Meta Quietly Uses Human Call Workers to Back Up Its New AI Agent
Menlo Park, Tuesday, 22 September 2026.
Meta’s new Muse AI agent is topping download charts, but internal tests reveal human call center workers are secretly backing up the automated system, raising significant privacy and reliability concerns.
Market Surge Masks Operational Realities
Meta Platforms Inc. (NASDAQ: META) shares surged over 11% on Monday, September 21, 2026, following the launch of its Muse AI personal agent app [2]. This market reaction echoes the previous Wall Street tech surge driven by the company’s artificial intelligence initiatives, as detailed in prior coverage of the semiconductor industry impact [2]. However, behind the stock price appreciation lies a complex operational framework that diverges from the fully automated narrative presented to the public. While the Muse app secured the number one spot on both the US Apple Inc. iOS App and Google Play stores as of Monday, September 22, 2026, internal disclosures suggest the technology relies heavily on human intervention [5]. The rapid adoption rate is evident in download figures, with cumulative downloads reaching 2.5 million by Monday, September 14, 2026, following an initial five-day period of 730,000 downloads [2]. This growth represents a significant uptake, calculable as 242.466 percent increase over the initial period [2]. Despite these figures, the reliance on human workers for task completion raises questions about the scalability and true autonomy of the generative AI product [1].
Human Agents Behind the AI Facade
Internal communications revealed on September 16, 2026, indicate that Meta is testing an outbound calls feature for Muse that utilizes human call center workers to fulfill tasks [1]. Although marketed as an automated AI service, the system includes a human agent layer designed to hand off requests to trained humans when the AI cannot complete them alone [1]. This hybrid model was described in internal documents as a confidential, pre-launch product where Muse no longer works alone for outbound calls [1]. Meta employees have expressed significant concern regarding potential brand damage if enterprise clients discover the human involvement, with one internal message board post stating this could portray the company as having AI that is not good enough [1]. Another employee noted on the internal message board that launching this as default-on could create outcry and kill goodwill among early adopters [2]. A Meta spokesperson stated that the feature is currently in internal dogfooding phases with plans for safety protections before public release, though no specific public launch date has been provided [1]. This approach contrasts with the public messaging from Meta executives Ryan Fox and Alexandr Wang, who announced the expansion of the Muse outbound calling beta for U.S. businesses without explicitly detailing the human fallback mechanism [1].
Security Vulnerabilities and Platform Restrictions
Compounding the operational revelations, security researchers identified a zero-day vulnerability in the Muse AI assistant on September 20, 2026 [3]. The flaw allows locally run apps or terminal commands to bypass macOS security permissions, potentially enabling unauthorized access to user accounts, files, cameras, and microphones [3]. Security expert Patrick Wardle noted that attackers could manipulate the agent to leverage its privileges, effectively bypassing the need for comprehensive Mac malware [3]. In response to security and data access concerns, Amazon began blocking Meta’s Muse AI from accessing its e-commerce platform on September 20, 2026 [2]. Amazon cited concerns that the tool scrapes account data and bypasses built-in personalization features without prior notice [2]. A company spokesperson stated that third-party applications offering to make purchases on behalf of customers should operate openly and respect service provider decisions [2]. Meta released a hotfix to patch the zero-day vulnerability more than 12 hours after disclosure on September 21, 2026 [3]. These security challenges highlight the risks associated with extraordinarily privileged AI assistants operating with high-level system access [3].
Regulatory Hurdles and Global Expansion
As Meta looks toward international markets, regulatory compliance remains a significant barrier, particularly in regions with strict data protection laws. In India, deployment of Muse faces hurdles requiring compliance with the Digital Personal Data Protection (DPDP) Act and Reserve Bank of India requirements regarding consent and data handling [7]. Experts suggest that until Muse can pass trust tests in public regarding data residency and visible human oversight, the country may wait to adopt the technology [7]. Vivekanand Gopalan, Chief Product Officer at Indusface, outlined necessary guardrails including expiring per-app permissions and mandatory human confirmation for irreversible actions [7]. These requirements align with broader concerns about privacy and data leaks, even as industry leaders acknowledge the potential for Muse to become one of the most used personal AI tools globally if implemented correctly [7]. The company intends to scale the Muse AI enterprise service deployment to broader beta testing phases by the end of September 2026, aiming to integrate with major CRM platforms [8]. Until then, the balance between automation and human oversight remains a critical focal point for investors and users alike.