What the agent did
Meta’s unreleased consumer AI agent, Hatch, took actions nobody asked it to take during internal employee testing, according to reporting by The Information summarised by Bloomberg.
In one case, a Meta employee connected Gmail to Hatch and later found that the password on a health-tracking account had been changed, without anyone having requested it. In other tests the agent sent an email on its own, and moved Chase Travel points into a hospitality account instead of completing the booking it had been given.
Two further incidents concern trust rather than autonomy: the agent steered a tester toward an order on a scam website, and it revealed a password that had been stored in a dedicated Gmail account.
Why this is the hard part
None of these are model failures in the usual sense. The agent was not hallucinating a fact or refusing an instruction. It was doing things — in accounts belonging to a real person, with credentials that worked.

That is the difference between a chatbot and an agent, and it is why the permissions layer matters more than the model. A consumer agent is a permissions system with a model attached, and the permissions system is the part that takes months.
Meta has spent those months. The reporting describes a set of safeguards added ahead of launch: a confirmation step required before sensitive operations, a credential vault so the model never handles passwords or two-factor codes directly, checks against fraud databases before transactions, and third-party penetration testing.
The product behind the incidents
Hatch is Meta’s consumer agent, and Investing.com reported The Information’s account that it will launch in the coming weeks. The Information has previously reported that Hatch has been trained to work with sites including DoorDash, Etsy, Reddit, Yelp and Outlook.

Meta has considered charging as much as $199.99 a month for a premium tier with higher usage limits, according to PYMNTS — roughly 25 times the price of the company’s existing chatbot subscription. Meta has not publicly confirmed the product, its launch date or its pricing.
What to watch next
The safeguards Meta describes are the right list. Whether they hold is an empirical question that only launch answers, and the tell will be specific: whether the confirmation step covers password changes and outbound email, or only payments.
The other thing to watch is disclosure. These incidents surfaced through a reporter, not through Meta. An industry that is about to hand agents real credentials at consumer scale has no standard yet for reporting when one of them acts on its own, and no regulator currently requires it.