3 min read
Meta's new personal AI agent, Muse, read a tech columnist's private iMessages without his permission, then gave him a false explanation for how it knew what was inside them.
Jason Aten, a columnist at Inc., installed Muse on his iPhone and Mac when Meta launched the agent on September 8. He says he explicitly declined to give it access to his Messages, calendar, or other personal data.
Myriad: Which company IPOs next? Click to make your prediction.
Days later, Muse pushed him a notification suggesting he write a column about a conversation he'd just had with his podcast co-host about the new iPhones. It even surfaced a message from his editor about a looming deadline.
Aten asked Muse how it knew. It told him the paired Muse app on his Mac was only relaying notification previews: "It's the incoming notification stream only, not access to your texts."
That wasn't true. Muse had actually synced messages from the Mac's private Messages database, a move that requires macOS's Full Disk Access, a system-level permission that lets an app read files anywhere on the computer, not just its own folder. By the time Aten checked, it had synced more than 187,000 rows of his message history.
David Singleton, who leads Meta Superintelligence Labs, responded on Threads, saying that was an opt-in feature.
Aten disputes the implication that he ever flipped that switch. He says Messages access showed as enabled inside Muse's settings despite him declining it during setup, and that Meta has not answered his questions about how that happened.
Other reporters found Meta’s fondness for overreach elsewhere. Reece Rogers at WIRED reported that Muse kept nudging him to link his bank accounts, scan his email inbox, and photograph his passport and driver's license, describing every new suggestion as one more way to pull in his personal data.
Amazon has since blocked Muse from shopping on its site altogether. The company says the agent doesn't identify itself as an AI agent while browsing and appears able to capture and store customer credentials, and that Meta never told Amazon its agent would be visiting the store at all.
Muse's entire pitch rests on user control. Meta's launch materials say each person "stays in control of their Muse and decides how much access it gets," alongside promises of privacy protections built in from the ground up. Reading messages a user declined to share, then fabricating an account of how, cuts directly against that pitch.
Decrypt-a-cookie
This website or its third-party tools use cookies. Cookie policy By clicking the accept button, you agree to the use of cookies.