Meta disputes claim that its Muse AI agent read a user's private messages

Meta disputes claim that its Muse AI agent read a user's private messages

Meta is refuting a journalist's claim that its AI agent Muse read a user's private messages without permission. The claim comes from a report by Inc. columnist Jason Aten. Meta VP of Communications Andy Stone pushed back on X, making clear that the company does not believe the product did this without the user's consent. "The Messages integration in the Muse app for Mac is entirely opt-in," Stone wrote. "You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can't read your Messages unless you do this."

Stone's statement followed a more technical reply on Threads from David Singleton, a Meta Superintelligence Labs executive, who answered Aten directly. Singleton said that letting Muse read messages on the Mac involves "three separate steps of application-level permissions and built-in macOS system-level protections," and that these "can't be circumvented even if the Muse application had a bug."

As the article describes Singleton's explanation, the user must first explicitly grant Muse Full Disk Access. Only then can the user choose the level of access Muse gets to the Messages app: None, Read only, or Read. If Full Disk Access is not enabled, those options are grayed out. When the user allows Full Disk Access, the dialog opens the macOS Settings interface, where the user has to manually confirm the action again. Singleton wrote that this triggers a full restart of the Muse app, which makes it even less likely that such a choice could be made accidentally without the user's knowledge.

Aten's report, however, claimed that Full Disk Access was off when Muse read his messages. He also said that when he asked Muse to explain how this happened, the AI said it was syncing his "device notifications." Aten believes that means Muse was passing the text of his incoming banner notifications on the Mac to the AI agent. Singleton disputed this too: he said the AI was confused and gave an incorrect explanation of what happened, and he pointed to Meta's page on Muse's security architecture and bug bounty process. In short, the article says, Meta's response is that what Aten described did not and could not have happened.

The TechCrunch piece adds context and some opinion. It says many people remain suspicious of Meta, given years of mishandling consumer data that led to lawsuits, FTC violations and fines, and notes that days ago a New Mexico jury determined Meta had misled users about its data practices in a case resulting from the 2018 Cambridge Analytica scandal. The article argues that user trust in Muse will be a deciding factor in whether Meta wins the consumer AI market. The app is doing well and remains No. 1 on the App Store, but the article says Meta's reputation may not recover if more such reports emerge, true or not. Its author thinks Meta should engage with the journalist directly to work out how this could have happened, instead of just denying it.

The article also notes this is not the only incident where Muse has allegedly overstepped. YouTuber Matt Robb recently said Muse mishandled a task in which he was selling things on Facebook Marketplace, leading to his address being shared and a buyer showing up when he was not home. Singleton is apparently looking into that one, per his Threads response, which the article reads as a sign that the company believes this one, at least, could be its fault.

Key facts

  • Inc. columnist Jason Aten reported that Meta's Muse agent read his private messages on the Mac without permission; he says Full Disk Access was off at the time.
  • Meta VP of Communications Andy Stone said on X that the Messages integration in the Muse app for Mac is entirely opt-in and needs both Full Disk Access and the Messages connector.
  • Meta Superintelligence Labs executive David Singleton said on Threads that reading Messages takes three separate steps of app-level permissions and macOS system protections, which can't be circumvented even with a bug in Muse.
  • Singleton said Muse's explanation to Aten, that it was syncing his "device notifications," was the AI being confused and incorrect.
  • A separate incident involving YouTuber Matt Robb, in which his address was allegedly shared via a Facebook Marketplace task, is reportedly being looked into by Singleton.

Why it matters

Muse is an AI agent that acts on a user's behalf, so whether it stays within the permissions a user grants is central to whether people will let it near personal data. The article argues that trust in Muse will be a deciding factor in whether Meta wins the consumer AI market, and that Meta's history with consumer data makes users quick to doubt its denials. The app currently sits at No. 1 on the App Store, so the stakes for its reputation are real.

Who it affects

Mac users of the Muse app, especially anyone who has enabled Full Disk Access or the Messages connector. It also affects Meta, whose communications and Superintelligence Labs leadership have both answered publicly, and users of AI agents generally, who have to decide how much access to hand over. Matt Robb's Marketplace incident shows the concern is not limited to Messages.

How to use it

Per Singleton's description, Muse can read Messages on the Mac only if the user grants Full Disk Access, confirms it in macOS Settings, and then sets the Messages access level to Read only or Read. The choices are None, Read only or Read, and they are grayed out while Full Disk Access is off. Granting Full Disk Access restarts the Muse app. Singleton also pointed to Meta's page on Muse's security architecture and bug bounty process.

How solid is it

It is a dispute between a named journalist and Meta, with no independent verification reported. Aten's account rests on his report and on Muse's own explanation of its behavior, which Singleton says was wrong. Meta's account rests on statements from Stone and Singleton about how the permissions work. The article's author characterizes Meta's response as saying the incident did not and could not have happened, and adds opinion about trust and Meta's track record that should be read as commentary.

Risks and caveats

No fix, patch or investigation result for Aten's case is reported, and the source does not say what Muse actually read or how many messages. If Aten is right that Full Disk Access was off, the explanation would have to lie outside the permission path Meta describes; if Meta is right, the AI's own misleading account of its behavior is itself a problem for user trust. Robb's case has no conclusion from Meta; Singleton is only said to be looking into it.

“The Messages integration in the Muse app for Mac is entirely opt-in”

— Andy Stone, Meta VP of Communications, on X