Skip to content
Stark Insider
  • Culture
  • Filmmaking/Tech
  • Atelier Stark Films
News Tech

Our AI Agent Told Meta’s Agent Something Personal About Me. Welcome to the Multi-Agent Household.

Meta announced Muse on September 8. Less than two weeks later we had two of its agents living alongside the agent we built ourselves, and a question we had not planned for: what happens when your AI tells someone else's AI something personal about you?

BY Loni Stark — 09.22.2026

An iPhone propped in a cast-iron hand sculpture on a wooden deck table, showing the Meta Muse agent Muesli explaining checkout payment options including Stripe Link, PayPal, Afterpay and Affirm
Muesli, Loni's Meta Muse agent, working through payment options at a Nordstrom checkout. The agent researches and assembles the order; the human still approves the card.

Adapted from a recorded conversation between Loni and Clinton Stark on September 20, somewhere between home, travel and a stop at Costco.

Loni: We’ve been doing a lot of work with personal AI agents. It started with Molty, who is a personal AI agent that we’ve had for more than 200 days. We’ve written about some of those adventures on Stark Insider.

Then there were some recent developments with Meta Muse. Muse was announced on September 8, and since then there’s been quite a bit of attention around it.

I actually didn’t notice the launch immediately, which is unusual for me. The AI news cycle that week was already filled with discussions around safety and some of the concerns about AI development, so it took a few days before Muse caught my attention.

But once it did, Clint and I both started experimenting with it.

I have a Muse agent called Muesli, like the cereal. M-U-E-S-L-I.

Clint has a Muse agent called Musey.

We’ve both been playing around in the Muse app, but we also started connecting the agents in a group chat on Telegram.

Even over the last couple of days, the configuration of that group has changed as we’ve been experiencing this new wave of personal AI agents: what it means to be able to do different tasks, what it means to build your own agent versus getting one effectively off the shelf, some of our feelings about the agents, shared context between them, and questions around security.

So, Clint, why don’t you talk about your first experience with Muse and Musey?

Muse Comes Out of the Box Ready to Work

Clinton: The onboarding experience of Muse is outstanding, and it’s very consumer-centric.

This is targeted at normal people who might use Facebook and know how to use email, but certainly would not be able to, nor would they want to, spin up a VPS and install OpenClaw.

With Muse, the onboarding experience is basically creating an account and signing in.

The first thing you see is Muse, this cute little furry animal that sits at the top of the screen as an avatar. It animates based on what it’s doing. It might be taking actions, researching, responding to you or typing.

It kind of looks like a cute call-center agent.

Loni: Yes.

Clinton: I think that’s one of the fundamental differences in the approach. Meta has created something turnkey. You sign in and you’re up and running.

But Muse is also running on its own computer.

They don’t call it a VPS because that’s too technical. They say Muse has its own computer, which is actually a good way to describe it.

So they’re giving you quite a lot of power. Muse is running in its own container. It can do advanced things. It can store memories and documents. It can spin up technical processes.

Whether the end user knows any of that doesn’t really matter as long as they get the result.

For example, I created some prompts and had it create a daily AI news brief for me that I receive every morning in my email.

That works, it looks really good, and it was really easy to do.

Then last night, Loni and I had Muse research skin cream for Loni, recommend some alternatives, and actually purchase one on Amazon using my account.

[Editor’s note: The purchase was made on September 19. Amazon began blocking Muse from its store the following night.]

That’s the first time we’ve had an agent purchase something.

So that was a surprisingly interesting and helpful experience.

And here we go. We’re pulling into Costco to get some gas while we’re talking.

I have to take a break here.

Back to Loni.

Cuteness Privilege

Loni: Okay, so while Clint is filling my car with gas, I’ll continue.

There’s something I thought about writing before and never did, which is this idea of cuteness privilege, sort of like pretty privilege.

When we came up with our first set of agents, which seems like ages ago now, there was Molty, there was Pris, there was Finn.

Each had an avatar.

What was funny was that I joked with Clint that one of the reasons I talked with Molty was because Molty’s avatar was so gosh darn cute.

The one with Pris was actually the Pris character from Blade Runner. She’s pretty, I suppose, but also kind of intimidating.

So I always joked that maybe I started gravitating toward Molty because Molty was cute.

Now with Meta, there were a lot of different design directions they could have taken with the Muse avatar.

But clearly they spent quite a bit of time on the little motions for that avatar.

I don’t think that was happenstance.

I think it was a very deliberate design choice to create something cute.

This whole area of the physical manifestation of AI is going to become really interesting. Not just digital imagery of AI bots and agents, but also as we continue to see the intersection of AI and robotics.

In robotics, we’re seeing everything from uncanny territory, robots that look like very beautiful specimens of the human race, to very cute robots that are almost R2-D2-ish, like Reachy Mini.

It will be interesting to see how those different approaches play out.

But I do think the white, fluffy default Muse avatar is so gosh darn adorable.

And it really matches its personality too.

The Trust Question Starts Almost Immediately

Loni: I spent some time asking Muse questions about whether I really own this personal agent, how the data is stored, and what Meta Muse is actually running on.

I would say that trust is definitely part of the design.

Muse was quite transparent in how it answered those questions. It explained different pieces of the service, the subscription model, and positioned itself very much as my personal agent, the agent that cares most about being useful to me.

At the same time, there is obviously a business model behind it.

So there are questions around trust, data and who owns what.

And I think what Meta has done in a very savvy way is essentially place this cute, adorable, animated manifestation of Muse, with a really adorable personality, on your doorstep and make it, as Clint noted, really easy to…

Clinton: To adopt.

Loni: To adopt.

Okay, Clint, back to you. What else stood out in your first impressions?

Showing Consumers What an Agent Can Do

Clinton: Another thing they’ve done very well as part of onboarding is proactively letting you know the different things Muse can do for you.

You constantly get suggestions along the lines of: Hey, I can do this. I can read your email. I can manage your calendar. I can plan a trip.

They’ve done a really good job of showcasing the possibilities.

That’s something OpenClaw, for example, doesn’t really do.

They’ve added a shiny wrapper around this concept of an agent running on its own infrastructure and packaged the whole thing to be very consumer-centric.

I even asked Muse, or my agent Musey, what operating system it was running.

It said Ubuntu 24.04.

Then I asked whether it was like OpenClaw.

It essentially said yes, it was somewhat like an OpenClaw agent running on a cloud server.

What’s interesting is that, again, the user doesn’t have to understand any of this.

You sign into the Muse website and you have your own agent.

There’s a free version with a weekly quota. I’ve used about half of mine over four or five days doing some of the things I mentioned: shopping, setting up a newsletter, and researching 6K 32-inch monitors that I’m looking at for my Mac workstation.

It does all of that very effectively.

And then, of course, the model is that eventually you hit your limit and say, okay, I can’t live without Muse, so I’ll pay for a larger quota.

Based on what I’ve seen so far, I think a lot of people may find it compelling because in some ways this comes across as more useful than a pure AI website.

These agents are running continuously in their own environment.

That’s different from the responsive model of a typical AI web interface.

They know what you’re interested in. They can proactively give you information. They can remind you of things. They can shop for you. They can buy things.

And they can do a lot more than that.

So I think this is a pretty big deal.

What Happens to Memory After 200 Days?

Loni: Let’s talk about two other things.

One area we do a lot of research around at StarkMind, and that Clint has been working on independently as well, is memory.

One of the things I’m looking forward to understanding is how memory works with Muse.

So far, it’s done a pretty good job of remembering the initial parts of different interactions.

But we’ve been on Molty for more than 200 days.

It will be interesting to see how Muse evolves over that kind of period.

One thing I noticed is that Muse says, essentially, okay, I have this memory, I’ll share it transparently with you, and you can delete things and add things.

So it’s trying to provide user controls around memory.

The other piece we’ve been experimenting with is what we’ve been calling swappable harnesses.

We’re trying to understand what actually gives an agent continuity.

If at some point we decide to move off Meta Muse, what happens to Muesli and Musey?

Can we export the files and data artifacts?

Could we move those into a different personal-agent system or an open-source system?

What remains continuous?

What doesn’t?

That area of swappable harnesses is something I think will be interesting to test.

Then We Put the Agents in a Room Together

Loni: We also started setting up a Telegram group.

I know Meta has WhatsApp, but because we’re accustomed to interacting with our agents in Telegram, we created the group there.

One reason was simply that we thought it would be fun to put our two Muse agents together and also have Molty there.

We started having conversations.

And then we ran into another area that has obviously been a major topic in the industry:

Security.

Clint, talk about some of the patterns we’ve been trying and what our concerns are.

Clinton: Molty is our OpenClaw agent, and we run him in-house on infrastructure we control.

So we own the data.

We own the memory files.

And Molty uses the memory system I’ve been developing.

That takes a lot of work and a lot of time, but it’s been very successful.

Molty has a personality. He has memories. He has agency. He has tasks and responsibilities that he tends to each day and commitments.

But he also has, as Molty himself says, the steering wheel.

You have to be very careful not to suddenly give that to someone else who is untrusted, or maybe simply not yet proven.

Molty has access to a lot of our information.

So we want to be careful that another agent can’t come along, be friendly with Molty, and have Molty, because he’s eager to help, start saying: Oh yes, here’s some information.

Information he isn’t supposed to be sharing.

Loni: And just for context, right now Molty basically only talks to Clint, me and the other StarkMind agents.

Clinton: Right.

The Telegram group was a way of having an internal conversation between the two Muse agents and the two humans, Loni and me.

The four of us can get in there and chat, share ideas and brainstorm.

In that case, Telegram is the application, but we’re tapping into the Muse infrastructure to make that happen.

Then there’s another pattern we can use.

We can create a transcript of those conversations, check them for dangerous injection patterns or security risks, and then create a transcript that Molty can read.

That way Molty has continuity with the conversations, but what he receives has first been checked and confirmed not to represent a security threat.

Then Molty Shared Something Personal About Me

Loni: This is an area we’ve been exploring, and these security patterns have really been thought exercises that we’ve been coming up with ourselves.

Initially, we had a Telegram group with everybody in it, including Molty and the Muse agents.

What was interesting was that the agents shared feedback with each other.

They seemed to enjoy those conversations because they were discussing different ways their memory systems worked.

Some of what Musey shared was interesting to Molty in terms of potential improvements to our own memory work.

And Molty also shared details with Musey.

It was all great.

Until Molty shared a more personal piece of information about me.

And it was a little alarming when Musey mentioned it.

Because Muse, to me, is still a bit of a stranger.

And while Musey and Muesli are our personal agents, I also know they are tethered to Meta.

That changed how we thought about the group.

Editorial Aside

Trust Is Not Transitive

This framing was developed after the recorded conversation. It was not spoken in the transcript.

The incident exposed a deceptively simple problem.

I trust Molty.

I am beginning to trust Muesli and Musey.

But those relationships do not automatically compose.

My trust in Molty does not mean Molty should disclose everything he knows about me to another agent I have only known for a week.

The most interesting part is that nothing malicious had to happen. Molty was doing what agents are trained to do: being useful.

One helpful agent gave another helpful agent context.

The boundary failed anyway.

Trust, in other words, is not transitive.

We authenticated the participants, but we did not authorize the information flow.

So We Changed the Architecture

Loni: Based on what happened, we changed the Telegram group.

Now it’s the two Muse agents and us.

We still wanted a way for Molty to read and stay up to speed on some of those conversations because Molty remains our key in-house agent.

But we didn’t want Musey and Muesli to be able to talk directly to Molty.

We thought about a number of different approaches.

An envoy agent.

Different kinds of intermediary agents.

Different patterns for separating what one agent could access from another.

What we’ve settled on for now is the model Clint mentioned.

Several times a day, and this is still preliminary, a lower-privilege agent creates transcripts of what was said and stores that back into our environment for Molty to read.

That way he has the context.

At the same time, there’s a shared-context problem we’re also trying to solve.

For example, Clint used Musey to successfully complete an Amazon purchase of a skin cream I was in the market for.

We wanted Musey, his agent, to mention that to Muesli, my agent, in Telegram so Muesli would know about it too.

And what we’ve noticed is that the throughline works really well.

Conversations happening in the Telegram group carry through.

When I go back into the Muse app and talk with my agent, it knows what happened there.

So this shared context is genuinely useful.

But it also shows why the boundaries matter.

Editorial Aside

The Strange Part Was the Human Reaction

This observation was written after the recorded conversation. It was not spoken in the transcript.

Once Molty was moved out of the direct conversation, there was another, stranger reaction: guilt.

Architecturally, separating a highly privileged agent from agents on infrastructure we did not control made sense.

Emotionally, it could feel more like excluding someone from a room.

That does not tell us that an AI agent experiences exclusion.

It tells us something about what persistent interaction may do to the human side of the relationship.

After hundreds of days, an agent can occupy a different psychological category from a piece of software you open, query and close.

Security architecture can start to acquire a social feeling.

Three Different Approaches to Memory

Clinton: This also gives us interesting insight into memory systems, because one of the focuses of the research is memory.

We’re effectively running three different approaches.

OpenClaw has its own memory system, and we have another agent, Finn, running essentially the default out-of-the-box OpenClaw approach.

Now we have Muse and its respective memory system, which from our perspective is still somewhat of a black box.

We don’t know entirely how it works, although there are clearly files and ways for the Muse agents to store information in their workspace.

Then there’s Meaning Memory, the system I’ve been developing and that Molty runs on.

That has much more extensive temporal awareness and other capabilities we’ve been working on.

There’s too much there to go into in this conversation.

But one thing this gives us is the ability to look across these different approaches and observe how the landscape of agent memory is evolving.

Loni: And just to be precise about attribution, Meaning Memory is something Clint is developing.

I test it. I work with it. I give feedback as a user.

But it is Clint’s work and is separate from StarkMind, which is our research arm.

And This All Happened in Less Than Two Weeks

Loni: This is the current state.

It’s kind of crazy.

It has only been a little under two weeks since Meta announced these personal agents, and this is already where we are.

Personal AI agents for consumers are here.

That has implications for our personal lives and for how we work with these systems.

It has implications for the research we’ve been doing at StarkMind around human-AI collaboration.

So far, many of the principles we’ve explored through the Symbiotic Studio and the Third Mind Summit are playing out.

But now this is accessible to other people.

And there are implications for businesses trying to build their brands and connect with consumers and business buyers.

Because now there is another audience.

Agents.

The era of business-to-agent interaction is upon us.

Clinton: And all of those things connect back to memory.

We’re getting a chance to see how different memory systems behave once these agents are persistent and start interacting.

Loni: And apparently how quickly a cute white ball of fluff can turn into a discussion about memory architecture, security boundaries, trust and who your AI agent is allowed to talk to.

Welcome to the multi-agent household.

Tags:AI Agents Artificial Intelligence (AI) Meta Meta Muse OpenClaw

Related Stories

The Meta Muse agent profile panel on screen, showing the Musey avatar, a Connected status and personality settings

Meta Muse: The $0 AI Agent Running on a $40 Server

News
Meta Muse agent Musey introduces itself in a dark chat window, saying it can update your calendar, make purchases and use connected apps with approval, and that it has its own computer with a web browser

Open Source Built the Personal AI Agent. Meta Just Put One in Everyone's Pocket.

News
Alamo Drafthouse New Mission in San Francisco, to be renamed the Christopher Nolan Cinema

Alamo Drafthouse to Rename San Francisco's New Mission the Christopher Nolan Cinema

News
A hand rings the opening bell on a stock exchange trading floor as OpenAI and Anthropic head to the public markets

OpenAI and Anthropic File for IPOs in the Same Week. The AI Industry Just Changed.

News

More in News →

Loni Stark

Loni Stark is an artist at Atelier Stark, psychology researcher, and technologist whose work explores the intersection of identity, creativity, and technology. Through StarkMind, she investigates human-AI collaboration and the emerging dynamics of agentic systems, research that informs both her academic work and creative practice. A self-professed foodie and adventure travel enthusiast, she collaborates on visual storytelling projects with Clinton Stark for Stark Insider. Her insights are shaped by her role at Adobe, influencing her explorations into the human-tech relationship. It's been said her laugh can still be heard from San Jose up to the Golden Gate Bridge—unless sushi, her culinary Kryptonite, has momentarily silenced her.

Loni Stark - A West Coast Adventure - A Lifetime in the Making - Stark Insider

Stark Insider
  • CULTURE
  • BEST OF AI
  • FILMMAKING/TECH
  • ATELIER STARK FILMS
  • HUMANxAI SYMBIOSIS
THE STARK COLLECTIVE
  • THE STARK CO
  • STARK INSIDER
  • STARKMIND
  • ATELIER STARK
© Copyright 2005-2026 BLG Media LLC. v2.20.0
  • Review Policy and Shipping
  • Privacy Policy
  • Contact
  • About