New Delhi: Meta has pushed back against claims that its Muse artificial intelligence agent accessed a user’s private messages without permission, saying the feature requires multiple user-approved permissions before it can access Messages content on a Mac. The company said its permission system is designed to prevent Muse from accessing message data unless the required settings are enabled.
The clarification comes after journalist Jason Aten reported that Muse had accessed the contents of his messages even though Full Disk Access was disabled on his Mac. Aten said he questioned Muse about how it obtained the information and received an explanation suggesting that the AI was syncing device notifications. This led to concerns that message previews appearing in notifications might have been made available to the AI agent.
Meta says Messages access is optional
Meta vice president of communications Andy Stone disputed the explanation provided by Muse. According to Meta, the Messages connection is optional and cannot access message content unless users activate both Full Disk Access and the Messages connector.
Meta executive David Singleton provided further details about the permission process. He said users have to complete multiple steps involving Muse, macOS settings and access to Messages before the AI can use the relevant content.
The company said users can select different levels of access, including no access, read-only access or broader read access after enabling Full Disk Access. Singleton also said the protections are designed so that they cannot simply be bypassed because of a software bug.
Meta’s position is therefore that the reported access described by Aten should not have been technically possible under the permission model. The company has disputed the suggestion that Muse obtained the information by quietly reading notification previews.
Conflicting explanations raise questions
The incident has nevertheless highlighted a broader issue surrounding AI agents that can interact with a user’s computer and applications.
A traditional chatbot generally responds to information that a user explicitly provides during a conversation. Agentic AI systems such as Muse are designed to operate more broadly, potentially interacting with applications and completing tasks on a user’s behalf. Meta describes Muse as a personal AI agent capable of carrying out tasks and working across applications, while saying that users remain in control of the access they grant it.
That model makes permission settings particularly important because the AI may need access to information stored across different parts of a device.
In the case involving Aten, the disagreement centres on how the information became available to Muse. Aten’s account suggested that notification syncing could have played a role, while Meta said that explanation was inaccurate and that Messages content requires specific permissions.
The conflicting accounts leave open questions about exactly what occurred on the device. NDTV Profit reported that the incident has renewed questions about how users can independently verify which information an AI agent is accessing.
Muse faces another privacy-related incident
The latest dispute comes shortly after another incident involving Muse and Facebook Marketplace.
YouTuber Matt Robb said Muse mishandled a Marketplace task, resulting in his home address being shared with a prospective buyer who arrived at his house while Robb was away. The incident raised concerns about how much autonomy users should give AI agents when they are allowed to negotiate transactions or communicate with other people.
Meta executive David Singleton has indicated that the company is examining that case.
The two incidents are different in nature. The Marketplace case involved an AI agent performing an action on a user’s behalf, while the latest dispute concerns alleged access to private messages on a Mac. However, both have focused attention on the relationship between AI autonomy, user permissions and data protection.
Meta’s privacy model under scrutiny
Meta introduced Muse in September as a personal AI agent designed to do more than answer questions. The company said Muse was built with a dedicated secure environment and that each user decides how much access the agent receives. Meta has also described security and privacy as core elements of Muse’s design.
The controversy demonstrates the practical challenge of communicating those controls to users. Permission systems can involve several operating-system settings, application-specific controls and individual connectors. If users do not clearly understand what each permission enables, they may find it difficult to determine what information an AI system can access.
For Meta, this is particularly relevant as it seeks to expand the use of AI agents beyond conventional question-and-answer services. The company is positioning Muse as a system that can take actions and work across the applications people use in everyday life.
For users, the incidents underline the importance of checking permissions before giving an AI agent access to sensitive information or allowing it to act independently. Meta’s latest response maintains that its technical safeguards prevent the Messages connector from accessing content without the required permissions, while the circumstances reported by Aten remain the subject of discussion.