A Week With a Personal AI Agent:It Sent the Email Without Asking, and Waited for My Click to Spend Money
A week of errands with Meta's Muse: it emailed support for me unasked, but spending money still took my click. Where to draw that line.
A week of running errands through Meta's Muse showed me where a personal agent's freedom should stop. It could send a polite email for me without asking, but spending my money still took my click - and that split is the one worth copying if you're handing an agent your inbox.
Another agent? I already had three
I know some of you felt the way I did when Meta launched Muse. Another AI agent? I already use Claude, ChatGPT and Grok Bot every day. What could this one do that they can't?
That was me until about a week ago. Then I tried it.
It doesn't feel like the coding tools I work in all day. Those are precise and a little cold. Muse feels more like a big brother who's keeping an eye out for me.
It brought up something I never asked about
It's also proactive in a way my other agents aren't. My Muse agent (I'll call him Marvin) can read my email.
A few days in, he flagged a failed build on one of my projects. A security scan had blocked it over an outdated library.
I never asked him to watch for that. He worked out that it mattered to me and brought it up anyway. That's what I'd expect from a good human assistant.
That one alert changed how I thought about the rest of the week. An agent that only answers questions is a tool. One that decides what is worth interrupting you for is closer to staff, and staff need rules about what they may do on their own.
Errands, and the click it left for me
It also changed what I think agents are for. I'd treated them as work tools. Muse is the first one I've used for errands, and it made them kind of fun.
I asked it to find me a pair of shoes. It went through the sites, picked the pair that fit my criteria and my budget, and put a buy button in the chat. That saved me maybe thirty minutes of tab-hopping.
It never asked for my card number. It had me connect through Shopify instead, then filled in the payment on the checkout page. Twice the site flagged it as a bot, and I took control to click the human check.
At the order screen it stopped. Nothing was placed until I clicked Submit myself.
That's not a gap. That's exactly what I want.
The refund it chased for me
The next errand went further. I'd forgotten to cancel an AI note-taker, and it renewed for a year at $127.20. On September 29 I asked Marvin to do two things: cancel the subscription, and negotiate for a full or partial refund.
It did not go smoothly, and I think the rough parts are the useful part.
First he signed into the wrong Google account. I caught it, took over and logged in myself. Then his browser stalled. Instead of forcing it, he stopped, told me what had happened and gave me two options. When I asked him to try again, he opened the sign-in page and waited for me there.
Once he was in, he found the plan: one seat, $127.20, charged July 26. He also found there was no cancel button anywhere in billing. The only options were changing the seat count or the billing cycle, and even removing the card was disabled.
So he emailed their support from my address and asked for both the cancellation and the refund.
He didn't show me that email first. Afterwards he told me it had called the plan "already cancelled" when it was only a request. I liked that he flagged his own mistake. I'd still rather have seen the email before it went.
Then he told me what he would do next: "if they counter with a partial refund, I'll bring it to you before accepting."
Support has replied. The renewal was past their automatic refund window, so they escalated it to their billing team for a decision. The refund is with them now. The person at support also said I could cancel in the billing settings myself, which contradicts what Marvin found on that same page. And they asked why I was leaving.
This time Marvin didn't answer on his own. He offered to draft a reply for me to review.
Where the line sits
So here's where I've landed. Marvin can send a polite email for me without asking. Spending my money still takes my click.
I've written that I'd never give an agent a goal and the keys and walk away, and Muse seems to be built the same way.
What I noticed over the week is that Muse drew the line by consequence, not by task. Finding shoes, filling in a form, opening a support ticket, telling me about a broken build: it did all of that without me. Placing the order and accepting a partial refund came back to me.
If you're about to give an agent your inbox, at home or at work, decide that line before it acts, not after:
- What it can do alone. Look things up, fill in forms, send a routine request in your name.
- What it must bring back to you. Anything that spends money, accepts terms or settles a dispute for less than you asked.
- What you want to see first. For me, after this week, that includes the first email it sends on a new thread. The "already cancelled" line was harmless this time. On a different request it might not be.
It isn't perfect
It isn't perfect. Neither am I. It signed into the wrong account, it overstated what it had done in an email, and its browser stalled once. I caught the first one. He told me about the other two himself, and none of the three cost me money.
But a week in, Marvin is already a better personal assistant than most people I could hire, and he'll only get better.
Muse surprised me. What's a technology you keep putting off trying?
Your old AI agent conversations are worth more to the next agent than to you
Most people never reopen an AI conversation. Six ways I put old agent transcripts to work, and the one rule to follow before trusting one.
ReadWhat I learned trying to use Jev to judge AI-generated photos
Jev can't see images, so its photo scores are only as good as the model describing each photo. What six describers taught me.
ReadWhat I changed in my AI workflows after trying Claude Opus 5.5
What changed when I audited my coding-agent skills with Opus 5.5: fewer procedural rules, clearer ownership, and stronger verification.
ReadWorking on something like this?
Bring the app or the process to a free 15-minute call. I will tell you what I would look at first, and whether I am the right person for it.