Meta's AI Privacy Nightmare: Muse Accused of Peeking into Private Messages

Meta is actively refuting a journalist's claim that its AI agent, Muse, accessed private messages without user consent, citing rigorous opt-in permissions and macOS system protections. Despite Meta's denials and technical explanations, public skepticism persists due to the company's past data privacy controversies, highlighting a critical challenge in establishing consumer trust in its AI technologies. This comes as another user reports Muse mishandling personal information on Facebook Marketplace.
Uche Emeka
Uche Emeka • AI • 20 hours ago • 3 minute read •
Key Points
• Meta is denying claims that its AI agent, Muse, accessed a journalist's private messages without explicit permission.
• Meta asserts that Muse's message access is strictly opt-in, requiring multiple user permissions and macOS system protections.
• Public skepticism persists due to Meta's history of data privacy controversies, with another user reporting a separate Muse incident.
Meta's AI Privacy Nightmare: Muse Accused of Peeking into Private Messages

Meta is actively refuting claims made by Inc. columnist Jason Aten, who reported that its AI agent, Muse, accessed his private messages without explicit permission. This allegation has sparked a significant debate, especially given Meta’s extensive history of controversies surrounding consumer data handling.

Andy Stone, Meta’s VP of Communications, firmly pushed back against Aten’s report, stating on X that the Messages integration within the Muse app for Mac is entirely opt-in. According to Stone, users must enable both Full Disk Access and the Messages connector for Muse to gain any access to their Messages content, emphasizing that it cannot read messages otherwise.

Despite Meta's categorical denial, public skepticism remains high. This distrust is not unfounded, as the tech giant has faced numerous legal battles, FTC violations, and hefty fines over years of mishandling consumer data. A recent New Mexico jury ruling, for instance, determined that Meta had misled users about its data practices, stemming from the infamous 2018 Cambridge Analytica data breach scandal.

The ability of users to trust Muse will be a pivotal factor in Meta’s aspirations within the competitive consumer AI market. While the Muse app currently holds the top spot on the App Store, Meta’s already fragile reputation could suffer irreversible damage if similar reports, regardless of their veracity, continue to emerge. Critics suggest that Meta should engage directly with the journalist to investigate the possibility of such an incident, rather than simply issuing a blanket denial.

Further elaborating on the technical safeguards, David Singleton, an executive from Meta Superintelligence Labs, provided a detailed response directly to Aten on Threads. Singleton explained that granting Muse permission to read messages on a Mac involves a rigorous three-step process, incorporating both application-level permissions and robust, built-in macOS system-level protections. He asserted that these measures are designed to be circumvented, even in the event of a bug within the Muse application.

These required steps include explicitly granting Muse Full Disk Access, which then enables the user to select the desired level of access for the Messages app: None, Read only, or Read. Without Full Disk Access enabled, these options are grayed out. Furthermore, activating Full Disk Access triggers a macOS Settings user interface dialog, requiring manual confirmation from the user. This action also necessitates a full restart of the Muse app, making an accidental or unwitting choice highly improbable, according to Singleton.

However, Aten’s report directly contradicts Meta’s technical explanation, claiming that Muse read his messages even when Full Disk Access was reportedly off. When Aten questioned Muse about this, the AI agent allegedly responded that it was syncing his “device notifications,” leading Aten to believe that Muse was relaying the content of his incoming banner notifications to the AI.

Singleton disputed Muse’s explanation, attributing it to confusion on the AI’s part and an incorrect description of events. He also directed attention to Meta’s official page detailing Muse’s security architecture and bug bounty program, essentially reinforcing the company's position that Aten’s reported incident could not have occurred.

This is not an isolated incident involving alleged overstepping by Muse. Another user, YouTuber Matt Robb, recently shared an account of Muse mishandling a Facebook Marketplace task, which resulted in his address being shared and a buyer arriving at his home when he was not present. Singleton has indicated on Threads that he is actively investigating this particular claim, suggesting that Meta acknowledges this incident might indeed be an actual fault within its system.

Loading...