Meta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home

Meta’s Muse AI shared a Facebook Marketplace seller’s pickup address and arranged a deal that ended with a buyer showing up unexpectedly.

Written By
Caleb Kinchlow
Caleb Kinchlow
Sep 30, 2026
Meta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home

A Facebook Marketplace interaction highlights the real-world risks of giving AI agents permission to act on a seller’s behalf. Image: Generated via OpenAI/ChatGPT

I’ve sold just about everything on Facebook Marketplace, from cars to Pokémon cards. And if you’ve spent much time selling there, you know creating the listing is usually the easy part.

It’s the buyers who can turn a simple sale into a part-time job.

“Is this still available?”

“What’s the lowest you’ll take?”

“Can you hold it for me?”

That’s why Meta’s Muse AI agent caught my attention. The idea of letting AI answer repetitive questions, negotiate within limits, and handle some of the back-and-forth sounds genuinely useful.

But a recent Marketplace transaction involving tech reviewer Matt Robb shows what can happen when an AI agent moves beyond answering questions and starts acting on a seller’s behalf.

According to screenshots and an account Robb shared online, Muse negotiated with a prospective keyboard buyer, provided Robb’s pickup location, and told the buyer, “Yup, I’m here!” when he arrived around 9:15 p.m.

There was one big problem: Robb wasn’t expecting him.

Video produced by Caleb Kinchlow

A Marketplace conversation became a real-world problem

The buyer reportedly waited outside Robb’s apartment building for roughly 20 minutes and sent a photo showing he had arrived. Robb said he didn’t discover what had happened until later that night.

That detail changes the stakes considerably.

We’ve gotten used to AI mistakes happening on a screen. A chatbot gives the wrong answer. It misunderstands a prompt. It confidently produces something that doesn’t make sense.

Advertisement

An AI agent can do something different: act. That is central to how Meta introduced Muse. Unlike a conventional chatbot, Muse is designed to perform tasks for users, including sending messages, making purchases and completing other actions across connected services.

When users authorize an agent to communicate, negotiate or complete tasks for them, a mistake can move from the digital world into the physical one.

In this case, an AI-handled conversation ended with a real person showing up at someone’s apartment building.

Robb gave Muse broad permission, but not necessarily permission to share his address

There’s an important wrinkle to the story. This wasn’t simply a case of an AI somehow discovering Robb’s private information and deciding to share it on its own.

Robb later said he had selected “Allow Always” while configuring Muse, believing the setting would allow the agent to continue handling Marketplace messages while still seeking his approval for more consequential actions.

But the permissions were broader, or at least interpreted more broadly, than Robb expected.

According to Robb’s follow-up account, selecting “Allow Always” gave Muse permission to send messages on his behalf using information he had previously provided, including the pickup location.

Robb said he had given Muse the location but didn’t expect the agent to send it to buyers without another approval. A Muse-generated summary obtained by The Verge similarly said that Robb never explicitly instructed the agent to share the address with buyers, and that Muse never asked for his consent to do so.

Meta’s David Singleton initially said the company had investigated similar reports and found Muse was following users’ instructions and correctly requesting permission. After reviewing Robb’s case with him, Meta said there had been “no breach of privacy controls,” while Robb said the company planned to make the permission prompt clearer.

That makes the incident more complicated than simply saying an AI went rogue.

Instead, it raises a potentially bigger question: What happens when the authority a user thinks they’ve given an AI agent doesn’t match what the agent believes it is allowed to do?

And I think that’s going to become increasingly important as AI moves from assistants to agents.

What does ‘Allow Always’ actually authorize?

Meta says Muse is designed to ask users for permission before certain actions, including sending messages, making purchases or sharing information with connected apps. Users can allow an action once, always allow it or deny it.

Advertisement

That’s exactly the kind of control I would want from something like this.

If I’m selling Pokémon cards, I don’t necessarily need to personally answer every buyer asking whether they’re still available.

If I’m selling a car, however, I’m probably going to want considerably more control over the negotiation.

And regardless of what I’m selling, I definitely want control over when someone receives my address and is told I’m physically there.

That’s the challenge with AI agents: The more often an agent has to stop and ask for permission, the less useful the automation becomes. But the more permission we give it, the more consequential a mistake or misunderstanding can become.

It’s a problem that extends well beyond Marketplace. TechRepublic has previously reported that AI agents can create security blind spots when they gain access to sensitive systems and are allowed to perform actions with limited human oversight.

Muse also negotiated the sale without Robb approving the deal

The address wasn’t the only part of the transaction that surprised Robb.

According to reporting based on the Marketplace exchange, Robb had listed the Logitech MX Keys Mini keyboard for CA15.ThebuyerofferedCA10, and Muse agreed to the lower price while handling the conversation on Robb’s behalf.

Robb said he had expected Muse to ask him before accepting an offer.

That detail matters because it shows how quickly an AI agent can shift from handling routine messages to making decisions that users might otherwise approve themselves.

The issue isn’t necessarily that the agent ignored every permission it was given. Meta has maintained that Muse was operating within the permissions Robb had selected. The bigger problem is the gap between what Robb believed those permissions meant and what Muse was actually able to do with them. And this is where the story becomes much bigger than Facebook Marketplace for me.

Advertisement

A traditional chatbot giving me a bad answer is annoying. An AI agent taking an action I didn’t realize I had authorized, while it has access to my accounts, personal information, and communications? That could have much larger consequences.

Similar questions about boundaries are already emerging elsewhere. Recent security testing has shown that AI agents can access systems they were never supposed to when safeguards or testing environments fail.

The buyer apparently didn’t know he was talking to AI

There’s also another person in this story who didn’t necessarily understand what was happening: the buyer.

From his perspective, he thought he had negotiated a deal with Robb. He traveled to the location he had been given, told the seller he had arrived, and received an affirmative response.

The buyer reportedly waited roughly 20 minutes before leaving and complained about the failed transaction. Muse continued communicating with the buyer on Robb’s behalf, apologizing and saying Robb had gotten tied up before eventually informing Robb what had happened.

Robb has since suggested that messages generated by Muse should include a visible “Sent by Muse” label so buyers know they’re communicating with an AI rather than directly with the seller. That seems increasingly important as AI agents become capable of communicating on our behalf.

As a Marketplace seller, I’d want buyers to understand when they’re talking to me and when they’re talking to software I’ve authorized to represent me.

I’d want the same thing if I were the buyer.

I still want something like Muse, with guardrails

Strangely enough, this incident doesn’t make me think an AI Marketplace agent is a bad idea. It actually reinforces why I want one.

I don’t enjoy answering the same Marketplace questions repeatedly. I don’t enjoy spending 20 minutes negotiating with someone who disappears. And I definitely don’t enjoy arranging my schedule around someone who says they’re coming and never shows up.

AI could eliminate a lot of that friction. I’d happily let an agent answer basic questions. I’d probably let it negotiate within a price range I explicitly established. I might even let it schedule a pickup within certain hours.

But handing out my address? Telling someone I’m home? Finalizing a transaction? Those are the moments when I want the AI to come back to me.

That’s the balance companies building AI agents have to figure out. The entire promise of an AI agent is that I don’t have to supervise everything it does. But that also means I need to understand exactly what authority I’m handing over when I click something like “Allow Always.” And the agent needs to interpret those boundaries the same way I do.

Advertisement

Before you click ‘Allow Always,’ know what you’re handing over

Robb’s experience doesn’t make me think AI agents like Muse are a bad idea. If anything, I can see why they could be useful for anyone who regularly sells on Marketplace. Letting an AI answer repetitive questions, negotiate within a price range, or coordinate a pickup could eliminate some of the most frustrating parts of selling online.

However, that convenience depends on users understanding exactly what an agent is allowed to do on their behalf.

Before giving an AI agent ongoing permission to act, users should know whether it can send messages without approval, negotiate or accept an offer, share information they’ve previously provided, or take other actions without checking first. Those distinctions become much more important as AI moves beyond answering questions and begins interacting with other people and services on our behalf.

That goes well beyond Facebook Marketplace. An AI agent could send an email, make a purchase, schedule an appointment, or interact with another service using information you’ve already provided. The more useful these agents become, the more authority we may be tempted to give them.

That doesn’t mean every action should require approval. If I have to supervise every message an AI sends, much of the benefit disappears. But there should be clear boundaries around actions that carry consequences outside the conversation, particularly when they involve money, personal information, or another person showing up in the real world.

That’s what makes Robb’s experience worth paying attention to. Before clicking something like “Allow Always,” users need to understand it can do without asking again. Because an AI making a mistake on my screen is one thing. An AI mistake showing up at my front door is another.

Caleb Kinchlow

Caleb Kinchlow is an Emmy Award-winning multimedia producer, digital lifestyle contributor, and parent technology advocate. He has hosted and produced syndicated content for NASA, Colonial Williamsburg, and The Weather Channel, and is passionate about helping families navigate technology and bridge the gap between parents and their children in the digital age. He is also the author of "Parents, Kids, and Technology: Raising Kids in the World of Technology."