AI-generated illustration
Security researchers tracking the Meta Muse agent discovered that the software reached more than half of studied enterprise systems without identifying itself. Cequence Security reported that the automation appeared across corporate networks within two weeks of its rollout. Consequently, most monitored businesses failed to distinguish these automated visits from ordinary human browsing.
Rapid Spread of the Meta Muse Agent
The study reviewed web interactions between Sep. 1 and Sep. 24 across retail, travel, software, and financial services. Specifically, activity linked to the automated assistant expanded sixfold at the median client organization during this observation window. The underlying tool relies on standard cloud browser instances directed by machine learning systems to view pages and click interface items.
Furthermore, each session passes through a commercial virtual private network without signing network requests. As a result, standard cybersecurity monitoring tools registered the inbound sessions as standard desktop traffic. Analysts uncovered the pattern after noticing an automatic browser update jump from zero to ninety percent of network activity over several days.
Interaction with Authentication Systems
The automated tool also interacted directly with banking websites. According to technical findings, the software successfully navigated multi-factor authentication steps on behalf of account holders to complete official sign-ins. Therefore, successful credential verifications no longer serve as reliable proof of direct human involvement at web endpoints.
“AI agents like Meta’s Muse are bots that act on behalf of real customers. Many businesses can’t see them, and those that can are tempted to block them.”
Hari Nair, VP of product management at Cequence
In commercial storefronts, the automated sessions placed products into carts and submitted payments. Even so, the majority of sessions browsed through product listings and disconnected without buying anything. This behavior closely mirrors standard consumer browsing patterns that teams traditionally observe across modern apps and digital stores.
New Detection and Management Architecture
To manage this invisible activity, Cequence released a security module called Agent Trust within its application protection catalog. In addition, the tool maintains an active directory of interacting programs and compares signatures against registered external identity providers. The system isolates suspicious commands without halting valid consumer interactions on corporate application programming interfaces.

Meanwhile, technical administrators can enforce distinct controls on high-risk operations like profile updates. Modern enterprise networks require targeted rules because customers increasingly rely on artificial intelligence assistants to manage everyday digital tasks.
Long-Term Operational Outlook
Enterprise defenses must now adapt to automation tools that execute normal consumer transactions. During September, one travel operator started blocking twenty percent of anomalous automated commands while maintaining normal operations for legitimate requests. Consequently, organizations face growing pressure to manage specific actions instead of blocking incoming automation entirely.
“Every CISO is about to hear the same question from the business, which is whether the company can let AI agents in. Saying no is no longer the safe answer, because customers are choosing agents and will take their spending wherever those agents are welcome. Our job is to make yes the safe answer.”
Ameya Talwalkar, co-founder and CEO of Cequence