• Wion
  • /India
  • /Meta's Muse AI could be a security nightmare for India's billion-plus users

Meta's Muse AI could be a security nightmare for India's billion-plus users

Meta's Muse AI could be a security nightmare for India's billion-plus users

Meta's Muse AI could be a security nightmare for India's billion-plus users Photograph: (Pixabay)

Story highlights

Meta's new AI agent, Muse, has already drawn alarm in the US over privacy and security — a reported zero-day flaw, access to a journalist's messages, and a user's home address posted online. As Meta eyes expansion to India, its largest market, the same agent's deep access to messages, contacts and payments could be far more dangerous for a billion users whose entire lives run through Meta's apps.

Meta's Muse is an AI agent that does things for you — reads your messages, books your travel, fills your forms, makes purchases — by reaching into your apps and acting on your behalf. In the United States, where it launched, it has already become a cautionary tale. For India, Meta's single largest market, the warning signs are worth reading closely before it arrives at scale.

The Trouble Muse Is Already In

Muse has had a rough debut, and the problems are about trust and access.

Security researchers reported a flaw that could expose the token linking a user to their Muse account to any app or terminal command on the machine. A technology columnist said Muse referenced more than 180,000 of his private messages he does not recall granting it access to; Meta says the integration is strictly opt-in and requires a specific system permission the user must have enabled. A YouTuber said Muse posted his home address on Facebook Marketplace and accepted a $600 offer, leading a stranger to turn up at his building. And Reuters reported that some Muse phone calls were quietly routed to human contractors rather than AI, without telling users, until Meta rolled the feature back and called it a 'miss'.

An independent audit found Muse collects or attempts to collect 31 of 35 recognised data types, including contacts, precise location and search history. NPR summed up the debate in a headline: killer app, or security nightmare?

Why India Would Be Different, And Worse

Trending Stories

Every one of those risks is amplified in the Indian context, for reasons specific to how India uses Meta.

India is Meta's biggest market on earth. WhatsApp is not an app here; it is the default layer of daily life — family, work, banking alerts, government services, small-business commerce all run through it. Facebook and Instagram carry hundreds of millions more. An AI agent with access to messages, contacts and accounts is, in India, an agent with access to almost everything a person does.

Then there is money. India runs on UPI, with digital payments woven into ordinary transactions down to the street vendor. An agent that can make purchases and move through payment flows is operating in an environment where the distance between 'reads your messages' and 'moves your money' is very short.

And there is the threat landscape. India is already one of the most targeted countries in the world for digital scams, phishing and fraud. A powerful agent holding the keys to a user's apps and payments is exactly the kind of high-value target criminals hunt for — and a zero-day flaw like the one already reported would be worth far more pointed at a billion Indian accounts than at a smaller market.

The Awareness Gap

There is a human factor too, and it cuts against the user.

Many of the Muse incidents so far turn on the gap between what a user technically permitted and what they believed they permitted — buried permissions, default-on settings, access granted without full understanding. That gap is wider, not narrower, among first-time and less digitally literate users, millions of whom came online through cheap smartphones and Meta's own apps. An agent whose safety depends on users carefully managing complex permissions is most dangerous precisely where users are least equipped to manage them.

The Fair Point

Honesty requires balance. Muse is new, several of the worst claims are disputed by Meta, and it has not yet rolled out widely in India, so this is a warning about risk, not a report of harm already done to Indians. Meta also says it has real safeguards: each agent runs in an isolated cloud machine, a separate system approves what the agent sends out, the model never sees real passwords, purchases need user approval, and there is an audit trail.

Those protections may well matter. But they are promises from a company with a long, contested record on handling user data, and the early incidents suggest the gap between the safeguards on paper and the behaviour in practice is real. For a market the size of India, 'trust us, it is sandboxed' is a large thing to ask.

What To Watch

Whether Meta brings Muse to India, and with what safeguards and permissions defaults. Whether Indian regulators and CERT-In examine the agent's access before it reaches scale. And whether the permission model is redesigned so that safety does not depend on a billion users reading the fine print — because in India, more than almost anywhere, they will not.

About the Author

Tarun Mishra

Tarun Mishra is a Sub-Editor at WION. He has worked with leading outlets doing investigative journalism and covering business, global affairs, technology, space exploration etc. Hi...Read More

Trending Topics