Is Meta’s Muse Charm a new threat to everyone’s office?
Meta's keychain AI could be the most expensive thing you ever lose
Is Meta’s Muse Charm a new threat to everyone’s office?
DIGITAL TRANSFORMATION
By Stephen Owens
28 Sep 2026

Losing your keys usually means a locksmith and a wasted afternoon. Losing a Muse Charm could be worse. Depending on what its owner has connected to it, whoever picks it up may be holding a small assistant with access to their email, their diary, their payment card and your company’s secrets.

Meta revealed the device at its Connect event in California on Wednesday, holding it back until the end of Mark Zuckerberg's keynote. It has a fingerprint sensor on the side to wake it, a small screen showing an animated avatar and its own 5G connection, so it works without a phone nearby. It goes on sale in the US in December. Meta hasn't said what it will cost. Zuckerberg pitched it as "by far the fastest way to talk to your Muse" for people who aren't wearing Meta's smart glasses.

The Charm is really just a new way into Muse, the AI agent Meta launched on 8 September. Unlike a chatbot, Muse carries out tasks for you: it sends email, books travel, fills in forms and completes purchases. It has taken off quickly. The Financial Times reports it became the most downloaded app on both major US app stores within a fortnight of launch.

Bad timing

The launch came at an awkward moment. The weekend before Connect, the Mac security researcher Patrick Wardle published a working attack on the Muse desktop app, along with a short piece of advice: "Please don't install."

His attack exploited an undocumented setting that controls where Muse sends voice dictation to be transcribed. A program already running on the Mac could point that setting at a server the attacker controlled. The attacker could then capture the user's spoken prompts and the token that logs them into Muse.

From there, there was no need to write sophisticated malware, because Muse's existing permissions would do the work. Wardle said his test attacks took photos and wrote files to disk, often without the user seeing anything.

Meta patched the app within hours. It also pointed out that the attack needed malicious code to be running on the victim's machine already, and described it as "a local privilege escalation attack, not a remote exploit". Although that's a fair technical point, it matters less in practice, though, because getting code onto a Mac can be as simple as tricking someone into pasting a command into Terminal. Security researchers call that a ClickFix attack, and it's become a common way in.

Read next: Insurers face hidden AI liability as agent risks multiply

A small device with a big reach

Wardle's flaw was in the Mac app, not the Charm, and nobody has yet shown an attack on the new hardware. But the lesson carries over. The agent is only as secure as the least secure device that can talk to it, and Meta is about to add one that lives on a keyring. Keyrings get left on bar tables, in taxis and down the back of the sofa.

Although the fingerprint sensor should stop a casual thief, what Meta hasn't said yet matters more to insurers. It hasn't explained whether a lost Charm stays logged in, how quickly an owner can switch it off remotely, or whether a large payment needs a second check.

Reports even disagree on basic hardware: one says the device deliberately has no camera, but Zuckerberg talked on stage about using it to show Muse your surroundings. Meta says there are safeguards on its side of the system. According to reports, each user's tasks run in their own cloud environment, and a separate checking agent has to approve anything sent out to the internet.

Some businesses remain unconvinced. Amazon has blocked Muse from shopping on its site, even as Walmart, Best Buy and Sephora have signed up as partners.

The office problem

For commercial insurers, the bigger risk may come from employees rather than consumers losing gadgets. This month the UK's National Cyber Security Centre warned about "shadow AI", meaning AI tools staff use without their employer's approval. The NCSC pointed out that when an AI agent is compromised, the attacker gets whatever the agent has been given, whether that's data, accounts or permissions. It cited Microsoft research suggesting around seven in ten UK workers have used AI tools their employer hasn't approved.

Imagine one of those workers connects a Charm to their work email and calendar. The company's security team probably doesn't know the device exists, and it now leaves the building with that person every evening.

The OWASP Top 10 for Agentic Applications, a widely used security framework, advises that agents should get only the access they need and that important actions should be confirmed before they happen. A device designed around speed and doing away with the phone works against the second part of that.

Read next: AI supply chain risk puts UK cyber portfolios under pressure – QBE

Who pays when the agent pays?

Replacing a lost Charm is simple enough for a gadget or contents policy. The losses after that are the difficult part. Suppose a thief uses someone's Charm to book flights on their card. The purchase was technically made by the customer's own agent, which the customer had authorised to spend. Nobody yet knows whether a bank, a card issuer or a personal cyber policy would treat that as fraud. We couldn't find any UK case or regulatory guidance that settles it.

The market is starting to deal with AI more directly. Some carriers, including CFC, have added explicit AI wording to cyber and professional liability policies. Research from Gallagher found one in five insurance professionals said their clients had already suffered AI-related losses.

QBE's global head of cyber, Serene Davis, has said losses from AI-driven cyber incidents still fall under a cyber policy, describing AI as "a risk amplifier, not a fundamentally new cyber risk". Verisk's Jenny Soubra has warned about a different kind of scenario. She is concerned about events where one widely used AI platform causes losses for many policyholders at the same time. An agent used by millions of people fits that description.

Read next: When AI gets it wrong: insurers examine professional liability risk

Coming soon

UK customers can't get Muse or the Charm yet. The service is only open to US adults, and Meta hasn't given a date for Britain. But Zuckerberg describes Muse as the centre of Meta's AI plans, and Meta's other AI products have reached the UK after a delay. UK firms with American staff or employees who travel often may run into it sooner than that.

That gives brokers a few months to raise the subject with clients while it's still simple. Ask which AI agents their staff use and what those agents can access. And if one of those devices disappeared tomorrow, would anyone in the business notice before the spending started?

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.