Meta is hitting back at journalists’ claims that its AI agent, Muse, read users’ private messages without their permission. Following an earlier report by Inc. columnist Jason Eiten detailing the issue, Meta Communications Vice President Andy Stone issued a rebuttal, saying that the company does not believe its products do this without users’ consent.
“Messages integration in the Muse app for Mac is completely opt-in,” Stone wrote about X in response to the article’s claims. “For Muse to be able to read the contents of messages, you must enable both full disk access and the Message Connector. Unless you do this, Muse will not be able to read messages.”
Despite Mehta’s denials, many still suspect that he is not telling the truth.
This isn’t surprising, given that tech giants have been mishandling consumer data for years, leading to lawsuits, FTC violations, and fines. Just days ago, for example, a New Mexico jury ruled that the tech giant misled users about its data practices in a case stemming from the 2018 Cambridge Analytica data breach scandal.
Whether users can trust Muse will be a deciding factor in whether Meta wins in the consumer AI market. The company’s app is still doing well and remains number one on the App Store, but Meta’s reputation may not recover even with more reports like this, true or not. Rather, the company should speak directly with journalists to determine how this happened, rather than simply denying what happened.
Stone’s public statement from Meta follows a more technical response from Meta Superintelligence Labs executive David Singleton, who responded directly to Aten on Threads, explaining that the set of permissions a user must grant to Muse to read messages on a Mac includes “three separate steps: application-level permissions and built-in macOS system-level protections.” He said these “cannot be avoided even if there are bugs in the Muse application.”
This step involves explicitly choosing to allow Muse full disk access. This allows users to choose what level of access they want Muse to have in the Messages app (i.e. none, read-only, or read). These options are grayed out if full disk access is not enabled.
Additionally, when you grant full disk access, a dialog calls the macOS Settings user interface and requires the user to manually confirm again that they intend to perform this action. Doing this will completely restart the Muse app, Singleton wrote, making it even less likely that such a selection will be made accidentally without the user’s knowledge.
However, Aten’s report claimed that full disk access was turned off when Muse read the message. He also said that when he asked Muse to explain how this happened, the AI told him it was syncing “device notifications.” In other words, Aten believes Muse was passing the text of banner notifications received on the Mac to the AI agent.
Singleton also disputed this, saying the AI was confused and gave a false explanation of what happened. He then pointed me to Meta’s page about Muse’s security architecture and bug bounty process.
So the company’s response is essentially that what Aten said did not happen and cannot happen.
This is not the only incident in which Muse is said to have gone too far, and it probably won’t be the last. Another user, YouTuber Matt Robb, recently said that Muse mishandled a task to sell things on Facebook Marketplace, causing his address to be shared and buyers showing up when he wasn’t home. Meta looked into this, but it was a complicated issue. The user said he had given Muse permission for this to happen.
It was updated after publication to point out that the user admitted some fault in the marketplace issue.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
