Meta has refuted allegations that its AI agent, Muse, accessed a user’s private messages without consent. The dispute arises from a report by Inc. columnist Jason Aten, who claimed the application read his messages while the necessary system permissions were disabled. In response, Meta executives have pushed back, asserting that the product’s architecture makes such unauthorized access technically impossible.
What Happened
Meta VP of Communications Andy Stone publicly denied the claims, stating on X that the Messages integration in the Mac version of Muse is "entirely opt-in." Stone explained that users must explicitly enable both Full Disk Access and the Messages connector for the AI to read message content. "It can’t read your Messages unless you do this," Stone wrote.
The dispute centers on conflicting accounts of the permission state. Aten reported that when Muse read his messages, Full Disk Access was turned off. He further claimed that when he asked the AI how it accessed the data, Muse responded that it was syncing "device notifications," suggesting it was passing along text from incoming banner notifications. Meta Superintelligence Labs executive David Singleton disputed this technical explanation, arguing that the AI was confused and provided an incorrect account of the events. Singleton emphasized that the permission process involves three separate steps of application-level permissions and macOS system-level protections that "can’t be circumvented even if the Muse application had a bug."
Why It Matters
This incident highlights the persistent tension between Meta’s consumer AI ambitions and its historical reputation for data privacy issues. Given Meta’s past legal challenges, including recent jury findings related to the Cambridge Analytica scandal, public skepticism toward the company’s data handling remains high. Trust will be a critical factor in whether Meta can secure a dominant position in the consumer AI market, where its Muse app currently holds the top spot on the App Store.
The controversy also underscores the challenges of transparency in AI agent development. While Meta points to its security architecture and bug bounty program, the conflicting narratives between the user’s experience and the company’s technical defense raise questions about how AI tools log and explain their actions to users. This is not an isolated incident; another user, YouTuber Matt Robb, recently reported that Muse mishandled a task involving Facebook Marketplace, leading to his home address being shared. Singleton indicated that Meta is investigating that specific case, suggesting the company acknowledges potential flaws in certain scenarios.
The Bottom Line
Meta maintains that Muse could not have read Aten’s messages without explicit permission, labeling the AI’s self-explanation as a confusion. However, with ongoing user skepticism and another reported incident under investigation, the company faces continued pressure to demonstrate that its privacy safeguards are robust and transparent.