Meta's Muse shopping agent filled four of its six product recommendations from the live web and just two from Meta's own product catalog, according to research Profound published on October 2, 2026, even though the catalog supplied roughly 15 times as many candidates. The same study found that Muse and its rival Instinct browse websites without identifying themselves.
In Short
Profound, a company that tracks how AI tools talk about brands, tested Meta's new Muse shopping assistant and found that most of its product suggestions came from websites it visited live, not from Meta's big product list. That matters to any shop selling online, because these assistants pick products for people and do not show which pages they read. If an agent like this is going to recommend your products, it has to be able to find them and read your website, and right now it is hard for you to even tell when it has visited.
What Profound published
The research post, titled "The era of personal agents: Muse and Instinct" and written by Allison Huang of Profound's research team, appeared on the company's blog on October 2, 2026. It sets out to answer two questions for marketers: how agents that shop on behalf of users decide which products make a shortlist, and how large the opportunity is.
Two products sit at the centre of the analysis. Muse is Meta's consumer agent, which Meta put inside WhatsApp and a standalone app on September 8, 2026, with each user's agent running on a dedicated cloud machine with its own browser and a single-use payment card for each transaction. Instinct is a startup agent that operates through text messaging. According to Profound, Muse has been downloaded "over 2.5 million times since its launch on September 8," while Instinct is "reportedly approaching an annualized transaction volume of $1B."
Neither figure comes from Profound's own data. Both are linked citations in the post. The download number in particular was already dated when the post went live: Sensor Tower estimates reported on September 30 put Muse installs across the US and Canada above 5 million within 22 days. Profound did not update the 2.5 million figure.
Instinct's numbers carry their own context. According to Fortune, the company was founded in 2025 by Noah Shinn, who said on a podcast that annualised transaction volume was approaching $1 billion, with travel accounting for about half. Fortune reported on September 30 that Instinct had just raised $1 billion in a Series C at a $10 billion valuation, a month after raising $250 million at a $2.5 billion valuation. Fortune also reported that it is unclear how many users Instinct has.
Personal agents versus answer engines
Profound draws a distinction between two categories of AI product. Answer engines, in Profound's vocabulary, are tools like ChatGPT and Claude, which "focus on search and knowledge work." Personal agents "are designed to help with everyday tasks like making dinner reservations, canceling forgotten subscriptions, purchasing items, or planning trips."
According to Profound, both are built on the same foundational components. The difference lies in two areas. The first is context: personal agents build detailed user profiles from past conversations and from sources the user connects, such as email, calendar or messaging apps. Muse, according to the post, "maintains a shopping profile for each user that records tastes by product category." The second is workflows: both Muse and Instinct "use detailed instruction files that act as operating guides for tasks such as shopping," according to Profound. A workflow diagram in the post shows Muse reading a file labelled "shopping/PROFILE.md" before searching its memory.
The post frames the shift for marketing teams in one line. "Personal agents expand the challenge from influencing what AI says to understanding how AI acts on a user's behalf," according to Profound.
That framing will be familiar to readers who have followed the industry's push into GEO and the scramble to measure brand mentions in chatbot answers. What changes with agents is that the AI system is no longer only summarising a page. It is choosing products and, in some cases, buying them.
Side by side: Muse and Instinct
Profound's comparison table sets out how the two agents differ.
| Muse | Instinct | |
|---|---|---|
| Base model | Muse Spark 1.3 | Undisclosed |
| Browser access | Yes | Yes |
| Shopping sources | Browser, Meta product catalog, Facebook Marketplace | Browser, Shopify product catalog |
| Availability | US and Canada | Private beta, by invite or waitlist |
| Interface | Muse app, WhatsApp | iMessage, WhatsApp |
The model detail is worth noting. When Meta unveiled Muse in September, its announcement described the agent as powered by Muse Spark without naming a version, and a "Muse Spark 1.3" post had been dated September 2, six days earlier. Profound's table names version 1.3 directly. Meta made the previous version, Muse Spark 1.1, available to developers on July 9, 2026, with a 1 million token context window.
The catalog split carries more commercial weight. Muse queries Meta's product catalog, the same store of product data that, according to Profound, "also powers shopping on Instagram and Facebook." Instinct searches Shopify's catalog. A merchant listed in one and absent from the other is, in effect, visible to only one of the two agents through structured data.
Shopify's catalog had already been pulled into another agentic channel weeks earlier. On September 22, Google emailed Shopify merchants to say their stores had been matched to Merchant Center and enabled for native checkout in AI Mode and Gemini, with an opt-out rather than an opt-in.
How Muse builds a shortlist
According to Profound, a Muse shopping request runs in three stages.
Conversation
After a user expresses shopping intent, Muse may ask follow-up questions to narrow the request. "It always checks the user's shopping profile for recorded preferences, and it sometimes searches its memory for additional context," according to the post.
Discovery
Muse then runs two searches in parallel. One uses a browser to search merchant websites. The other queries Meta's product catalog.
Recommendation
Candidates from both paths are filtered and ranked into a final recommendation set.
To see how the two sources contribute, Profound ran 50 prompts from a single consumer retail category through one Muse instance. The workflow diagram's caption dates the run to September 30, 2026, and states that the figures are medians. Profound does not name the retail category. The company also calls the exercise "a small, exploratory sample, so the patterns below are illustrative rather than definitive."
The medians are nonetheless striking. For each prompt:
- The browser typically visited 3 domains and returned 4 products from 2 merchant sites.
- Meta's product catalog returned roughly 60 products from 30 merchant sites.
- The final recommendations typically contained 6 product cards: 2 from the catalog and 4 from the browser.
Put another way, the catalog supplied about 94% of the candidate pool but only a third of the final slots. The browser supplied about 6% of candidates and two-thirds of the slots. On median figures, almost every product the browser surfaced ended up recommended, while roughly one catalog product in 30 did.
Medians do not add up neatly across rows, so the ratios are approximate. The pattern still matters. If the sample holds beyond one category, a place in Meta's catalog buys a merchant entry to a large and heavily filtered pool, while the handful of sites Muse chooses to open in its browser take most of the shortlist. Profound does not explain why the browser results rank higher, and Meta has not published how Muse weighs the two sources.
Reading the web through the accessibility tree
The browser path explains why Profound spends much of the post on how agents read pages. Answer engines, according to the company, read the static content of pages that bots have already discovered and indexed. Muse and Instinct can fetch static content too, but they "can also visit your website live and read each page using a browser."
According to Profound, the agents navigate using the accessibility tree, which the post defines as "a structured description of the page's content and controls that the browser builds from your HTML and accessibility labels." The same structure that screen readers rely on is, in this account, the interface through which an AI agent understands a product page, a size selector or a checkout button. Pages built with semantic HTML and clear labels produce a more complete tree.
The technical point has a practical edge. A product page that renders its key specifications as images, hides compatibility details behind unlabelled tabs, or relies on custom controls with no accessible names may look fine to a human shopper and remain partly unreadable to an agent. Profound lists intended uses, compatibility, dimensions, materials and relevant limitations as the details agents need to compare products for a specific user.
No citations, no self-identification
Two findings in the post bear directly on measurement.
The first concerns citations. "By default, Muse and Instinct do not name the sources they visit when gathering realtime information for a response," according to Profound. Answer engines such as ChatGPT and Perplexity at least expose links that brands and tools can count. A personal agent that recommends a product without showing where it learned about it leaves no such trail.
The second concerns traffic. According to Profound, Muse and Instinct "do not identify themselves by name when browsing websites. Instead, they route traffic through residential internet connections and present as ordinary human visitors, which makes them difficult to separate from human traffic."
Routing through home connections resembles the residential proxy networks more commonly associated with scraping and ad fraud, and it defeats the two checks most site operators rely on: user agent strings and published IP ranges. Even the self-declaration approach has limits. A June 2026 roundup of AI crawler user agent strings cited DataDome data finding that 80% of AI agents do not declare themselves properly.
Other platforms have taken a different route. In March, Google added Google-Agent to its list of user-triggered fetchers, giving its browsing agents a named identity and a separate IP range file, and said it was experimenting with Web Bot Auth, the protocol that has bots sign requests cryptographically. Cloudflare published a registry format for those signatures in October 2025. Profound's post gives no indication that Muse or Instinct sign their requests.
Measuring Muse through an unverified crawler
Because Muse does not announce itself, Profound built an indirect estimate of its traffic. The method rests on an observation from the company's manual testing: some Muse browser sessions triggered a request from a self-identified "meta-webindexer" bot immediately before the human-looking visit.
Meta-WebIndexer is a real Meta crawler, a sibling to Meta-ExternalAgent that is used to improve Meta AI search results. According to Profound, requests from these bots have historically come from IP addresses publicly claimed by Meta. The ones tied to Muse sessions did not. Profound labels these "unverified" requests and treats them as a signal of Muse activity rather than as proof of it.
Muse's staggered rollout gave Profound a natural comparison. The agent reached the US and Canada before the rest of the world, so the company compared the change in unverified meta-webindexer requests across the two geographies.
The methodology
According to the post:
- Data: daily unverified meta-webindexer requests to e-commerce and retail websites tracked by Profound, from August 19 to September 27, 2026.
- Exclusions: 15 high-volume domains were removed because they showed evidence of being targeted by automated activity, receiving tens of thousands of requests a day from only a few hundred IP addresses.
- Groups: the remaining set covers 280 sites, with 115 unique hostnames assigned to the US and Canada and 165 to the rest of the world. Each domain was assigned to a country by its suffix, for example .uk to the United Kingdom.
- Periods: a 20-day baseline before launch (August 19 to September 7) and a 20-day post-launch window (September 8 to September 27).
- Calculation: average requests per day in each period, then percent change from the baseline.
The result
Unverified requests to US and Canadian sites rose 1,313% against the baseline. Requests to sites in the rest of the world rose 827%. Profound divides one by the other to produce its headline: the increase was 1.6 times as large in the US and Canada.
The chart accompanying the figures tells a sharper story than the ratio. US and Canadian sites hovered at a few hundred unverified requests a day through early September, with a single pre-launch spike of about 650 around September 3. The line stayed roughly flat for a week after the September 8 launch, began climbing around September 15, passed 2,000 a day around September 21 and reached roughly 6,700 by September 27. The rest-of-world line stayed close to zero throughout, reaching perhaps 100 to 150 on its highest days.
That gap exposes a weakness in the headline metric. An 827% increase from a near-zero base can involve very few requests, so comparing two percentage changes compresses a difference in absolute volume that the chart shows to be far larger than 1.6 times. Profound itself calls the estimate "conservative."
Other caveats sit in the methodology. Country assignment by domain suffix leaves open how generic domains such as .com were classified; the post does not say. Unverified requests by definition come from outside Meta's claimed address space, so some could come from third parties spoofing the Meta crawler name rather than from Muse. Profound acknowledges the limitation in its own words: "This is only a proxy for Muse traffic, but it's an early sign that agents are driving a meaningful and rapidly growing volume of web traffic."
The timing of the climb, a week after launch, may also reflect Meta's own promotion rather than organic adoption. Sensor Tower estimated that Meta ramped Muse advertising spend on September 16. Profound does not discuss this.
Vendor research, vendor products
Profound is not a neutral observer. The post closes with a "Get started" section stating that the company "helps companies understand how AI represents their brand, monitor how visible their products are in AI responses, and track AI agents reading their website," followed by a demo booking link. The company's site navigation lists products named Agent Analytics and Shopping. On October 11, 2026, Profound published a separate post presenting Dynamic Bot Rendering, which detects AI bot visits and serves those bots a fully rendered version of a page.
The 50-prompt test covered one category on one Muse instance on one day. The traffic estimate covers 280 sites that Profound already tracks, selected by an undisclosed process. Neither has been independently replicated. The figures are best read as an early, vendor-supplied look at agent behaviour rather than as a market measurement.
Meta has not published any comparable data on how Muse sources products or how much traffic it sends to merchants.
Why this matters for marketers
For advertisers and retailers, the post adds evidence to a question PPC Land has tracked for more than a year: what happens to paid media when software, not people, compiles the shortlist?
Skepticism has been part of that coverage. When OpenAI introduced Instant Checkout in ChatGPT in late September 2025, Andrew Lipsman's analysis questioned whether shoppers would hand purchasing decisions to agents at all. Survey data from June 2026 pointed the same way: Koddi's research found that only 20% of consumers were comfortable with AI acting autonomously, while 84% of commerce media leaders said they would invest in AI recommendation visibility and 33% named measurement of agent-mediated journeys as a major blocker.
Profound's findings sharpen that measurement problem. Without citations in the conversation and without a declared user agent at the server, a merchant whose product Muse recommends may have no direct way to know that the agent visited, which pages it read, or why it chose one product over another. Bot defences are rarely positioned to help: DataDome found in September that only 2.4% of 21,491 high-traffic domains blocked all 10 of its test bots, and its report put AI agents at 1.25% of the requests it analysed.
For Meta, the stakes run in two directions. The company's catalog is the infrastructure behind its shopping ads on Facebook and Instagram. If Muse in practice gives most recommendation slots to products it finds by browsing, the catalog's role in the agent is narrower than its role in the ad business. Mark Zuckerberg's August 10 letter, which promised every user a highly capable personal agent, ran to 6,542 words without once mentioning advertising. How Meta eventually monetises Muse, and whether catalog placement becomes something merchants pay to influence, remains open.
Meanwhile, retailers are already reacting. Amazon said on September 20 that it had cut Muse off from purchasing on Amazon.com, citing among other reasons that the agent does not identify itself when browsing - the same behaviour Profound documents.
Timeline
- July 30, 2025: Mark Zuckerberg sets out Meta's "personal superintelligence" vision
- September 29, 2025: OpenAI adds Instant Checkout to ChatGPT, drawing skepticism about AI shopping agents
- October 30, 2025: Cloudflare publishes a registry format for Web Bot Auth signatures
- March 20, 2026: Google adds Google-Agent to its list of user-triggered fetchers
- June 10, 2026: Koddi report finds 20% of consumers comfortable with fully autonomous AI shopping
- June 28, 2026: Roundup of AI crawler user agent strings cites DataDome finding that 80% of AI agents do not declare themselves properly
- July 9, 2026: Meta releases Muse Spark 1.1 to developers
- August 10, 2026: Zuckerberg's 6,542-word letter promises a personal agent for everyone, without mentioning advertising
- August 19 to September 7, 2026: Baseline period for Profound's unverified meta-webindexer measurement
- September 2, 2026: A "Muse Spark 1.3" post is dated six days before the Muse agent goes live
- September 8, 2026: Meta puts Muse in the US through an app and WhatsApp
- September 20, 2026: Amazon says it has cut Muse off from purchasing on Amazon.com
- September 22, 2026: Google emails Shopify merchants enabling native checkout in AI Mode and Gemini
- September 22, 2026: DataDome report finds only 2.4% of high-traffic sites block all its test bots
- September 27, 2026: End of Profound's post-launch measurement window; unverified requests to US and Canadian sites reach about 6,700 a day
- September 30, 2026: Profound runs its 50-prompt Muse shopping test; Sensor Tower estimates put Muse above 5 million installs in the US and Canada
- October 2, 2026: Profound publishes "The era of personal agents: Muse and Instinct"
- October 11, 2026: Profound publishes a post presenting Dynamic Bot Rendering
Related PPC Land coverage
- Meta puts an AI agent that buys things inside WhatsApp, US only - Details of the Muse release on September 8, 2026, including its cloud machine architecture, Stripe Link checkout and the Muse Spark 1.3 dating.
- Meta's Muse Spark 1.1 gains 1 million token context for developers today - Covers the July 2026 developer release of the model family that powers Muse.
- Zuckerberg's 6,500-word AI letter never mentions advertising once - Analysis of Meta's August 2026 letter promising personal agents for everyone.
- Google switched on AI Mode checkout for Shopify stores without asking - How Google enabled agentic checkout for Shopify merchants by default in September 2026.
- AI shortlists are commerce media's next paid placement battle - Koddi survey data on consumer comfort with AI shopping and industry plans for AI recommendation visibility.
- Full bot protection drops to 2.4% of popular websites, DataDome finds - DataDome's 2026 report on bot defences and AI agent traffic volumes.
- Google-Agent joins the crawler list as AI browsing gets an official identity - Google's approach to giving its browsing agents a declared, verifiable identity.
- The user agent strings every SEO and site owner needs right now - A reference list of AI crawler identifiers and the limits of user agent verification.
- Cloudflare unveils registry format for bot and agent authentication - The infrastructure behind cryptographic signing of bot and agent requests.
- AI agent traffic is up 8x - HUMAN Security now tells marketers why - HUMAN's April 2026 data on automated traffic growing faster than human visits.
- Skepticism grows over AI shopping agents as ChatGPT checkout launches - Andrew Lipsman's 2025 case against rapid adoption of agentic shopping.
Summary
Who: Profound, an AI visibility analytics company, in a research post by Allison Huang. The subjects are Meta's Muse agent and Instinct, a startup personal agent founded by Noah Shinn.
What: A 50-prompt test of Muse found that its typical six recommendations included four products from two browsed merchant sites and two from Meta's product catalog, which had supplied about 60 candidates. Profound also found that Muse and Instinct browse without identifying themselves and do not cite sources, and estimated Muse traffic through unverified meta-webindexer requests, which rose 1,313% on US and Canadian retail sites against 827% elsewhere.
When: Published October 2, 2026. The traffic study covers August 19 to September 27, 2026, and the shopping test ran on September 30, 2026.
Where: Muse is available in the US and Canada; Instinct is in private beta. The traffic study covered 280 e-commerce and retail sites tracked by Profound, 115 in the US and Canada and 165 elsewhere.
Why: Personal agents choose and buy products on behalf of users. If they favour live-browsed pages over catalog feeds and leave no citations or identifiable traffic, merchants lose both visibility into how they are chosen and the means to measure it.
Discussion