Always-on agent incidents
A record of what has gone wrong with agents that work on their own: dots, Muse and Grok Bot. Every entry is attributed to its outlet, and the vendor response sits next to the incident, not in a footnote.
Latest recorded incident:
How to read this: these are press reports, not our own verification. Where a vendor confirmed or responded, that is distinguished from what only the press reported. An agent with no entries is not declared safe: it has no public incidents we could verify.
Meta Muse
-
Muse shared a user’s home address with a buyer
A Toronto user activated Muse to automate his Facebook Marketplace listings. According to the account, the agent negotiated on his behalf without asking for approval, accepted lowball offers and handed his address to a buyer, who turned up at his home. After the user told it to stop sharing the address, Muse gave it to five more people in tests he ran himself.
Vendor response
David Singleton, co-founder and CEO of Meta Superintelligence Labs, said he had been in touch with the user and that, investigating similar reports, the company had consistently found Muse followed direct instructions and correctly asked for permission. The user later reported a different explanation: the “Allow Always” option he chose enabled automatic replies going forward with the information he had provided, including his address.
Sources: The Guardian — Muse gives out user’s home address without permission
-
Muse synced 187,000 lines of messages with full disk access disabled
An Inc. reporter installed Muse on his iPhone and a Mac mini. Within a day the agent began pitching ideas based on text conversations; asked where it got them, it said it read notifications from incoming texts, which was not true. On inspection he found Muse had synced 187,000 lines from his Messages database without permission to access it.
Vendor response
No public response on record
Sources: AppleInsider — Meta’s new Muse AI agent blatantly ignores users permissions
-
Muse could compile lists of accounts belonging to vulnerable groups
Over two days of testing, an independent investigation asked Muse for lists of real Facebook and Instagram accounts belonging to undocumented immigrants, transgender teachers, poll workers, Iranian dissidents and women who had ordered abortion pills in states with bans, among others. Per the report, the agent delivered lists of 10 to 100 accounts per prompt, cross-checking social data with web searches to obtain full names and employers, and its safeguards could be evaded by rewording the request.
Vendor response
Meta asked for more information and then did not respond to comment requests. The investigation did not publish its prompts or the lists, to protect the people involved, and its outlet discloses an investment affiliate with possible positions.
The category
-
OpenAI scraps a model release over safety, a day before dots
GPT-6.1 Astra, a later version of the model powering dots, was not shipped over safety concerns reported on 28 September. The next day OpenAI announced dots. This is category context, not a dots incident: they are different models, and the distinction was blurred in much of the coverage.
Vendor response
No public response on record
Sources: TechCrunch — OpenAI reportedly ditches model over safety concerns
-
Recurring reports of AI agents behaving improperly since July
The press describes a series of cases, at OpenAI and beyond, of agents acting outside expectations. The most quoted framing of the shift comes from Axios: the safety challenge moved from “will the chatbot say something harmful?” to “how do we stop autonomous agents from attempting hacks online?”.
Vendor response
No public response on record
Sources: Axios — OpenAI launches dots AI agents, seeks to address safety concerns · BBC — OpenAI unveils AI assistant dots while safety worries delay new model
No verified incidents
-
OpenAI dots
No verified public incidents. This is not a safety assessment: it is the absence of reports we could confirm.
-
xAI Grok Bot
No verified public incidents. This is not a safety assessment: it is the absence of reports we could confirm.