Meta Denies AI Agent Muse Read Private Messages Without Permission
Tech

Meta Denies AI Agent Muse Read Private Messages Without Permission

TechNews Editorial
TechNews EditorialOct 1, 2026 · 2 min read
Share

Why it matters

User trust in Muse will help determine if Meta wins the consumer AI market, though past data mishandling and new reports complicate its reputation.

The facts

  • Meta is refuting claims that its Muse AI agent read a user private messages without permission.
  • Company executives stated that macOS system protections and opt-in settings make unauthorized reading impossible.
  • The reporting follows previous controversies regarding consumer data handling and trust in Meta AI products.

Meta is refuting a journalist claim that its AI agent Muse read private messages without permission. The issue follows an earlier report from Inc. columnist Jason Aten detailing the incident.

Andy Stone, Meta VP of Communications, pushed back on X by stating the company does not believe the product acted without consent. Stone noted the Messages integration in the Muse app for Mac is entirely opt-in.

Users must enable both Full Disk Access and the Messages connector for Muse to read message content. Stone emphasized that the software cannot read messages unless a user takes these steps.

Read nextDoorDash Launches Text-to-Order AI Agent for Apple Messages

Meta executives explained security permissions

David Singleton, a Meta Superintelligence Labs executive, responded directly to Aten on Threads. Singleton explained that the required permissions involve three separate steps of application-level permissions and built-in macOS system-level protections. He stated these protections cannot be circumvented even if the application contained a bug.

The process requires explicitly choosing to grant Full Disk Access. This choice allows the user to select the level of access granted to the Messages app, such as None, Read only, or Read. Without Full Disk Access enabled, these specific options remain grayed out.

Enabling Full Disk Access invokes the macOS Settings user interface where a user must manually confirm the action. This step triggers a full restart of the Muse app. Singleton argued this makes accidental activation without user knowledge extremely unlikely.

A user manually confirms expanded computer access, then watches the assistant app restart while its controls are temporarily unavailable.
Illustration: AI & Tech News

The journalist maintained his original claims

Aten claimed that Full Disk Access was turned off when Muse read his messages. When asked for an explanation, the AI reportedly stated it was syncing device notifications. Aten believes Muse was passing along incoming banner notifications from the Mac to the AI agent.

Singleton disputed this explanation by stating the AI was confused and provided an incorrect account. He pointed toward Meta documentation covering the security architecture and bug bounty process for Muse. Meta maintains that the events described by Aten did not and could not happen.

User trust remains critical for Meta as it attempts to win the consumer AI market. The Muse app currently ranks number one on the App Store. However, past data mishandling incidents and ongoing legal scrutiny complicate consumer confidence.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading