Meta’s Muse Reached More Than Half of Customers Cequence Studied in Two Weeks Without Identifying Itself as an AI Agent

Editorial Brief
At a glance: AI-assisted overview, optimised for journalists, search & news aggregators

Meta's Muse AI agent, launched on 8 September, was detected by Cequence Security in over half of the companies it studied within two weeks, often without the businesses realising it was an AI. Muse appears as a regular Chrome browser, making it difficult for standard security checks to identify it as an AI agent. Cequence's new Agent Trust capability helps businesses manage such agents by allowing them to block specific actions rather than the agent itself, ensuring legitimate customer use while preventing harmful activities.

EDITORIAL INSIGHT: Context, industry insight and market perspectives of this news story

Meta's rapid rollout of its Muse AI agent has presented a new challenge for businesses that rely on traditional security measures to distinguish between human users and automated agents. Cequence Security’s findings highlight the practical difficulty of detecting sophisticated AI-driven traffic, particularly when such agents are designed to blend in with ordinary browser activity. For organisations in sectors like finance, retail, and travel, this development raises immediate questions about how to maintain both security and customer experience as AI agents become more prevalent.

The emergence of solutions like Cequence’s Agent Trust points to a growing need for more granular controls that can identify and manage agent activity without broadly blocking legitimate customer interactions. As AI agents increasingly handle sensitive tasks, including navigating multi-factor authentication and completing transactions, businesses must adapt their security strategies to ensure they can distinguish between helpful automation and potential abuse. For many, the decision is shifting from whether to allow AI agents to how best to manage their presence without disrupting service or exposing vulnerabilities.

Story Ideas
Consumer trend

Implications of AI Agents on Cybersecurity and Consumer Behaviour

The rise of AI agents like Meta's Muse challenges traditional cybersecurity measures and affects consumer behaviour, as these agents can mimic human browsing and purchasing actions.

Target audience
business-finance
Story potential
8/10
Economic impact

Impact of AI Agents on Financial Institutions’ Security Protocols

AI agents like Meta's Muse are capable of performing tasks traditionally requiring human intervention, such as completing multi-factor authentication, posing new challenges for financial institutions' security protocols.

Target audience
trade-industry
Story potential
7/10
Press Release

LONDON, UK. — 7 October 2026

Within two weeks of Meta’s 8 Sept launch of its Muse personal AI agent, Cequence Securityfound traffic matching Muse at more than half of the customers it studied. Most of those businesses would not have known. Muse presents itself as an ordinary Chrome browser rather than identifying as an AI agent, so to standard security checks it looks like a person.

 

Cequence spotted the traffic with the same behavioural detection that powers Agent Trust, a new capability in Cequence Application and API Protection available today. Agent Trust verifies agents that present an identity and catches the ones that don’t. Muse shows why businesses need both. With Agent Trust, they can stop harmful requests while still letting customers use their services through agents like Muse. 

 

What Cequence found

Cequence analysed traffic across customers in financial services, retail, travel, software and other sectors from 1 Sept to 24 Sept 2026. At the median customer, Muse traffic grew nearly sixfold within about two weeks of first appearing.

 

  • Passes as a regular browser: Each Muse user gets their own agent. It runs a real Chrome browser in the cloud, directed by an AI model that reads each page and decides what to click, and it routes its traffic through a consumer VPN. It does not sign its requests or identify itself as an agent, so to most security tools it looks like a person browsing. Cequence identified it through behavioural analysis, which picked up signals such as a browser update that went from 0% to more than 90% of Muse traffic within days, a sign that Meta hosts and updates these browsers centrally.
  • Getting through multi-factor authentication: At financial institutions, Muse logged in to customer accounts and completed multi-factor authentication on users’ behalf, with confirmed successful sign-ins. For those businesses, a successful multi-factor login no longer shows whether a person or an agent is on the other end.
  • Browsing like a bot, buying like a customer: Muse searched, compared options, filled carts and moved through checkout, and a small share of sessions ended in a completed purchase. Most sessions browsed and left; the pattern businesses have long used to spot bots. Whether a visitor completes a purchase is no longer a reliable way to tell a bot from a customer.
  • Blocking the request, not the agent: In late Sept, a travel and hospitality customer’s security team began blocking nearly one in five Muse requests, targeting only the ones that looked abnormal. Muse itself remains allowed, and the rest of its traffic goes through. More businesses face this choice now, and it only works with controls precise enough to act on individual requests.

 

Together, the findings show why agents are hard to govern. Traffic that is almost always legitimate, invisible to standard checks and trusted with customer logins looks the same whether it comes from Muse or from an attacker using a stolen agent credential.

 

“AI agents like Meta’s Muse are bots that act on behalf of real customers. Many businesses can’t see them, and those that can are tempted to block them,” said Hari Nair, VP of product management at Cequence. “Agent Trust lets businesses block the action, not the agent. The agent keeps working for its customer, and the one request that crosses a line gets stopped, slowed or challenged.”

 

How Agent Trust works

Agent Trust pairs identity verification with the behavioural detection Cequence has run across bot and API traffic for years. It includes:

 

  • Detected agents inventory: A live view of every agent in an organisation’s traffic, including agents like Muse that do not identify themselves. Built-in agent detection rules, kept up to date by CQ Prime Threat Intelligence, are already running for every Cequence customer with no setup required.
  • Issuer registry: Verification of agent identity against the providers an organisation trusts, alongside Cequence Biometric Check. The registry is protocol-agnostic, so supporting a new agent identity framework means registering a new issuer rather than waiting on a product update.
  • Agent activity log and behavioural analysis: A request-by-request record of what each agent did. Cequence Intent Graphbuilds a behavioral profile of each agent that separates the real agent from an impostor replaying a stolen token.
  • Transaction-level enforcement: Policies that block, rate-limit, or challenge a specific action rather than the agent behind it. For sensitive actions such as changing an account email, Biometric Check lets the account holder confirm on their own device whether they meant for their agent to act.

 

Because Cequence discovers and inventories an organisation’s APIs, Agent Trust knows which endpoints handle login, checkout, pricing, and stock. If an agent that normally checks order status starts pulling price and stock for every product, the platform can stop the scraping while the agent keeps working for its customer.

 

“Every CISO is about to hear the same question from the business, which is whether the company can let AI agents in. Saying no is no longer the safe answer, because customers are choosing agents and will take their spending wherever those agents are welcome. Our job is to make yes the safe answer,” said Ameya Talwalkar, co-founder and CEO of Cequence.

Notes to editors

Availability

Agent Trust is immediately available to Cequence customers as part of Application and API Protection. To learn more or discuss how Agent Trust applies to your environment, request a demo at

https://www.cequence.ai/demo/bot-management

Resources

About Cequence Security

Cequence protects the applications and data that power the agentic enterprise. More than a decade of bot defence and API security experience has established Cequence as the leader of safe and secure agentic AI adoption. The Cequence platform delivers deep insight into user, entity, and agent behaviour, enabling organisations to secure, govern, and control agentic AI workflows while protecting against bad actors and rogue agents. Cequence delivers value in minutes rather than days or weeks with a highly scalable, no-code approach. Trusted by the largest and most demanding private and public sector organisations, Cequence protects more than 10 billion daily API interactions and 4 billion user accounts. To learn more, visit: https://www.cequence.ai/.

Get more news like this

Get more news like this on Google. Set News By Wire as a ‘Preferred News Source’ to get quicker access to news that’s important.

All done!
Thank you for subscribing.

Email Subscription