HUMAN Security stated in a blog post dated September 28, 2026 that Meta's Muse agent accounts for an average of 72% of daily AI-agent requests in its early observations, with daily request volume 5.2 times that of ChatGPT Agent, the next largest.

In Short

A security company that tracks web traffic says one new AI assistant from Meta now generates most of the requests that AI agents make to websites. That matters because advertisers, retailers and fraud teams count visits, carts and purchases, and an AI agent shopping for a person can be mistaken for a human or filed with malicious bots. What changes is the nature of the task: counting agent traffic is no longer enough, and HUMAN argues that telling the agents apart, and judging what each one does, becomes the main job.

What HUMAN measured

The figures come from a post by Julian Norton on HUMAN Security's blog, dated September 28, 2026 and described as early observations. According to HUMAN, Muse accounts for an average of 72% of daily AI-agent requests, and its daily request volume is 5.2 times that of the next largest agent, ChatGPT Agent. By September 27, daily Muse requests outnumbered those of all other measured agents combined by a factor of 2.34. Read as a ratio, that works out to roughly 70% of the day's requests, close to the 72% average.

A third comparison is more striking and less precise. HUMAN states that Muse reached, in two days, a request volume that took ChatGPT 11 months to achieve. The post names ChatGPT rather than ChatGPT Agent, gives no absolute volume and does not say which milestone is meant, so the claim cannot be matched against any outside series.

Much else is missing. The post offers no request counts, no sample size, no observation window and no definition of a request, which could mean a page load, an HTTP call or a session. The phrase "measured agents" appears to refer to those that HUMAN's AgenticTrust product identifies; the company says it verifies Muse and more than 30 other AI agents. Taken at face value, and assuming a common basis, a 72% share and a 5.2 times ratio would leave ChatGPT Agent with about 14% of daily agent requests and all remaining agents with about 14% between them. The post does not say the two figures share a basis, so that arithmetic is indicative only.

A free agent with a distribution network

HUMAN offers two explanations for the pace. The first is price. Most other AI agents, the post says, require a paid subscription for browser automation, whereas "Muse has a generous token limit on the free tier, includes an AI browser agent by default, and is designed for everyday consumers." The second is reach: Facebook, Instagram, Messenger and WhatsApp give Muse "an ability to scale that OpenAI and Anthropic lack", in the company's wording.

Adoption figures follow. By September 21, Muse had reportedly exceeded 2.5 million downloads and reached the top of U.S. app charts, according to the post, which does not name the source of the download count. Apptopia data cited by HUMAN indicates heavy overlap with Meta's existing apps: 95% of Muse's users are also Facebook users, and 63% are Instagram users. HUMAN frames the release as the first mass-market adoption of agentic AI and writes that "Muse will be many users' first experience of an agent browsing and acting on their behalf."

A share of agent requests is not, however, a share of web traffic, and the post supplies no bridge between the two. It recalls that HUMAN tracked a 7800% increase in agentic traffic in 2025, but a percentage rise says little without a starting volume. For a broader frame, Cloudflare data cited by Digiday and covered by PPC Land on September 8, 2026 put bots and AI agents above 50% of all web requests, a figure that covers automated traffic of every kind rather than agents alone.

Where the requests go

Among Muse requests, 84% target product and search pages, according to HUMAN. In what the post describes as a recent sample, Muse is 25% more likely than other AI agents to reach checkout pages. No absolute checkout rate, sample size or date range accompanies that comparison.

HUMAN's reading is that Muse follows the same discovery-to-purchase paths that businesses already measure, optimize and protect. Intent is where the company draws the line: "An agent researching products for a real shopper may be valuable. An agent that spoofs its identity, abuses an account, or attempts a fraudulent transaction is not." Counting both as undifferentiated bot traffic, or treating an agent session as a human one, "can distort conversion rates, funnel performance, attribution, and fraud signals", the post states.

Earlier HUMAN data offers a rough point of comparison. In its May 2026 report, covered by PPC Land in June, product and search routes made up 76.4% of agentic traffic, authentication 5.6% and checkout and payment 2.4%. Muse's 84% sits above that mix, although the two measurements differ in period and presentation. The same report listed Perplexity's Comet at a 47% share, with OpenAI's Atlas at 20.3% and the Claude Chrome Extension at 18.6%. The September post ranks ChatGPT Agent second and does not explain how its request-based ranking relates to the earlier share-based one.

Identification, not just counting

The post's policy conclusion is brisk. "The immediate need is accurate, real-time identification of this traffic, followed by governance that connects business policy to technical enforcement." It adds that 96% of CISOs cannot accurately quantify agentic traffic, a figure the text presents without describing the survey behind it.

On the technical side, the post names Web Bot Auth, which HUMAN supports, as a particular example of work on internet standards for identifying AI agents. Then comes the catch: "But most AI providers do not yet use these standards." Cloudflare put the protocol forward in May 2025, and it builds on HTTP Message Signatures, specified in RFC 9421, under which an agent signs its requests with a private key and publishes the matching public key where sites can fetch it. In Cloudflare's first proposal, bots send a Signature-Agent header that points to the endpoint hosting their keys, and Vercel, Shopify and Visa had implemented the scheme by the time of that November 2025 coverage. Whether Muse signs its requests is not stated in the post.

HUMAN says AgenticTrust identifies and verifies Muse and more than 30 other agents "using proprietary research or digital signatures that cannot be spoofed". The post does not specify which of the two methods covers Muse. The distinction carries weight because a self-declared user-agent string is trivial to copy. A DataDome test cited in a March 2026 report found that 79.7% of 698,214 sites did not block or challenge a spoofed ChatGPT user agent.

Once an agent is identified, the post says, activity determines policy. Organizations can allow automation that creates value and block what creates risk, with granular control over actions such as add to cart or log in, or rules on which agent is trusted. That model treats the agent's identity and its behavior as separate inputs, since the same agent can browse harmlessly on one visit and attempt a transaction on the next.

Whether a site can refuse an agent at all remains contested. On November 4, 2025, Amazon told Perplexity to stop Comet users from buying on its marketplace, arguing that the agents operate without transparency and evade detection. On August 4, 2026, the Ninth Circuit vacated the preliminary injunction that had kept Comet Assistant out of Amazon shopping accounts, reasoning that an AI agent is a tool and that the user is the party accessing Amazon's systems. The panel left Amazon free to set access rules through its terms of service.

For publishers and retailers, that backdrop means identification comes first and the allow-or-block decision second. HUMAN's own earlier work points the same way: its April 2026 expansion of Agentic Visibility delivers insights to marketing and commerce teams natively inside Adobe Experience Platform, covering the measurement of AI-driven traffic and the distinction between human, bot and agent activity.

Why the counts matter to marketers

Many measurement setups were built around two categories, people and bots. An agent acting for a logged-in shopper fits neither cleanly. Ad verification and analytics tools that sort visits into human and invalid traffic must decide where such a session belongs: it is automated, yet it is neither the fraud that filtering is meant to remove nor a person whose behavior a campaign set out to influence.

The practical effects reach several places at once. Conversion rates change when agent sessions that browse but never buy enter the denominator, and funnel reports change when agent sessions that reach checkout enter the numerator. Retargeting pools can fill with non-human visitors. GoFish reported that bot traffic on client sites rose 80% year on year and that the retargeting adjustments made in response raised cost per thousand impressions by an average of 20%, figures that Digiday published in September 2026.

The commercial setting deserves a note. HUMAN sells bot and agent detection, and the post closes with an invitation to book an AgenticTrust demo and to join a webinar on October 1 covering where Muse agents go, what they do and what consumer-grade agents mean for the holiday season. The numbers come from HUMAN's own platform, and the post cites no independent measurement of them. Whether other vendors and site operators see the same concentration is a question the post leaves open.

Timeline

Summary

  • Who: HUMAN Security, a cybersecurity company, in a blog post by Julian Norton; Meta, whose Muse agent is the subject; Apptopia, cited for user overlap data.
  • What: HUMAN reports that Muse accounts for an average of 72% of daily AI-agent requests, runs at 5.2 times the volume of ChatGPT Agent, and outnumbered all other measured agents by a factor of 2.34 on September 27. Among Muse requests, 84% target product and search pages, and Muse is 25% more likely than other agents to reach checkout pages in a recent sample.
  • When: The post is dated September 28, 2026, with data through September 27, a download milestone dated September 21 and a webinar on October 1.
  • Where: Traffic observed by HUMAN's platform on the websites it protects; the post gives no geographic or sector breakdown, and cites U.S. app charts for downloads.
  • Why: HUMAN argues that a free, consumer-oriented agent distributed through Meta's apps changes the composition of web traffic, and that businesses need to identify agents and govern their actions to protect conversion data, attribution and fraud signals. HUMAN also sells products for that purpose, and the figures come from its own data.