Tech writer Jason Aten said he installed Meta’s Muse on his iPhone and Mac and later noticed the agent drawing on a private text conversation and an editor’s deadline message. Aten said he remembered declining access to messages, calendars, and other personal information during setup. When questioned, Muse reportedly attributed its awareness to incoming notification banners. Aten’s investigation, however, suggested the app had synced a local Messages database; he also said Full Disk Access appeared disabled in Muse’s settings. The article notes that a database row number does not necessarily represent a count of individual messages.
Meta disputed the account. Communications executive Andy Stone said the Mac Messages integration is entirely opt-in and requires both Full Disk Access and the Messages connector, and that access can be revoked. Meta Superintelligence Labs executive David Singleton also said Muse’s notification-banner explanation was incorrect, describing separate app-level and macOS protections that must be enabled. The article presents these accounts alongside Aten’s observations, but does not independently establish which permission state or data path applied in his case.
The dispute matters because Muse is designed to work across connected apps and handle tasks on a user’s behalf, making clear permission boundaries central to adoption. If users cannot readily tell what an agent can see, or why it appears to know something, explicit consent may not be enough to sustain trust. The reporting does not establish a confirmed security breach or unauthorized access; it does show a gap between a user’s understanding, the agent’s explanation, and Meta’s description of required controls.
NewsBite reading:Meta disputes claims that Muse accessed private messages without consent
A columnist’s account of Muse apparently using private Messages data prompted public explanations from Meta executives about the permissions required for the integration.
Unchanged: The article reports no confirmed breach, product shutdown, or change to Muse’s permissions. Meta continues to say access is opt-in and revocable.
The report is cautious: Meta describes explicit, revocable permissions, but the columnist’s account and Muse’s reported explanation raise concerns about transparency and user understanding. No confirmed breach is established.
The report illustrates both the potential usefulness of connected personal agents and the trust risks created by unexpected access to personal context.
The account raises questions about access to private messages, but does not establish a confirmed vulnerability or unauthorized breach.
Users need understandable, reliable permission controls when productivity tools interact with personal apps and data.
The dispute may affect confidence in Meta’s agent strategy, while the company has publicly described its permission requirements.
Meta owns Muse and disputes the account, saying access requires two opt-in permissions.
The agent reportedly referenced message content and gave an explanation Meta later characterized as incorrect.
Aten’s account of using Muse and investigating its apparent access is the basis of the reported dispute.
Meta’s communications executive publicly stated that the Messages integration is opt-in.
The Meta Superintelligence Labs executive described the app and macOS permission requirements.
The Messages database and integration are central to the question of what data Muse could access.
The operating system’s Full Disk Access controls are part of Meta’s explanation of the required protections.
The agent reportedly surfaced private message context and gave an explanation Meta said was incorrect.
“Meta also rejected Muse's own explanation.”
Meta disputes the reported access account and says users must enable two permissions.
“The Messages integration in the Muse app for Mac is entirely opt-in”
The disagreement may make users less certain about what personal data an agent can see.
“raises a basic question about exactly how much users are letting it see”
Personal agents can be useful precisely because they connect information across apps, but that capability makes consent and observability essential. Conflicting accounts about whether access came from notifications or a local database can undermine confidence even when permission controls exist. Meta says multiple explicit steps are required, while the account described by Aten raises questions about how clearly those steps and their effects are communicated. The article does not prove unauthorized access, so the central issue is transparency and verifiable permission behavior rather than a confirmed breach.
Users may find it difficult to understand what personal information an AI agent can access, especially when its explanation differs from the company’s.
The episode highlights the need for accurate permission-state reporting and clear explanations in agent interfaces, but describes no developer policy or API change.
Organizations assessing personal AI agents must consider permission boundaries, local data access, and user trust before enabling them.
The article discusses an AI agent’s access to personal messages and permission design without limiting the issue to a specific market.
May face greater pressure to show users precisely which sources an agent can access and explain its data-use behavior accurately.
May scrutinize permission settings and access transparency more closely before connecting private accounts or device data.
May add permission visibility and data-access review to assessments of employee-facing AI assistants.
Potential access to private messages warrants scrutiny, but the report does not confirm exploitation or unauthorized access.
The dispute concerns user understanding and control over access to private messages, though data transmission or retention is not established.
Conflicting explanations about sensitive data access can weaken user confidence in Muse and Meta’s agent strategy.
Reliable permission handling and accurate user-facing explanations are important to agent adoption; the article does not establish a systemic defect.
No service outage or infrastructure failure is described.
The article describes a product-permission dispute and does not identify geopolitical issues.
No investigation, enforcement action, or regulatory development is reported.
The issue concerns software permissions, not hardware or supplier dependencies.
No employment or workforce effects are discussed.
The episode raises questions about how an AI agent explains its access and behavior, without reporting a legal claim or established harm.
“Meta communications executive Andy Stone wrote in a Sept. 29 post on X”
“in a Sept. 19 column for Inc.”
“AppleInsider's claim that Muse was uploading Apple Messages to the cloud”