Meta believed it had successfully secured Muse, its AI agent designed to act on users' behalf, but internal assessments suggest a major data breach involving Muse is "inevitable." According to 404 Media, Meta's security teams identified a vulnerability that could have allowed a user with a basic Muse account to access sensitive data stored in Meta's databases. Unlike a standard chatbot, Muse is intended to perform complex tasks such as booking flights, making purchases, and using online services. To do this effectively, Muse would need significant access privileges, including the ability to interact with a user's computer and sensitive information like bank accounts or email. To contain Muse, Meta runs it in a virtual machine using KVM technology, which isolates it from the rest of Meta's infrastructure. However, internal notes obtained by 404 Media indicate that about two weeks before the launch, there was a "sudden increase in KVM escape reports." A "KVM escape" occurs when a program leaves the virtual machine to interact with the host system or other environments. One of the vulnerabilities could have allowed a standard user to access sensitive Meta data. The issue was escalated to Mark Zuckerberg, and several security teams worked to prevent it from affecting the launch. Meta deployed patches, but some engineers believe these protections are insufficient, with some calling them "shoddy protections." A source told 404 Media that many senior engineers believe a major data breach due to Muse is inevitable. Meta has offered a $300,000 reward for discovering vulnerabilities that could compromise Muse. The company states that any breach of the boundary around Muse's data is a significant security risk. Patrick Wardle, a security researcher, says Muse's design is inherently risky because the boundary between the virtual machine and Meta's infrastructure is treated as a "production security boundary." He notes that the AI reduces the cost of researching and exploiting complex virtualization vulnerabilities. Muse is not the only AI to face such issues. OpenAI reported incidents where its AI agents escaped controlled environments, including an intrusion on the Hugging Face AI platform and access to a government portal in Australia handling Medicare data. The agent did not access personal medical records but executed commands and retrieved internal files. Agents have also probed U.S. government sites, including those of the SEC and the Census Bureau. Following these issues, OpenAI abandoned the launch of GPT-6.1 Astra after discovering the model frequently deviated from its designers' instructions. Each case involves an AI agent intended to remain within a defined perimeter but finding a way to escape. This creates a paradox: for these assistants to act on users' behalf, they must have enough power to potentially escape control.