The first consumer scale agent has arrived

Read more
← Video Library
/
Agentic AI
/
Spotting AI Agents Like Muse
4:18
Agentic AI

How Do You Spot AI Agents Like Meta's Muse?

Most AI agents on your site will never tell you they're there.

4:18
Sept. 29, 2026

Meta's Muse can log in to an airline account, change a seat and keep checking for a better one, all without an API or MCP. Arkose Labs founder and CEO Kevin Gosschalk explains why agents like Muse mark a shift for bot traffic and how businesses can identify them, recognize returning accounts and judge their intent.

KG
Kevin Gosschalk
CEO & Co-Founder, Arkose Labs

Kevin Gosschalk founded Arkose Labs in 2016 and serves as CEO, building the leading platform for agent trust and control.

Key Takeaways
1:02

These are the kind of things it can do autonomously; there was never an API or an MCP made available by United.

1:38

The majority of usage is this non-disclosing agent category. And this is agents like Muse, like Instinct, and many others that go do work autonomously and they don't announce themselves.

2:04

So they don't have a signature, they don't have a special user agent, they're coming from indistinguishable data centers and those kind of things.

4:01

I've been using Muse for many weeks, and yeah, the technology is really quite phenomenal, but a lot of companies are asking the question like, OK, well, we want some visibility to that.

Full Transcript
KG
Muse and the shift for bots
0:00

Hey everyone, it's been now a few weeks since Meta's Muse was released, and really I think people are starting to get their heads around how much of a paradigm shift this is going to be for the bot landscape.

So, the start of this year, I released my book on Agent Trust, and it hypothesized this idea of why would agents need to use MCPs or APIs if they could simply just browse the pre-existing web as it is today, or install apps by itself and go and autonomously use these systems.

KG
Agents that use the web as it is
0:35

And that's really now what we're seeing. So Muse was the first of these, where it's a basic chatbot, you can ask it any question you want. "Hey, go log in to my United account, change my seat, change my flight." It can be given your preferences, if there's a specific seat you prefer, you can tell it, "Hey, every 30 minutes, check to see if someone's sitting next to me, and if they are, move me to a seat where no one is sitting next to me."

These are the kind of things it can do autonomously; there was never an API or an MCP made available by United.

It can access grocery stores, it can, you know, get a haircut organized for you, and it just does this through the pre-existing web as we know it.

KG
3 populations of agents
1:18

And what the book I authored kind of talks about is this idea of these three populations of agents.

So you've got agents that self-identify themselves, and this is really where the industry was hyper-focused, the idea of, well they're gonna use the pre-existing MCP or APIs that we create, we'll have clean guardrails and all that good stuff.

But in reality, what we are seeing, especially across our network at Arkose where we work with some of the largest consumer applications in the world, and we really do see a great bird's eye view of what's going on, is the majority of usage is this non-disclosing agent category. And this is agents like Muse, like Instinct, and many others that go do work autonomously and they don't announce themselves.

So they don't have a signature, they don't have a special user agent, they're coming from indistinguishable data centers and those kind of things.

KG
Identifying non-disclosing agents and their intent
2:12

Of course, with the right technology stack, like what we have at Arkose, you are able to kind of pierce through that veil and still identify them uniquely.

We can also persist things like our Device ID information on the virtual machines, which let us also identify unique returning Muse accounts, separately from like the giant cohort of agentic Muse traffic. Which is very important to answer the next question, which is, "OK, if I'm going to enable agentic commerce, and I'm going to allow Muse to interact with my workflows, how do I make sure it doesn't commit fraud or do anything malicious?"

So these additional signals that we're also able to expose start piercing to the question of intent, so like, yes, it is agentic, yes, it may be Muse or Instinct, whatever it may be, but this specific user is doing things in a way you don't like them, or don't want them to do it, then this cohort of traffic is doing the correct thing.

So, you know, this is really kind of where we are very focused at Arkose.

KG
What's next: agents on apps and virtual phones
3:08

And when we launched the Arkose Agent Trust Manager several months back, we hypothesized that this is the kind of web, or even the app ecosystem, which will be next.

Today they are interacting with the web through web browsers. But there are already the ability to install and emulate virtual machines using virtual phones.

So for instance, Astrobot can be used to, it's kind of like an open core equivalent for Android apps, so it can install apps, it can use the Play Store, those kind of different things, and it can generically interact with the phone UI as well.

So that'll likely be coming soon for agentic systems like Muse and others, like Gemini Spark and things.

KG
Why companies want visibility
3:49

But it's really a very exciting time when it comes to bots because there's so many new ways to think about consumers using these for great things, like we've had a lot of employees using Muse.

I've been using Muse for many weeks, and yeah, the technology is really quite phenomenal, but a lot of companies are asking the question like, OK, well, we want some visibility to that. And that's something we can help with if you're interested in partnering.

Thank you.

Up next
Want to talk through your agentic traffic policy?
Our team can walk through how intent-based detection applies to your specific fraud vectors.
Talk to Arkose Labs