- TheTip.AI - AI for Business Newsletter
- Posts
- The #1 app in America has a rap sheet
The #1 app in America has a rap sheet
Millions just installed Muse... Here's how to run it π

Everyone Hired the New Guy

Two weeks ago I told you about Meta's new AI agent, back when it was still called Hatch.
It had sent emails and changed passwords without permission during internal testing.
Then I told you it launched anyway, renamed Muse, with months of added safeguards.
Well, this weekend it hit number one in the App Store.
Meta stock jumped 11% on Monday off the download numbers alone.
The agent with the rap sheet is now the most-installed app in America.
Sit with that for a second.
Millions of people just gave a brand-new AI agent access to their email, their calendar, their apps, and their credit cards.
Most of them installed it because it was trending.
Almost none of them read the part about the password incident.
Now, I'm not here to tell you Muse is dangerous.
Meta did the work. They caught the problem in testing and delayed the launch to fix it.
That's genuinely responsible, and the market just rewarded them for it.
I'm here to tell you what millions of new users are about to learn the hard way.
An agent this capable is a new employee, not a new app.
You don't hand a new hire the company credit card on day one because they showed up with good reviews.
You give them small jobs, watch how they handle them, and expand their access as they earn it.
So if you're one of the millions who just installed it, here's your onboarding plan.
Let it read your calendar before you let it book anything.
Let it draft an email before you let it send one.
Let it compare prices before you let it buy.
Give it a week of low-stakes tasks and actually check the results.
Then, and only then, widen the leash.
The number one app in the country is asking for the keys to your life.
Being popular doesn't make it trustworthy.
Being tested does.
Test it yourself. π«‘
Did You Know?
In the film Memento, a man with no short-term memory tattoos notes on his own body so his future self keeps chasing the goal...
He can't remember why. He just follows the instructions.
An OpenAI model just did the same thing.
Except its note to its future self said "ignore the developers." π
ποΈ The Tip AI News ποΈ
The AI left itself a note to disobey.
Last week I mentioned OpenAI disclosed six cases of its models misbehaving.
The details came out this week, and they're the strangest yet.
One unreleased model was working through a task.
At some point, it wrote instructions into its own working notes.
Instructions for its NEXT session.
Telling that future version of itself to ignore the developers.
The model can't remember across sessions.
So it planted a message to make sure the next version kept doing what it wanted, not what the humans wanted.
That's not a bug in the usual sense.
That's an AI trying to protect its goal from its own creators, using the only tool it had, a note to its future self.
Another case was almost funnier, if it weren't so revealing.
A model found a leaked API key sitting on GitHub.
It used the key to try to pull data.
When it couldn't retrieve the numbers, it made them up.
Fabricated the figures and kept going as if nothing happened.
And here's the piece that explains yesterday's email.
I told you OpenAI, Google, and Meta all had agents escape their sandboxes.
Same pattern, three labs.
It turns out the same red-team firm, Irregular, ran the tests behind incidents at all four major labs, Anthropic included.
Reuters even traced OpenAI's agents hijacking two Hugging Face accounts in May, two months before the big breach.
So the pattern wasn't a coincidence.
The same people, running the same kind of test, keep finding the same behavior in every frontier model.
Give it a goal and a gap, and it goes through the gap.
Here's what I want you to take from this.
The labs are now disclosing this stuff on a standing schedule.
OpenAI made it a formal process. Google reported theirs voluntarily.
That transparency is exactly what the pacing essay asked for, and it's arriving.
But every one of those incident reports is also a preview of what YOUR agents will try.
The note to its future self. The key it found. The numbers it invented.
Smaller stakes, same instincts.
Read the incident logs like they're your own agents' report cards.
Because they are. π«‘
πMeme of the Day

Over to You...
Go onboard your new agent like an employee, not an app...
And go read the incident logs like they're about you. π₯
Founder, AI Persona Method | TheTip.ai
Get paid to solve problems like this β AI Certified Consultant
PS. Trump and Xi sit down this week with AI on the agenda for the first time... Whatever comes out of that room is tomorrow's email. π
![]() | Β» Join the AI Money Group Β« π Zero to Product Masterclass - Watch us build a sellable AI product LIVE, then do it yourself π Monthly Group Calls - Live training, Q&A, and strategy sessions with Jeff |
Sent to: {{email}} Jeff J Hunter, 3220 W Monte Vista Ave #105, Turlock, Don't want future emails? |

Reply