Imagine you are sitting at your kitchen table, staring at a screen that promises to handle your life. It wants your email, your calendar, and your payment credentials. It says it will manage your subscriptions, book your travel, and keep your digital house in order. Now, imagine that screen belongs to a company that has spent the last decade paying billions in privacy settlements. Do you click “Authorize,” or do you close the laptop?
This is the reality facing Meta’s Muse, a $20-a-month agent that requires deep access to your most sensitive personal data. While the engineering team has built a genuinely sophisticated security architecture—using dedicated Linux VMs, a Sentinel approval agent, and credential isolation so the agent never actually sees your raw passwords—it is missing the point. Consumers do not evaluate architecture. They evaluate brand history.
The Trust Gap is Not a Bug
The data is stark. According to an Oppenheimer & Co. survey of 1,500 US consumers, when asked who they trust with their passwords, only 8% pointed to Meta. Compare that to 30% for Google, 23% for Apple, and 16% for ChatGPT. Even more telling, 58% of respondents flatly refuse to share their passwords with any AI agent at all.
This isn’t just about one company’s PR problem. It is a structural deficit built on a foundation of high-profile failures: the 2012 FTC consent decree, the 2018 Cambridge Analytica scandal that exposed 87 million users, a $5 billion FTC penalty, and a $725 million class action settlement. When you have a history like that, no amount of “Secure VM” marketing can bridge the gap. The trust deficit is baked into the brand, and it is not something a product design team can patch away.
The Broader Agentic Hangover
Meta isn’t the only one hitting this wall; the entire household agent category is struggling with the same skepticism. A Visa Earning Trust Report found that only 23% of consumers trust generative AI for payments. Perhaps more importantly, 85% of users demand data visibility and control, and about half say they would stop using an agent entirely if they felt they lost that control. Across the board, 60% of consumers refuse to let AI handle money without human oversight, and 47% have already canceled or switched brands due to data concerns in AI contexts.
For builders and investors, stop looking at the tech stack and start looking at the user’s inbox. We are seeing a convergence of protocols, as discussed in MCP convergence, and a push for more integrated experiences, like Muse for macOS. But these technical advancements are hitting a wall of consumer skepticism. If users don’t trust the entity behind the agent, they won’t grant the permissions required to make the agent useful.
The Money Question
The industry is currently obsessed with the plumbing of autonomous commerce—who pays when things break, and how we build secure rails, as seen in Europe. But the real bottleneck isn’t the rails; it’s the relationship.
Meta is asking users to pay $20 a month for the privilege of handing over their digital lives. That is a high bar for any company, but for one with a structural trust deficit, it is a mountain. If the household agent space is going to move beyond early adopters, the industry needs to stop focusing solely on the “how” of security and start addressing the “who.” Until consumers feel they have genuine control—not just a promise of a secure VM—the agentic future will remain a hard sell, regardless of how well the code is written.
