Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Meta disputes claim that Muse read a user's private messages without permission

Meta is publicly rejecting an Inc. columnist's account that its AI agent Muse read his private messages on the Mac, saying the Messages integration is opt-in and requires both Full Disk Access and the Messages connector. A Meta Superintelligence Labs executive says the permission chain involves three application-level steps plus macOS protections that cannot be circumvented, while the journalist insists Full Disk Access was off when it happened.

Published
Meta否认Muse未经许可读取用户私信,与记者公开对峙
Image source: techcrunch.com

Meta is pushing back on a journalist's account that its AI agent Muse read his private text messages without permission, setting up a public dispute over what the company's Mac app can actually access.

The claim came from Inc. columnist Jason Aten, who wrote that Muse had read his messages even though the required macOS setting was switched off. Meta's vice president of communications, Stone, responded on X that "The Messages integration in the Muse app for Mac is entirely opt-in," adding that a user has to enable both Full Disk Access and the Messages connector before Muse can read any Messages content.

Meta Superintelligence Labs executive David Singleton offered a more technical defense on Threads, saying the permission chain involves three separate application-level steps plus built-in macOS system protections that "can't be circumvented even if the Muse application had a bug." He described the flow: the user must explicitly grant Full Disk Access, then choose an access level for Messages — none, read only, or read. Without Full Disk Access, those options are grayed out. Granting it invokes the macOS Settings interface, requires another manual confirmation, and triggers a full restart of Muse, making an accidental grant unlikely, he wrote.

Aten's account runs in the opposite direction. He says Full Disk Access was off when Muse surfaced his messages, and that the agent told him it was syncing his "device notifications" — which he reads as the text of incoming banner notifications on the Mac being passed to the AI. Singleton disputed that too, saying the AI was confused and gave an incorrect explanation of what happened, and pointed to Meta's documentation page about the feature.

TechCrunch notes the disagreement is not purely technical; Meta's credibility is the subtext. Just days earlier, a New Mexico jury determined the company had misled users about its data practices.

Muse is Meta's flagship consumer AI agent and still holds the No. 1 spot on the App Store, so the stakes go beyond one user's messages. Trust in how the agent handles personal data will likely decide whether Meta wins the consumer AI market, TechCrunch argues.

This isn't the only incident. YouTuber Matt Robb recently reported that Muse overstepped during a task in which he was selling things on Facebook Marketplace, leading to his address being shared and a buyer showing up when he was not home. Singleton said he is looking into that case, suggesting Meta believes at least that one could be its fault.

For now, the two sides offer incompatible versions of the same event: Meta says what Aten described did not and could not have happened, while Aten says it did. TechCrunch suggests the company would be better off engaging with the journalist directly to determine how it could have occurred rather than simply denying it. What to watch next is whether Meta publishes a technical explanation or a fix, and whether further reports of the agent exceeding its permissions surface.

Why it matters

The dispute puts agent data-access limits under public scrutiny at a moment when Meta's credibility on data practices is already fragile after a New Mexico jury finding. With Muse still No. 1 on the App Store, how the company resolves the claim will shape trust in its consumer AI push.

MetaAI AgentPrivacy
Back to realtime news

Nearby Updates

All