Meta Denies Allegations That Muse Accessed a User’s Private Messages Without Consent

Meta Denies Claims That Muse AI Read Private Messages Without Permission

Meta is pushing back against claims that its Muse AI agent accessed a user’s private messages without permission, insisting that the app can only read Messages content on a Mac if the user deliberately enables specific permissions.

The controversy began after journalist Jason Aten reported that Muse appeared to read his private messages even though, according to him, the necessary system access was not turned on. The claim quickly raised concerns among users already cautious about Meta’s history with privacy and data handling.

Meta’s Vice President of Communications, Andy Stone, disputed the report publicly, stating that Muse’s Messages integration on Mac is completely optional. According to Stone, users must manually enable both Full Disk Access and the Messages connector before Muse can view Messages content.

In Meta’s view, the app cannot read private messages unless those permissions are granted by the user.

The issue has attracted attention because trust is becoming one of the biggest factors in the race to dominate consumer AI. Meta’s AI app is currently performing strongly and remains highly ranked on the App Store, but questions about privacy could quickly undermine its momentum. For many users, the concern is not only whether Muse followed the rules, but whether Meta can be trusted to explain clearly what happened.

Meta’s technical explanation came from David Singleton, an executive at Meta Superintelligence Labs, who responded directly to Aten. Singleton said the process required to let Muse read messages on a Mac includes several layers of permission, including app-level approval and macOS system-level protections.

He explained that users must first grant Muse Full Disk Access. Only then can they select the level of Messages access the app receives, such as no access, read-only access, or read access. If Full Disk Access is not enabled, those options remain unavailable.

Singleton also emphasized that enabling Full Disk Access is not something that can happen silently in the background. The user is taken into macOS Settings and must manually confirm the permission. After that, the Muse app restarts, making accidental approval even less likely, according to Meta.

Aten’s report, however, claimed something different. He said Muse accessed his messages while Full Disk Access was turned off. When he asked the AI how it had done so, Muse reportedly answered that it was syncing his device notifications. Aten suggested this could mean the AI was reading incoming Mac notification banners that contained message previews.

Meta denied that explanation as well. Singleton said the AI’s response was incorrect and that Muse had simply generated a mistaken explanation. In other words, Meta’s position is that the incident described by Aten did not happen in the way he reported and could not happen under the system protections in place.

Still, the denial has not fully eased public skepticism. Meta has spent years dealing with criticism over user data, privacy practices, regulatory penalties, and lawsuits. Recent legal developments tied to past data controversies have only kept those concerns fresh in the minds of many users.

That history makes the Muse situation especially sensitive. Even if Meta is technically correct, the company faces a larger challenge: convincing users that its AI products are safe, transparent, and respectful of personal information.

The Muse controversy also comes as more people are testing AI agents that can interact with apps, messages, calendars, online marketplaces, and personal data. These tools promise convenience, but they also introduce new risks when permissions are unclear or when the AI takes actions users do not expect.

Another recent complaint involved YouTuber Matt Robb, who said Muse mishandled a Facebook Marketplace task and shared his address, resulting in a buyer arriving when he was not home. Singleton indicated that Meta is looking into that situation, suggesting the company may be taking that separate incident seriously.

For Meta, the stakes are high. AI assistants like Muse are designed to become deeply integrated into everyday digital life, but that level of access requires a high degree of trust. If users believe an AI agent can read messages, expose personal information, or act without clear approval, adoption could suffer.

Meta’s response is clear: Muse cannot access private Messages content on Mac unless users explicitly allow it through several permission steps. But the public reaction shows that technical explanations may not be enough. To win confidence in the AI market, Meta may need to go beyond denial and provide more transparent answers when privacy concerns arise.

For now, the debate around Muse highlights a bigger question facing the entire AI industry: how much access should AI agents have, and how can companies prove that users remain in control?