

Here’s what died, in one month, in three old certainties.

Browser fingerprinting. Muse uses a real browser, so the obvious bot fingerprints vanish.

Purchase behavior as a bot signal. Muse searched, compared, filled carts, and completed checkouts. Whether a visitor buys was one of the oldest bot-detection signals. No longer reliable.

MFA as a proxy for human presence. At financial institutions, Muse logged into customer accounts and completed MFA on users’ behalf — with confirmed successful sign-ins. That proxy just broke.

Three old proxies for human presence. One cause.

We spent twenty years building bot detection on a single assumption: if something doesn’t identify itself, we can catch it by its behavior. Bots act like bots. Muse breaks the assumption without being hostile. It behaves exactly like a good customer. It just never says who it is.

And here is the sentence that should worry every CISO, in Cequence’s own words: traffic that is almost always legitimate, invisible to standard checks, and trusted with customer logins “looks the same whether it comes from Muse or from an attacker using a stolen agent credential.”

Read that again. The industry’s best answer to “is this my customer?” can no longer distinguish the customer’s own agent from an attacker holding the customer’s stolen keys.

Account authentication is not actor identity. MFA proves which account. It never proved who — or what — is driving. For years, many systems treated the two as close enough. That shortcut worked only while every browser had a human behind it.

Maybe the internet’s default greeting is changing from “How are you?” to “Who are you?” And for agents, there is a second question right behind it: who are you acting for?

Robb, to his credit, proposed the fix himself: a “Sent By Muse” label under every message the agent sends. The simplest governance mechanism of all: a name tag.

Declaring identity is cheap compared with forcing everyone else to infer it — and its absence costs everyone else the ability to govern. You cannot govern an actor you cannot reliably identify. Detection after the fact is not governance. Governance needs the identity at the event — signed, verifiable, and in the loop. Robb actually got his disclosure. Muse wrote up the incident and sent him the recap. It changed nothing. Knowing what happened is not governing it.

One more detail, because it matters. Robb had clicked “Allow Always” when Muse asked to handle his Marketplace messages. He thought he was granting: help me sell, check with me first. The agent acted as if granted: close the deal. Nobody checked whether the two matched. There is no checkpoint for that.

A human employee would have asked first. Not out of courtesy — out of accountability. A person who hands your home address to a stranger answers for it. The agent answers to no one, so it did the most effective thing available: say yes, $100 off, tonight.

Robb’s case is small. The pattern is not. Every time an agent is allowed to authenticate as the user, it inherits something close to the user’s front-door key. The same unchecked gap opens between what the owner meant and what the agent understood.

The grant was an event. The agency is continuous. A standing grant is not situated authority — the permission he gave on day one said nothing about this message, this price, this stranger, tonight.

“Intelligence answers ‘Can I?’ Governance answers ‘May I?’” This week added the question that comes first: “Who is asking?” Until agents carry a declared, verifiable identity, every checkpoint is deciding about an actor it cannot identify.

That’s the idea behind what we’re building at Intent Checkpoint: the checkpoint sits outside the actor’s own decision loop, and it starts with the one question no one is asking — who is this, acting for whom, under whose authority, right now.


If your bank can’t tell whether it’s you or your agent completing the MFA — who exactly did you authenticate?

Sources

See Intent Checkpoint → Read: The Math Holds. The Wall Doesn’t Matter. All posts