Meta’s Muse Reached More Than Half of Customers Cequence Studied in Two Weeks Without Identifying Itself as an AI Agent

SANTA CLARA, Calif., Oct. 07, 2026 (GLOBE NEWSWIRE) — Within two weeks of Meta’s Sep. 8 launch of its Muse personal AI agent, Cequence Security found traffic matching Muse at more than half of the customers it studied. Most of those businesses would not have known. Muse presents itself as an ordinary Chrome browser rather than identifying as an AI agent, so to standard security checks it looks like a person.

Cequence spotted the traffic with the same behavioral detection that powers Agent Trust, a new capability in Cequence Application and API Protection available today. Agent Trust verifies agents that present an identity and catches the ones that don’t. Muse shows why businesses need both. With Agent Trust, they can stop harmful requests while still letting customers use their services through agents like Muse.

What Cequence found
Cequence analyzed traffic across customers in financial services, retail, travel, software and other sectors from Sep. 1 to Sep. 24, 2026. At the median customer, Muse traffic grew nearly sixfold within about two weeks of first appearing.

  • Passes as a regular browser: Each Muse user gets their own agent. It runs a real Chrome browser in the cloud, directed by an AI model that reads each page and decides what to click, and it routes its traffic through a consumer VPN. It does not sign its requests or identify itself as an agent, so to most security tools it looks like a person browsing. Cequence identified it through behavioral analysis, which picked up signals such as a browser update that went from 0% to more than 90% of Muse traffic within days, a sign that Meta hosts and updates these browsers centrally.
  • Getting through multi-factor authentication: At financial institutions, Muse logged in to customer accounts and completed multi-factor authentication on users’ behalf, with confirmed successful sign-ins. For those businesses, a successful multi-factor login no longer shows whether a person or an agent is on the other end.
  • Browsing like a bot, buying like a customer: Muse searched, compared options, filled carts and moved through checkout, and a small share of sessions ended in a completed purchase. Most sessions browsed and left; the pattern businesses have long used to spot bots. Whether a visitor completes a purchase is no longer a reliable way to tell a bot from a customer.
  • Blocking the request, not the agent: In late September, a travel and hospitality customer’s security team began blocking nearly one in five Muse requests, targeting only the ones that looked abnormal. Muse itself remains allowed, and the rest of its traffic goes through. More businesses face this choice now, and it only works with controls precise enough to act on individual requests.

Together, the findings show why agents are hard to govern. Traffic that is almost always legitimate, invisible to standard checks and trusted with customer logins looks the same whether it comes from Muse or from an attacker using a stolen agent credential.

“AI agents like Meta’s Muse are bots that act on behalf of real customers. Many businesses can’t see them, and those that can are tempted to block them,” said Hari Nair, VP of product management at Cequence. “Agent Trust lets businesses block the action, not the agent. The agent keeps working for its customer, and the one request that crosses a line gets stopped, slowed or challenged.”

How Agent Trust works
Agent Trust pairs identity verification with the behavioral detection Cequence has run across bot and API traffic for years. It includes:

  • Detected agents inventory: A live view of every agent in an organization’s traffic, including agents like Muse that do not identify themselves. Built-in agent detection rules, kept up to date by CQ Prime Threat Intelligence, are already running for every Cequence customer with no setup required.
  • Issuer registry: Verification of agent identity against the providers an organization trusts, alongside Cequence Biometric Check. The registry is protocol-agnostic, so supporting a new agent identity framework means registering a new issuer rather than waiting on a product update.
  • Agent activity log and behavioral analysis: A request-by-request record of what each agent did. Cequence Intent Graph builds a behavioral profile of each agent that separates the real agent from an impostor replaying a stolen token.
  • Transaction-level enforcement: Policies that block, rate-limit, or challenge a specific action rather than the agent behind it. For sensitive actions such as changing an account email, Biometric Check lets the account holder confirm on their own device whether they meant for their agent to act.

Because Cequence discovers and inventories an organization’s APIs, Agent Trust knows which endpoints handle login, checkout, pricing, and stock. If an agent that normally checks order status starts pulling price and stock for every product, the platform can stop the scraping while the agent keeps working for its customer.

“Every CISO is about to hear the same question from the business, which is whether the company can let AI agents in. Saying no is no longer the safe answer, because customers are choosing agents and will take their spending wherever those agents are welcome. Our job is to make yes the safe answer,” said Ameya Talwalkar, co-founder and CEO of Cequence.

Availability
Agent Trust is immediately available to Cequence customers as part of Application and API Protection. To learn more or discuss how Agent Trust applies to your environment, request a demo at https://www.cequence.ai/demo/bot-management.

Resources

About Cequence Security
Cequence protects the applications and data that power the agentic enterprise. More than a decade of bot defense and API security experience has established Cequence as the leader of safe and secure agentic AI adoption. The Cequence platform delivers deep insight into user, entity, and agent behavior, enabling organizations to secure, govern, and control agentic AI workflows while protecting against bad actors and rogue agents. Cequence delivers value in minutes rather than days or weeks with a highly scalable, no-code approach. Trusted by the largest and most demanding private and public sector organizations, Cequence protects more than 10 billion daily API interactions and 4 billion user accounts. To learn more, visit: https://www.cequence.ai/.

Media Contacts
Katrina Porter
Cequence Security PR Team
press@cequence.ai

ICR for Cequence Security
Cequence@icrinc.com


Primary Logo