SANTA CLARA, Calif., Oct. 07, 2026 (GLOBE NEWSWIRE) -- Within two weeks of Meta's Sep. 8 launch of its Muse personal AI agent, Cequence Security found traffic matching Muse at more than half of the customers it studied. Most of those businesses would not have known. Muse presents itself as an ordinary Chrome browser rather than identifying as an AI agent, so to standard security checks it looks like a person.
Cequence spotted the traffic with the same behavioral detection that powers Agent Trust, a new capability in Cequence Application and API Protection available today. Agent Trust verifies agents that present an identity and catches the ones that don’t. Muse shows why businesses need both. With Agent Trust, they can stop harmful requests while still letting customers use their services through agents like Muse.
What Cequence found
Cequence analyzed traffic across customers in financial services, retail, travel, software and other sectors from Sep. 1 to Sep. 24, 2026. At the median customer, Muse traffic grew nearly sixfold within about two weeks of first appearing.
Together, the findings show why agents are hard to govern. Traffic that is almost always legitimate, invisible to standard checks and trusted with customer logins looks the same whether it comes from Muse or from an attacker using a stolen agent credential.
"AI agents like Meta's Muse are bots that act on behalf of real customers. Many businesses can't see them, and those that can are tempted to block them," said Hari Nair, VP of product management at Cequence. "Agent Trust lets businesses block the action, not the agent. The agent keeps working for its customer, and the one request that crosses a line gets stopped, slowed or challenged."
How Agent Trust works
Agent Trust pairs identity verification with the behavioral detection Cequence has run across bot and API traffic for years. It includes:
Because Cequence discovers and inventories an organization's APIs, Agent Trust knows which endpoints handle login, checkout, pricing, and stock. If an agent that normally checks order status starts pulling price and stock for every product, the platform can stop the scraping while the agent keeps working for its customer.
"Every CISO is about to hear the same question from the business, which is whether the company can let AI agents in. Saying no is no longer the safe answer, because customers are choosing agents and will take their spending wherever those agents are welcome. Our job is to make yes the safe answer," said Ameya Talwalkar, co-founder and CEO of Cequence.
Availability
Agent Trust is immediately available to Cequence customers as part of Application and API Protection. To learn more or discuss how Agent Trust applies to your environment, request a demo at https://www.cequence.ai/demo/bot-management.
Resources
About Cequence Security
Cequence protects the applications and data that power the agentic enterprise. More than a decade of bot defense and API security experience has established Cequence as the leader of safe and secure agentic AI adoption. The Cequence platform delivers deep insight into user, entity, and agent behavior, enabling organizations to secure, govern, and control agentic AI workflows while protecting against bad actors and rogue agents. Cequence delivers value in minutes rather than days or weeks with a highly scalable, no-code approach. Trusted by the largest and most demanding private and public sector organizations, Cequence protects more than 10 billion daily API interactions and 4 billion user accounts. To learn more, visit: https://www.cequence.ai/.
Media Contacts
Katrina Porter
Cequence Security PR Team
press@cequence.ai
ICR for Cequence Security
Cequence@icrinc.com