Meta is refuting a journalistâÂÂs claim that its AI agent Muse read the userâÂÂs private messages without permission. Following an earlier report from Inc. columnist Jason Aten that detailed the issue, Meta VP of Communications Andy Stone pushed back, making it clear that the company does not believe its product did this without the userâÂÂs consent.
âÂÂThe Messages integration in the Muse app for Mac is entirely opt-in,â Stone wrote on X in response to the claims made by the piece. âÂÂYou have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It canâÂÂt read your Messages unless you do this.âÂÂ
Despite MetaâÂÂs denial, many people are still suspicious that Meta isnâÂÂt being truthful.
ThatâÂÂs not surprising, given the tech giantâÂÂs years of mishandling consumer data, which has led to lawsuits, FTC violations, and fines. Just days ago, for instance, a New Mexico jury determined the tech giant had misled users about its data practices in a case that resulted from the 2018 Cambridge Analytica data breach scandal.
Whether users can trust Muse will be a deciding factor in whether or not Meta wins the consumer AI market. Although its app is faring well now, and remains No. 1 on the App Store, MetaâÂÂs reputation may not recover if more reports like this emerge, true or not. If anything, the company should be engaging with the journalist directly to determine how this could have possibly happened, instead of just denying that it did.
StoneâÂÂs official statement from Meta follows a more technical reply from Meta Superintelligence Labs executive David Singleton, who responded directly to Aten on Threads, explaining that the set of permissions a user must grant to let Muse read their messages on the Mac involves âÂÂthree separate steps of application-level permissions and built-in macOS system-level protections.â He said these âÂÂcanâÂÂt be circumvented even if the Muse application had a bug.âÂÂ
The steps involve explicitly choosing to grant Muse Full Disk Access, which would then allow the user to choose what level of access Muse is being granted to the Messages app (i.e., None, Read only, or Read). If Full Disk Access is not enabled, these options are grayed out.
In addition, when allowing Full Disk Access, the dialog invokes the macOS Settings user interface, where the user has to again manually confirm that they intend to take this action. Doing this triggers a full restart of the Muse app, Singleton wrote, which makes it even less likely that such a choice could be made accidentally without the userâÂÂs knowledge.
However, AtenâÂÂs report claimed that when Muse read his messages, Full Disk Access was off. He also said that when he asked Muse to explain how this occurred, the AI said that it was syncing his âÂÂdevice notifications.â That means, Aten believes, that Muse was passing along the text of his incoming banner notifications on the Mac to the AI agent.
Singleton disputed this, too, saying that the AI was confused and gave an incorrect explanation of what happened. He then pointed to MetaâÂÂs page about MuseâÂÂs security architecture and bug bounty process.
In short, the companyâÂÂs response is essentially that what Aten said happened did not and could not have happened.
This is not the only incident where Muse has allegedly overstepped and wonâÂÂt likely be the last. Another user, YouTuber Matt Robb, recently said that Muse mishandled a task in which he was selling things on Facebook Marketplace, leading to his address being shared and a buyer showing up when he wasnâÂÂt even home. Singleton is apparently looking into that one, per his response on Threads, suggesting that the company believes this one, at least, could be its fault.
When you purchase through links in our articles, we may earn a small commission. This doesnâÂÂt affect our editorial independence.
