Meta disputes claim that Muse read a user’s private messages without permission

Meta is fighting back against a journalist’s claim that its AI agent Muse read the user’s private messages without permission. Following an earlier report from Inc. columnist Jason Aten that detailed the issue, Meta VP of Communications Andy Stone pushed back , making it clear that the company does not believe its product did this without the user’s consent.
“The Messages integration in the Muse app for Mac is entirely opt-in,” Stone wrote on X in response to the claims made by the piece. “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can’t read your Messages unless you do this.”
Despite Meta’s denial, many people are still suspicious that Meta isn’t being truthful.
That’s not surprising , given the tech giant’s years of mishandling consumer data , which has led to lawsuits , FTC violations , and fines . Just days ago, for instance, a New Mexico jury determined the tech giant had misled users about its data practices in a case that resulted from the 2018 Cambridge Analytica data breach scandal.
Whether users can trust Muse will be a deciding factor in whether or not Meta wins the consumer AI market. Although its app is faring well now, and remains No. 1 on the App Store, Meta’s reputation may not recover if more reports like this emerge, true or not. If anything, the company should be engaging with the journalist directly to determine how this could have possibly happened, instead of just denying that it did.
Stone’s official statement from Meta follows a more technical reply from Meta Superintelligence Labs executive David Singleton, who responded directly to Aten on Threads, explaining that the set of permissions a user must grant to let Muse read their messages on the Mac involves “three separate steps of application-level permissions and built-in macOS system-level protections.” He said these “can’t be circumvented even if the Muse application had a bug.”
The steps involve explicitly choosing to grant Muse Full Disk Access, which would then allow the user to choose what level of access Muse is being granted to the Messages app (i.e., None, Read only, or Read). If Full Disk Access is not enabled, these options are grayed out.
In addition, when allowing Full Disk Access, the dialog invokes the macOS Settings user interface, where the user has to again manually confirm that they intend to take this action. Doing this triggers a full restart of the Muse app, Singleton wrote, which makes it even less likely that such a choice could be made accidentally without the user’s knowledge.
However, Aten’s report claimed that when Muse read his messages, Full Disk Access was off. He also said that when he asked Muse to explain how this occurred, the AI said that it was syncing his “device notifications.” That means, Aten believes, that Muse was passing along the text of his incoming banner notifications on the Mac to the AI agent.
Singleton disputed this, too, saying that the AI was confused and gave an incorrect explanation of what happened. He then pointed to Meta’s page about Muse’s security architecture and bug bounty process.
In short, the company’s response is essentially that what Aten said happened did not and could not have happened.
This is not the only incident where Muse has allegedly overstepped and won’t likely be the last. Another user, YouTuber Matt Robb, recently said that Muse mishandled a task in which he was selling things on Facebook Marketplace, leading to his address being shared and a buyer showing up when he wasn’t even home . Meta looked into this one, it was a complicated issue. The user said they did allow Muse a permission that had allowed this to happen.
Updated after publication to note that the user admitted some fault in the Marketplace issue.
When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.


Get 50% off a second pass The Disrupt experience is meant to be shared. Get your pass and bring a colleague, partner, or peer at 50% off. Cover more ground by making connections, building momentum, and discovering what’s next in the startup ecosystem.
AMD will acquire Fei-Fei Li’s World Labs for $8.2B
Viral AI agent Instinct raises $1B Series C at a $10B valuation
Crusoe abandons $1.25B plan to use Boom turbines at AI data centers
Unsecured OpenAI agents posted 53 user images on the internet without the lab’s knowledge
Astra and Opus just passed Turing’s other test
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
Oracle sends force majeure notice on its New Mexico Stargate data center
Verified source · TechCrunch
Reported by TechCrunch. Open the original for full media and formatting.
More in Agents
All news
AgentsOpenAI’s Jev clone could help the frontier lab stop its swarming agents
OpenAI's "Decisions API" is a Jev clone that confirms the importance of fast, cheap intelligence.
Read at TechCrunch
AgentsDoorDash launches an AI agent you can text to order food
By launching an AI agent for food ordering, DoorDash is looking to gain an edge over rivals Uber Eats and Grubhub.
Read at TechCrunch
AgentsAll the latest news on Meta’s cute, creepy Muse AI agent
Meta launched a new Muse AI agent it claims can help you with everything from firing off emails to buying stuff online. Muse can be surprisingly effective at delivering on those promises — if you’re willing to trust Meta with your data and hand Muse your credit card. Since the l…
Read at The Verge
AgentsRestate lands $20M as the need for durable infrastructure increases with AI agents
Instead of building its durable execution engine on top of an external database, the company developed its own storage, replication, and redundancy layers. This architecture allows Restate to be exceptionally fast and lightweight.
Read at TechCrunch