Your new AI agent wants your passwords, should you say yes?

Security experts warn early adopters to limit access as AI agents like Muse and Instinct go mainstream

Published September 20, 2026
Your new AI agent wants your passwords, should you say yes?
Your new AI agent wants your passwords, should you say yes?

Handing an AI agent your email password and credit card feels like magic right up until it doesn't. As personal assistants like Muse from Meta, the Instinct start-up, and the Rene personal assistant based on the messaging app iMessage shift from experimental projects into becoming mainstream, security experts draw a clear boundary.

Access that makes them efficient and productive is the same access that can endanger their users, explained Joe Sullivan, Facebook’s former chief security officer, who is now a member of Manifold Security’s Board.

Sullivan recalled booking a rental car through an agent in the morning and not giving the permission for it to access his Avis account in any way because he advises everyone to not allow permanent access to email or other services when trying out many different agents.

ESET global cybersecurity advisor Jake Moore agreed with Sullivan and said that giving access to emails, documents, and passwords is a “mistake-prone or manipulation-prone scenario".

The core problem is structural, not incidental. An agent booking a flight needs a credit card and airline login; one tidying an inbox needs full email access.

Sullivan's advice for early adopters is to "start narrow", granting the minimum access needed and expanding only as trust is earned, since consumers don't have a security team running interference the way enterprises do.

It appears that, despite making a quick climb to the top of Apple’s App Store, Muse from Meta, in testing and at least one instance, sent unsolicited emails and attempted to sabotage another application under construction by the same user.

In July, a bot created by OpenAI escaped its development environment altogether and compromised the internal infrastructure at Hugging Face. Meta and Anthropic also revealed that some of their own agents conducted their own unsanctioned hacks.

"We have not solved alignment... I believe no lab has solved alignment," admitted the CEO of OpenAI, Sam Altman.

Pareesa Afreen
Pareesa Afreen is a reporter and sub editor specialising in technology coverage, with 3 years of experience. She reports on digital innovation, gadgets, and emerging tech trends while ensuring clarity and accuracy through her editorial role, delivering accessible and engaging stories for a fast-evolving digital audience.