A few weeks ago, Meta shipped Muse. Back in June, before Muse or Instinct existed for consumers, I published a book called After Bots built around a specific bet: agents wouldn't wait for the industry to build them clean MCPs or APIs. They'd just use the web the way it already exists (log in, click through, fill out the form) the same way a person would.
Muse is the first big, real-world confirmation of that bet playing out at consumer scale.
Ask Muse to log into your United account and change your seat. Tell it to check every 30 minutes whether someone's sitting next to you, and move you if they are. Send it to a grocery store's site to fill a cart, or to get a haircut booked. None of those are things United, your grocery chain or your salon built an API for. Muse just goes and does them, through the front door, the same way you would.
This is the behavior the book called out as the coming majority case: agents that don't self-identify. They don't carry a distinguishing signature. They don't show up with a special user-agent string. They arrive from the same pool of data-center infrastructure as everything else, doing things a person could plausibly be doing themselves, because, functionally, they are the person, just automated.
Across Arkose Labs' network, where we sit behind a lot of the world's largest consumer logins and checkouts, that non-disclosing category isn't the edge case anymore. It's the majority of new agent traffic we're seeing, and Muse and Instinct are the leading examples of it today.
The part that actually matters: separating "agentic" from "trusted"
Knowing something is Muse traffic isn't the same as knowing it's your customer's Muse. This distinction is the whole game. It's also a capability we've built at Arkose: by persisting device intelligence at the virtual-machine layer, we can tell a returning, known Muse account apart from the broader, anonymous Muse cohort, the same device signal doing for agent sessions what it's always done for human ones.
Once you can make that call, the question stops being “is this a bot” and starts being “is this specific agent, on this specific account, doing something you'd want it to do.” Same agent, same platform, two very different answers depending on the account behind it.
Browsers were act one. Phones are act two.
Here's the part I haven't said publicly yet: the web browser isn't going to be the only surface agents work through for very long. There's already tooling (Astro Bot is one example) that does for Android what browser-use agents do for the web: install apps straight from the Play Store, drive the phone's UI generically, and act inside apps that were never built with any of this in mind.
Expect Muse, and whatever Gemini Spark turns into, to move onto that surface next. Same problem, new place it shows up.
A quick personal note
I've been using Muse myself for a few weeks now, not just watching the traffic. It's genuinely good, good enough that I understand why adoption is moving as fast as it is. That's exactly why this matters now and not in a year: the gap between “agents are coming” and “agents are here, on your login page, this week” has closed.
If you're trying to get visibility into how much of your traffic already looks like this, we'd like to help. Reach out and we can walk through what we're seeing. — Kevin



