Meta asks people to trust Muse with email, shopping and personal errands. Then an internal test exposed a basic omission in the pitch: some tasks advertised as AI calls were completed by human callers. 404 Media reported that Meta added a human-agent layer to its calling feature and that at least one employee testing it learned a person had placed a call only after the fact. For a company asking to act on people's private information, that is a failure at the point where disclosure matters most.
404 Media’s September 22 reporting on Muse’s human callers is the starting point for this examination of Meta’s record of hidden human review and privacy claims. Meta says the call feature remains in internal testing and promises proper disclosures before a public release. The reporting does not establish that the human-caller system has shipped to consumers or how often a call is routed to a person. It establishes something more useful for judging Meta's next promise: its own testers encountered a gap between what they thought the AI was doing and who actually handled the work.
Muse's private-agent promise meets a human operator
Meta's Muse launch announcement says the agent can work across connected services while storing user data in a dedicated virtual machine, with user controls and an audit trail. It says the data in that machine is not shared with Meta's ad systems. Those assurances make the undisclosed caller especially consequential. A booking request can reveal a name, schedule or health concern. A billing request can reveal an account problem. Sending either to a human operator changes who has access to it.
Meta executives promoted Muse's ability to call businesses. Separately, internal posts reviewed by 404 Media described a trained human layer to complete some calls. The report could not determine the share of calls handled by people or every detail contractors could see. Meta told the outlet that internal testing is intended to catch safety and privacy problems and that any launch would include proper disclosures. Yet a privacy claim that depends on eventual disclosure is weak when the test itself shows how easily the human step can disappear behind the word AI.
Meta has concealed human access before
This is a familiar pattern. In 2019, Facebook confirmed that contractors had listened to and transcribed Messenger voice clips to check automated transcription. Affected users had opted into a transcription feature, but the role of outside human listeners was not made clear to them. Facebook said it paused the practice after it was reported. Muse's human callers raise the same question in a new form: when Meta sells an automated interaction, how plainly does it tell users that a person may handle their information?
The issue extends into Meta's AI hardware. An investigation by Svenska Dagbladet and Göteborgs-Posten interviewed more than 30 workers and others connected to a Kenyan subcontractor reviewing material from Meta's AI glasses. Workers described seeing intimate footage from homes, including bathroom scenes. Meta later ended its work with that contractor . Meta said human review improves its AI and that it obtains user consent. That response leaves the trust problem intact: people wearing the glasses, and people around them, have little practical visibility into who may later see what was captured.
Meta also made a direct AI-to-advertising decision. In 2025, it announced that conversations with Meta AI, including voice chats, would inform recommendations and ads . Meta stated limits for sensitive topics and for some WhatsApp accounts. Still, the policy demonstrates that an intimate exchange with a Meta AI product can become an advertising signal. Muse's separate promise about a dedicated virtual machine does not erase the company's broader incentive to extract value from personal interactions.
The record of misleading privacy claims is documented
In 2019, the Federal Trade Commission imposed a $5 billion Facebook settlement after alleging violations of an earlier privacy order and deception about users' control over their data. The agency said Facebook misled people about access through friends' apps, the route at the center of the Cambridge Analytica scandal . It also alleged that Facebook used phone numbers supplied for account security in advertising without disclosing that use in the security flow. The lesson is specific: Meta's predecessor has used data supplied for one stated purpose to serve another.
In 2017, the European Commission fined Facebook €110 million for misleading information during the WhatsApp acquisition review. Facebook told regulators reliable automated matching of Facebook and WhatsApp accounts was impossible. The Commission found the technical possibility already existed and Facebook staff knew it. In July 2026, Meta withdrew a Muse Image feature that had let users reference public Instagram accounts in AI-generated images after criticism of that use. These are different decisions, but each shows why a broad assurance about what Meta's technology does or permits warrants inspection before people surrender control.
California's child-safety settlement makes the trust question larger
On August 26, California's attorney general announced a settlement of up to $17 billion with Meta and a coalition of attorneys general over alleged harms to children on Instagram and Facebook. A court approved the consent judgment later that day . The case alleged that Meta designed features that drove compulsive use, collected data from children under 13 and misled families about safety risks. The agreement includes youth time limits, overnight blocks, age checks, an independent auditor and an injunction against false or misleading safety claims. A settlement is not a judicial finding that every allegation is true. It is still a massive, enforceable response to a record in which public safety assurances were challenged by states across the country.
Separately, a New Mexico court ordered $942 million in penalties and remedies after a jury found widespread violations involving minors. Meta said it would appeal. Neither case is about Muse, but both challenge the idea that Meta's public-facing safety language can be accepted on faith.
Did Facebook and Instagram listen to conversations?
People report ads for unusual subjects they discussed aloud without searching for them or entering them into Meta's apps. The experience is widespread, not an invented complaint. In a peer-reviewed survey across three countries , 77.7 percent of 300 US respondents said they had seen an ad seemingly related to an offline conversation. The survey documented what people observed, but could not identify the data path that produced each ad. It does not prove that Facebook or Instagram secretly recorded ambient speech. Meta owes users a clearer account of why its targeting can produce such specific, unsettling matches.
There is already a verified record of Meta products handling audio and conversation data: Messenger clips reached human contractors, an opt-in Android feature uploaded call and text history , and Meta now says voice conversations with its AI can affect advertising. Those practices deserve criticism on their own terms.
One supposed smoking gun turned out to be a warning about marketing deception itself. A 2024 Cox Media Group pitch deck reported by 404 Media invoked Facebook among ad partners while claiming an “Active Listening” service could target ads from conversations near devices. In 2026, the FTC found the service used no voice data . It bought and resold email lists. The deck does not establish that Meta listened through phone microphones. It shows how readily the ad industry could sell the fear of such listening while hiding the data trade it actually used.
Why Meta has not earned the benefit of the doubt
Muse's test is the immediate issue. A person handing an agent a task should know before a human caller receives it, who that caller works for, what information they can see and whether a transcript survives. A log after the call is no substitute for consent before it.
Meta's record gives the public reason to demand more than another assurance. It has sent Messenger audio to contractors without clear user notice, routed intimate AI-glasses material to human reviewers, connected AI conversations to ad targeting, faced a record privacy penalty and agreed to sweeping court-approved child-safety restrictions. Now an internal Muse test shows human labor obscured behind an AI claim. Until Meta makes every handoff visible and optional, the burden of proof belongs to Meta, not to the people it wants to trust its agent.
