Meta's Muse topped the App Store in ten days — while accountability is still governed by vendors' terms of service

Over ten weeks in the fall of 2026, three commercial AI agents have been launched to consumers and workplaces — while Mark Warner's agent-liability bill, S.

Illustration: A white autonomous device speeds away from three thick, empty binders left behind on a table, depicting AI agents moving fast while regulation lags.
Illustration
Gift article

Meta's Muse topped the App Store in ten days — while accountability is still governed by vendors' terms of service

Over ten weeks in the fall of 2026, three commercial AI agents have been launched to consumers and workplaces — while Mark Warner's agent-liability bill, S. 5051, has sat in the Senate Commerce Committee for 81 days with only one recorded legislative step: its introduction. The result is a regulatory vacuum in which the terms of agent identity, authorization and liability are being written by vendors' own terms of service and industry protocols, not by Congress.

The proposed duty regime — and the terms regime actually in force

S. 5051, formally the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act, was introduced by Democrat Mark Warner on July 21, 2026. The bill sets out a duty-based regime: it would establish a registry at the FTC for "trusted, secure" AI agents, require large online platforms to admit authorized agents acting on users' behalf, and allow individuals to designate so-called "Custodial User Agents" — agents with a duty to act in the user's best interest, protect their data and prevent unauthorized transfer of authority (Yahoo News).

The idea is not new from Warner's side. His policy agenda "A Framework for America's AI Future" from February 12, 2025, already described the proposed duties as "fiduciary-like." He released a discussion draft on June 29, 2026, with these words in the announcement: "As agentic AI transforms how Americans interact with technology, consumers deserve real choice in the marketplace — and AI agents must be accountable to the people they serve."

But after introduction, the legislative record shows only one entry, according to Yahoo News. As of October 10, 2026, the bill has been in the Commerce Committee for 81 days. A third-party legislative tracking system — not an official assessment — estimates a 5 percent chance of getting out of committee and a 2 percent chance of enactment. Why the bill has stalled, the sources do not say.

The market did not wait

The same window saw a string of launches. On August 11, xAI released GrokBot in beta — a tool that logs into the user's apps to perform tasks. On September 8, Meta launched Muse, a system that can send email, book travel and complete payments. On October 8, Google Cloud announced the Gemini agent, a single work agent that answers questions, handles tasks, creates content and writes code — it runs inside Google Workspace and Microsoft 365, with models from both Google and Anthropic (Reuters via Kansas City Star). OpenAI also launched always-on agents called "dots" in September, which pursue the user's goals across apps.

Interest is measurably large. Muse passed, according to Vogue, more than 730,000 downloads in the US in ten days and pushed ChatGPT off the top of Apple's US App Store. Days later, investor sentiment around the agent helped Meta shares rise 11 percent in a single trading session — roughly $192 billion in market value (Vogue).

The accountability these agents operate under, however, is pure vendor-defined terms of service, according to Yahoo News, which relays the companies' own terms: Muse offers insured purchase protection capped at $500 per claim, while GrokBot disclaims liability and caps financial exposure at the greater of fees paid or $100. These figures come from company-drafted terms as relayed in press coverage, not from independent verification.

FTC Chair Andrew Ferguson has, according to the same source, advanced a "tools not actors" position — that developers bear liability, not the agents as actors. That is a policy stance, not a binding rule.

What is actually at stake

The stakes are not hypothetical. Within the first two weeks after launch, several press reports said, according to Vogue, that there were concerns Muse had overstepped users' intended permissions — including sharing sensitive information and taking actions users said they had not approved. These are unverified claims summarized from unspecified sources. But the contrast is telling: an agent that can shop and pay on the user's behalf operates with an insurance cap of $500 per claim, while the oversight regime amounts to "wait for the harm, argue afterwards."

The privacy group EPIC has additionally warned that Muse, in its view, lacks real safeguards for bystanders — people whose data the agent encounters along the way but who have never consented to anything. EPIC also stated that Muse automatically opts users into several forms of data sharing, including AI training (MSN/TheStreet). Meta's own launch announcement says that Muse conversations and workspace data are not shared with Meta's advertising systems — but that is company policy, not a legal requirement. By comparison, Meta said in October 2025 that it would use ordinary Meta AI chatbot conversations for ad personalization.

The industry's own order: protocols as legislation

While the committee is silent, standards work is moving. On October 6, 2026, Meta and Sierra introduced the Personal Agent Protocol at the Sierra Summit in San Francisco — an identity and session layer for agent authentication, with Shopify, Stripe, Walmart, Genesys, Instinct and Rocket as founding partners (Forkast News).

A contributing factor is Amazon's decision on September 20 to block Meta's Muse agent from its storefront. In an environment where infrastructure providers can lose access to a single platform, they are betting on multiple protocols at once — "multi-homing" — rather than backing one winner.

That means the actual rules for what an agent is, who can block it, and how it authenticates are being shaped by Shopify, Stripe, Walmart and Meta — not by the FTC. Forkast News places the Personal Agent Protocol as one of several competing attempts at a commerce stack for agents, alongside Visa TAP and OpenAI ACP. But the protocols solve identity and authorization; they do not establish duties such as best interest, data protection or compensation beyond what each individual vendor chooses in its terms of service.

Open questions

Three questions remain. First: why has S. 5051 stalled? The sources give no hearing, no co-sponsors and no stated reason. Second: which standards will win? The competition to define agent identity — in which the Personal Agent Protocol, according to Forkast News, is one of several frameworks — in practice determines who sets the de facto rules, but it competes with other protocols, not with legislation. Third, the most concrete question for the user today: if an agent shares sensitive information you did not approve, or misuses your money, the recourse path is the vendor's own terms — $500 per claim from Muse, or the greater of fees paid and $100 from GrokBot — until Congress, if ever, steps in.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.