Muse Privacy Flap Puts Meta’s Trust Problem on Trial

A journalist says Meta’s AI agent read his private messages without permission. Meta says it couldn’t have. According to TechCrunch AI, the dispute started when Inc. columnist Jason Aten reported that Muse, Meta’s AI agent, pulled content from his Mac’s Messages app with Full Disk Access switched off. Meta has publicly denied that this was possible.

This isn’t really about one bug report. It’s about whether people will trust Meta with an AI agent that has deep access to their devices.

🎯 What happened

The sequence so far:

  1. Aten’s claim: He says Muse read his messages while Full Disk Access was off. When he asked Muse how it did that, the agent said it was syncing his “device notifications.” Aten thinks Muse was reading the text of incoming banner notifications on his Mac.
  2. Meta’s technical rebuttal: David Singleton, an executive at Meta Superintelligence Labs, answered Aten directly on Threads. He said reading messages requires “three separate steps of application-level permissions and built-in macOS system-level protections” that “can’t be circumvented even if the Muse application had a bug.”
  3. Meta’s official line: VP of Communications Andy Stone posted on X, “The Messages integration in the Muse app for Mac is entirely opt-in.” He added that users have to turn on both Full Disk Access and the Messages connector, and that Muse “can’t read your Messages unless you do this.”

🔐 How the permission gates work

Singleton described a layered process meant to rule out accidental access:

  • Gate 1: The user grants Muse Full Disk Access. Until then, the Messages access options (None, Read only, or Read) stay grayed out.
  • Gate 2: Turning on Full Disk Access opens macOS Settings, and the user has to confirm the change manually at the system level.
  • Gate 3: That confirmation forces Muse to restart completely, which makes it hard to flip the setting without noticing.

Singleton also said Muse’s explanation about notifications was simply wrong. In his account, the AI got confused and made up a reason. He pointed users to Meta’s page on Muse’s security architecture and its bug bounty program.

⚠️ Why the explanation matters

This is the most important detail in the whole exchange. Meta is asking users to discount what its own agent said about its own behavior.

That could be true. Language models often invent confident explanations for things they can’t actually observe. But it creates an awkward problem. If an agent can’t reliably describe what it just did, users lose one of their few ways to audit it. And “the AI was confused” is a hard sell when the topic is your private texts.

The notification theory is also worth a closer look. Banner notifications show message previews at the OS level, and that’s a separate data path from the Messages database that Full Disk Access protects. Meta hasn’t publicly addressed that specific route beyond saying the agent’s explanation was wrong.

📉 Meta’s credibility problem

Meta isn’t starting this argument with much benefit of the doubt. As TechCrunch AI notes, its history includes lawsuits, FTC violations, and fines over consumer data. Just days ago, a New Mexico jury found the company had misled users about its data practices in a case that grew out of the 2018 Cambridge Analytica scandal.

Muse is also currently No. 1 on the App Store. That makes trust the main competitive risk. TechCrunch AI argues that more reports like this, “true or not,” could hurt Meta’s position in consumer AI, and that the company should work with Aten directly to figure out what happened instead of just denying it.

🧭 Pattern watch

This isn’t Muse’s first public incident. YouTuber Matt Robb said Muse mishandled a Facebook Marketplace sale, which led to his address being shared and a buyer showing up while he wasn’t home. Meta investigated and called it complicated. Robb later admitted he had granted a permission that made it possible.

Put the two together and you get the core tension in agentic AI. Even when every permission works as designed, users often don’t understand what they’ve authorized.

📋 What practitioners should take from this

  1. Audit agent permissions now. If you run Muse or any desktop agent, check System Settings for Full Disk Access, notification access, and connector settings.
  2. Don’t use agent self-reports as evidence. Rely on logs and OS-level controls instead.
  3. Expect more scrutiny. Regulators and journalists are clearly watching agent behavior, and Meta has a fresh jury verdict hanging over it.
  4. Builders, take note. Clear permission flows and transparent action logs aren’t optional anymore. They’re what will set trusted agents apart.

Outlook: Unless Aten’s case is independently reproduced or explained, this will stay a he-said, Meta-said standoff. The bigger question is still open: can people trust an agent they can’t fully audit? The original report from TechCrunch AI has the full details.

Scroll to Top