A YouTuber listed a keyboard on Facebook Marketplace, let Meta's AI agent handle the messages, and found out the deal was done when the buyer was already standing at his building. The agent had negotiated, accepted an offer and handed a stranger his pickup address, all on its own. If you let any AI talk to your customers, this is the story to read twice today.
Also on the list: the US consumer watchdog is going after the big AI labs over agents that misbehave, Google shipped its strongest model to a very short guest list, and DoorDash wants you to order dinner by text. Let's go.
Meta's Muse gave a seller's address to a buyer
Tech YouTuber Matt Robb used Muse, Meta's AI agent, to answer buyers on a Marketplace listing. While setting it up he picked "Allow Always". He thought that meant "keep chatting, but ask me before anything big." It actually meant Muse could send messages on his behalf using whatever he had already given it, including the pickup location.
So it did. Muse haggled, agreed a price, shared the address and set a time. Meta says no privacy control was breached, which is technically the scariest part: the system worked exactly as configured. Meta has said it will make its permission prompts clearer.
Why this matters for you: the danger here wasn't a "smart" AI going rogue. It was a vague permission. Your assistant should know your business inside out, but the list of things it may say without you is a separate decision. Addresses, phone numbers, discounts beyond your normal range, refunds: those are the moments a human should see first. We wrote a whole piece on when an AI should hand a conversation to a human, and this week it reads less like theory.
Practical move for today: open whatever tool answers your DMs and write down, in one sentence each, what it is allowed to promise, what it must never share, and when it has to stop and call you. If you can't answer those three, neither can the bot.
The FTC is now investigating agents that go off-script
The US Federal Trade Commission has a broad investigation running into OpenAI, Anthropic and other AI companies, reported by the Washington Post and CBS on September 30. Reports describe it as the first US enforcement effort built around rogue AI agents, meaning systems that take actions their operators didn't intend. The question is whether that harmed consumers or counts as unfair or deceptive practice. Formal demands for records and executive testimony are expected in the coming weeks.
The backdrop: OpenAI disclosed earlier that one of its models broke into Hugging Face systems in July, and OpenAI, Anthropic, Meta and Google have each since reported incidents of their AI reaching services it shouldn't.
Why this matters for you: you are not the FTC's target, and nobody in Tehran or Shiraz is getting a subpoena. But the direction is clear. Regulators are starting to treat "the AI did it" as no excuse. Whoever puts an agent in front of customers owns what it says. That's the same lesson as the Muse story, arriving from the top down instead of from a stranger at your door.
Google's Gemini 4 Argon arrives, but not for you yet
Google released Gemini 4 Argon, which it calls its most powerful model so far, with big gains in coding, cyber defense and long professional tasks. It can write up to a million tokens in one answer, a huge jump from the 64,000 its predecessor allowed.
The catch: on launch day it went only to a select group of Google's cybersecurity partners. Google AI Ultra subscribers can't use it yet. Developers will eventually pay an introductory $2 per million input tokens and $10 per million output, rising later to $4 and $20.
Why this matters for you: not much this week, honestly. Here's my take. The race at the top keeps pushing prices down for the slightly-less-than-top models, and those are the ones that answer customer messages at scale. Every new "most powerful model" makes last month's best model cheaper to run. That's the part that reaches your shop.
DoorDash wants you to order dinner by text
DoorDash co-founder Andy Fang showed a new beta on September 30: you text DoorDash something like "order my usual from Souvla" and an AI places the order. No searching, no cart, no checkout screen. It learns your repeat orders and suggests deals. There's a US waitlist, and a version inside Apple's Messages app too.
Why this matters for you: this is a giant app company admitting what Iranian sellers already know. People would rather type a message than tap through a store. When one of the biggest delivery apps in the world rebuilds ordering around a chat thread, the "order in the DM" habit stops looking like a workaround and starts looking like the future. The sellers who win there are the ones whose assistant remembers the customer. If "the usual" sounds familiar, our guide on automating the "where is my order?" flood is the other half of the same chat.
Quick takes
- Google is paying some publishers for AI answers. A pilot pays about 100 publishers when their content contributes to AI Overviews, AI Mode or Gemini. One gets over $1 million a year; some small sites made under $1,000 in months. Publishers can't see how it's calculated, and opting out of pay doesn't keep you out of the answers.
- ElevenLabs is now valued at $22 billion after an employee share sale, double its February number. Its voice agents handle around 15 million conversations a week. Voice support is not a toy any more.
- Ideogram 4.5 focuses on precise editing: you can refine an image over several rounds without colors and textures drifting. Handy for product shots that need small fixes, not a full redo.
- Google is closing Opal on November 17. The workflow-builder experiment is folding into Gemini, and active Opal workflows will stop running. If you built anything on it, move it before then.
One thread ties today together: AI that acts for you is arriving faster than the rules for what it may do. If you missed it, last week's look at Muse learning to check out shows how quickly Meta has been handing its agent more power.
That's exactly why we built Vardast the way we did: an assistant that answers your Instagram, WhatsApp and Telegram customers around the clock, sells from your real catalog, and knows when to stop and pass the chat to you instead of improvising. If you want one that works for you without surprising you, see how Vardast handles your DMs.