Refacto

Industry story

Meta's Muse agent hits 5.6M requests in under two days, dominates AI agent traffic

ai-in-adtech attribution brand-safety measurement retail-media

Meta's Muse shopping agent hit 5.6 million requests in under 48 hours, a scale ChatGPT took 11 months to reach, and now accounts for 72% of daily AI-agent traffic HUMAN Security observes. Impressive numbers. What they don't show is a single completed purchase. An agent reaching checkout 25% more often than its peers could just as easily be scraping price and inventory data as buying anything. The company that wins this week, cleanly and immediately, is HUMAN Security: every retailer with a checkout flow just got handed a reason to buy agent-traffic tooling, and Muse is the pitch deck.

Full analysis

Meta's Muse shopping agent logged 5.6 million requests in under 48 hours, a scale OpenAI's ChatGPT took 11 months to hit, according to HUMAN Security. Muse now makes up about 72% of the daily AI-agent traffic HUMAN sees, and 84% of its requests hit product and search pages. That's the news. The question for operators: does a flood of agent traffic from one walled garden actually move money, and whose?

Here's the framing. This is easy to undo as a decision for any single operator, because nobody has to commit to anything yet. What's actually being decided is whether you treat agent traffic as a new channel that needs its own measurement and bot-handling, or as noise. There's no hard deadline, but the thing setting the clock is your WAF and attribution config: those break on their own schedule once Muse volume climbs, whether you planned for it or not.

The Skeptic

5.6 million requests in 48 hours sounds huge until you remember Meta runs Muse across four apps with billions of daily users. In engagement terms it's a rounding error. HUMAN sees what crawls its own customers' sites, which skews to retailers and publishers already paying for bot detection. So "72% of AI-agent traffic" is 72% of a small, self-selected pool. And "reaches checkout" is not "completes checkout." An agent hitting a checkout page 25% more often may just be scraping price and stock, not buying. For this to mean real commerce, you need merchants to open APIs, somebody to own liability when an agent places a bad order, and consumers to actually trust the thing. None of that is solved. For the non-specialist: a bot visiting the cart page is not the same as a customer paying.

The Market Analyst

The reflexive read is that Meta is attacking Google Shopping and Amazon. Careful. The data shows Meta showing up, not one dollar of budget moving. Nobody has lost anything yet. That said, the quiet winner is obvious: HUMAN Security now has a sales pitch that writes itself. Every retailer with a checkout flow suddenly has a reason to buy agent-traffic tooling, and Muse is the proof. For the product-feed and retargeting crowd, Criteo included, the risk is slower and real: if merchant dollars start flowing toward "make my catalog agent-readable," they flow away from retargeting the same user around the web. The contrarian seat is Amazon Ads. Agents need clean product data, and Amazon's catalog is the ground truth most of them end up hitting anyway. For the outsider: the company selling bot-detection just got handed a free ad.

The Operator

This lands on your desk Tuesday morning whether you booked the time or not. Muse hammers the same product and search URLs that scraper bots hit, so rules tuned to block malicious crawlers will catch legitimate Muse sessions in the crossfire. Expect false-positive blocks to spike within 30 days on anyone running rate limits or a WAF. Second problem, worse: if Muse reaches checkout 25% more than other agents, your attribution is now lying to you. A Muse-assisted purchase can credit a paid search click that did nothing, and you'll overpay that channel until you notice. Add an agent-origin field to the attribution model now. For the non-specialist: your software can't tell the helpful robot from the hostile one, so it either blocks a buyer or hands credit to the wrong ad.

The CFO

Follow the cash, because the cash here is a cost line, not a revenue line. TechCrunch ran a piece this same week on the ugly economics of consumer AI: these agents are expensive to run and the free tier is how Meta buys scale. Meta can eat that because the four apps subsidize it. For a retailer, every Muse session consumes server capacity, bandwidth, and, if you block wrong, a real sale. There's no revenue attached to agent traffic yet, only infrastructure load and a measurement bill. The payback question nobody can answer: when does an agent visit become a purchase that wouldn't have happened anyway? Until you can separate incremental agent-driven sales from agents scraping data you'd have shown for free, this is a cost center with a commerce story stapled on.

The Customer / End User

Two signals this week should slow anyone's enthusiasm. TechCrunch reported Meta disputing a claim that Muse read a user's private messages without permission, and a separate story on Meta's Instinct product recommendations "giving users the ick." Whatever the facts of the message dispute, the pattern is a trust problem showing up early. A shopping agent only works if people let it act on their behalf with their payment details and their DMs. The scale number says Meta can push distribution. It says nothing about whether consumers want an agent spending their money. For the outsider: a robot that shops for you is only useful if you trust it near your wallet, and the first headlines are about privacy, not convenience.

Where they disagree

The real split is scale versus substance. The Market Analyst and the Strategist read 5.6 million requests as Meta claiming the agentic commerce layer. The Skeptic reads it as a big number from a biased sample measuring robot visits, not sales. That gap is the whole call: if those requests are mostly price-scraping, the competitive threat to Google and Amazon is years off; if they convert, mid-funnel display has a demand problem fast.

The second disagreement is who benefits today. Everyone wants to name a loser (Google, Criteo), but the only operator with revenue on the line right now is HUMAN Security, which sells the shovels. The threat to retargeting budgets is real but slow, and it depends on merchants choosing to spend on agent-readiness, which no data here shows them doing yet.

What it hinges on

Three facts settle this, and we have none of them yet. One: what share of Muse's checkout-page visits end in an actual purchase. Two: whether merchants redirect budget toward agent-readiness and away from retargeting. Three: whether consumers trust an agent with payment and private messages after a rocky privacy start. The council leans Skeptic on near-term commerce impact and Market Analyst on who profits today. Before anyone re-architects for agents, verify the conversion rate behind the checkout stat and re-tune bot rules so you don't block buyers. That's cheap and it's reversible.

Prediction: HUMAN Security will publicly report that its paid customer count or agent-management revenue grew materially year-over-year when it next discloses business metrics, by the end of Q1 2027, driven by enterprises buying agent-traffic tooling in response to Muse-scale bot volume.

Confidence: Medium. The demand mechanism is clear, but HUMAN is private and may not disclose on that timeline.

Why: Muse jumping to 72% of observed AI-agent traffic in days gives every retailer running a checkout a concrete reason to buy tooling that tells helpful agents from scrapers, and HUMAN sells exactly that. The company is already putting this data in the press, which is how you prime an enterprise pipeline. The opposite outcome, flat or shrinking demand, would require agent traffic to stall or retailers to decide they can filter it in-house, and the 30-day false-positive problem that WAF teams are about to hit argues the other way. The weak link is disclosure: HUMAN is private, so the number may surface through a funding round or trade reporting rather than a clean release, which is why this is Medium and not High.

Revisit by 2027-04-05: We're right if HUMAN Security, in any public statement, funding announcement, or trade-press report by this date, cites year-over-year growth in paid customers or agent-management revenue tied to AI-agent traffic. We're wrong if no such growth is reported or the figure is flat to down.

Comments