Cute plush character with headphones using a laptop, surrounded by a plant, phone, and origami on a desk.

Meta denies Muse AI agent accessed private messages without permission

Meta denies Muse read private messages without permission, but the AI privacy dispute is fueling fresh doubts about its consumer AI trust.

Updated September 30, 2026 8:23 pm

In short

Meta continues to deny Muse accessed private messages without consent, while new allegations of a separate marketplace-related mistake add to scrutiny of the company’s AI assistant.

  • Meta denies Muse accessed Messages without consent and says the feature is fully opt-in.
  • The journalist behind the claim says Muse appeared to read messages even with Full Disk Access off.
  • Meta’s privacy reputation is under pressure amid long-running criticism and recent legal setbacks.
  • The dispute could affect trust in Muse as Meta competes in the consumer AI market.

Update — September 30, 2026 8:23 pm

TechCrunch’s updated report adds a new example of Muse allegedly mishandling a task. YouTuber Matt Robb said the assistant exposed his home address while he was trying to sell items on Facebook Marketplace, which led a buyer to show up when he was not home.

The new report says Meta executive David Singleton is reviewing that incident, suggesting the company may view it as a possible product error rather than a deliberate permission issue.

Meta is pushing back hard against claims that its Muse AI agent read a user’s private messages on a Mac without consent. The company says Muse only gains access to Messages content after a user explicitly turns on multiple permissions, but the dispute has renewed questions about whether people can trust Meta’s consumer AI products with sensitive data.

The controversy matters because Muse is one of Meta’s most visible attempts to bring AI agents into everyday personal computing, and its success depends not only on capability but on confidence. If users believe the assistant can see more than they intended, that could slow adoption even as the app climbs to the top of the App Store.

What triggered the dispute?

The dispute began after Inc. columnist Jason Aten published a report describing what he believed was an unexpected privacy incident involving Muse on a Mac. According to Aten, the AI agent appeared to read messages he had not knowingly authorized it to access, raising the possibility that Muse had somehow reached into private communications.

Meta says that interpretation is wrong. In a public response, Meta vice president of communications Andy Stone said the Messages integration in the Muse Mac app is completely opt-in and cannot work unless a user manually enables the necessary settings.

“The Messages integration in the Muse app for Mac is entirely opt-in,” Meta’s Andy Stone said. “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can’t read your Messages unless you do this.”

The disagreement is not simply about one user’s experience. It goes to the heart of how AI agents should be evaluated when they operate inside operating systems, app permissions, and notification systems that are often confusing even to technically savvy users.

How does Meta say Muse gets access to Messages?

Meta says the process requires a user to take several deliberate steps on macOS before Muse can interact with Messages content. According to the company, the setup involves application-level permissions as well as operating-system protections that are not supposed to be bypassed.

David Singleton, an executive with Meta Superintelligence Labs, offered a more technical explanation on Threads. He said the user must complete multiple permission prompts and that those protections cannot be overridden by a bug in the app.

Why does Meta believe the access was intentional?

Meta’s position is that the permissions chain is too explicit to happen accidentally. In its view, a user must first grant Muse Full Disk Access, then separately decide whether to allow access to Messages, and then confirm the choice again through macOS’s own security interface.

That process, according to Singleton, makes it difficult to imagine the app reading Messages content without the user understanding what was happening.

  • The user must first enable Full Disk Access.
  • The user must then choose a level of Messages access.
  • macOS presents another confirmation screen before activation.
  • The app restarts after permission is granted.

Meta’s argument is straightforward: if the app could read messages, the user had to authorize it.

What did the journalist say happened?

Aten’s account points in the opposite direction. He said Muse appeared to read messages even though Full Disk Access was off, which would appear to contradict Meta’s explanation of how the product is supposed to work.

He also said that when he asked the assistant to explain what had happened, Muse reportedly said it was syncing his “device notifications.” Aten interpreted that response to mean the app may have been ingesting the text of incoming banner alerts on his Mac, rather than reading Messages through the explicit settings Meta describes.

Meta disputes that explanation as well. Singleton said the AI was mistaken in the way it described the event and argued that the model had simply produced an incorrect account of the situation.

In effect, the company says the reported privacy breach did not happen and, given the permission structure, could not have happened as described.

Why are users still skeptical?

Users are skeptical because Meta’s privacy record remains one of the company’s biggest liabilities. The skepticism is not limited to one journalist’s report; it reflects years of public concern over how Meta has handled consumer data across its products and platforms.

That history includes litigation, regulatory penalties and repeated criticism over how the company collected, used or disclosed personal information. The shadow of the Cambridge Analytica scandal still looms large, and a recent New Mexico jury finding that Meta misled users about its data practices only deepened the perception that the company struggles to earn trust on privacy matters.

For many people, the issue is not whether Meta says Muse is secure. It is whether the company has enough credibility left to convince users to believe it when something appears to go wrong.

Meta critics argue that repeated privacy disputes make it harder to accept the company’s denials at face value, especially when the product in question is an AI agent designed to interact with sensitive personal information.

Why this matters for Meta’s AI ambitions

The Muse controversy arrives at a sensitive moment for Meta’s broader AI strategy. The company is trying to compete for consumer attention in a crowded market where convenience is important, but trust may be even more important.

Muse is currently performing well from a distribution standpoint, with Meta’s app holding the No. 1 position on the App Store at the time of the report. But top rankings do not guarantee long-term loyalty. If users begin to think the app mishandles private data, growth could stall quickly.

That is especially true for a product positioned as an AI agent, not just a chatbot. Agents are expected to do things on a user’s behalf, which often requires access to calendars, files, messages, contacts and notifications. The more powerful the assistant becomes, the more privacy risk it can appear to introduce.

In practical terms, Muse’s success depends on a delicate equation:

  1. It must be useful enough to justify deeper access.
  2. Its permissions must be understandable to ordinary users.
  3. Its security model must be believable when disputes arise.
  4. Its maker must have enough public trust to calm concern quickly.

Meta is trying to prove all four at once.

What is Meta’s technical defense?

Meta’s technical defense rests on the idea that macOS itself enforces the boundaries around Messages access. According to Singleton, the company’s setup page and security architecture spell out how the feature works and how users can verify permission settings.

The company also pointed to its bug bounty process, suggesting that security researchers can probe the system for weaknesses and report vulnerabilities if they find any. That is meant to reinforce Meta’s claim that the product is built with layered protections rather than hidden access paths.

Still, technical explanations do not always settle user concerns. Security systems can be described accurately and yet still produce experiences that feel opaque or surprising to people using them in the real world. That is one reason privacy controversies around AI tend to linger even after companies issue denials.

Issue Meta’s position Journalist’s claim Why it matters
Messages access Opt-in only, requires explicit permission Messages appeared to be read without authorization Determines whether a privacy violation occurred
Full Disk Access Must be enabled before Messages integration works Full Disk Access was off when the incident happened Tests whether the feature could have operated as designed
System behavior macOS protections cannot be bypassed by a bug Muse gave a different explanation involving notifications Raises questions about how the AI interpreted the event
Trust impact Meta says the report is inaccurate Users remain doubtful Affects adoption of Muse and Meta’s consumer AI plans

What else has gone wrong with Muse?

The privacy dispute is not the only recent complaint about Muse’s behavior. Another user, YouTuber Matt Robb, recently said the agent mishandled a Facebook Marketplace task in a way that exposed his home address to a buyer.

According to that account, the buyer arrived while Robb was not home, creating an obvious safety concern. Singleton responded to that complaint as well and indicated that Meta was looking into it, suggesting the company sees at least that incident as potentially related to a genuine product error.

That distinction matters. If one complaint is a user misunderstanding and another is a true product failure, Meta will need to explain where the line is between legitimate access, confusing defaults and actual mistakes.

How does Meta handle criticism of Muse?

Meta appears to be responding on a case-by-case basis, using public statements, technical explanations and direct replies from executives on social platforms. That approach can be effective for rapid-fire rebuttals, but it also puts the company in a reactive posture when privacy concerns dominate the conversation.

The challenge is that consumer AI products often depend on an emotional contract with users. People are not just asking whether the software is secure in a narrow technical sense; they want assurance that the assistant will behave exactly as expected when it touches personal data.

In that environment, even a disputed report can have an outsized effect.

How much should one disputed incident matter?

One incident may not define a product, but it can shape early public perception. For a new AI assistant, the first major privacy story can become a reference point for future debates, especially if the company involved already has a reputation for mishandling data.

That is why Meta’s response is so forceful. The company is not only denying an accusation; it is trying to prevent a narrative from hardening that Muse is the kind of AI product that quietly sees more than it should.

Even if Meta is correct on the facts, the episode illustrates a broader problem for the AI industry: users often cannot easily tell whether an assistant accessed information because they knowingly enabled it, because an interface was confusing, or because the system behaved in a way they did not expect.

Those distinctions matter greatly to engineers and security teams. To ordinary users, they often feel like the same problem: “Did the AI read my private information or not?”

What happens next?

For Meta, the immediate task is to convince people that Muse’s permissions model is real, understandable and reliable. That means more than issuing denials. It may require clearer documentation, better in-product warnings and faster investigation of reports that appear to show unexpected access.

It may also require the company to engage more directly with critics when incidents arise, rather than simply rejecting the claim. In privacy disputes, perception often changes only when users feel that a company has taken the allegation seriously enough to explain exactly what happened.

For now, the dispute leaves Muse in an uneasy position. The app is popular, Meta is insisting the security model is sound, and yet a sizable share of the public remains unconvinced.

That tension may define the next stage of consumer AI. The winners will not just be the products that can do the most. They will be the ones users believe will keep their personal information out of the wrong places.

Key facts at a glance

Item Details
Company Meta
Product Muse AI agent for Mac
Report date September 30, 2026
Core allegation Muse allegedly read private Messages content without permission
Meta response Denied the claim and said access requires explicit opt-in permissions
Why it matters Raises trust and privacy concerns around consumer AI agents
Related issue Another user reported a separate Marketplace mishap involving address exposure

Meta may have won a technical argument, but it still faces a trust problem. In the consumer AI race, that may be the harder battle to win.

Frequently asked questions

Did Meta’s Muse AI read private messages without permission?

Meta says no, and it insists Muse cannot access Messages content unless a user explicitly enables both Full Disk Access and the Messages connector. The journalist who raised the issue says the app appeared to read messages even though he had not knowingly authorized that level of access.

How does Muse get access to Messages on Mac?

According to Meta, the user must manually grant Full Disk Access, choose a Messages permission level, and confirm the choice through macOS settings. Meta says those steps are required before Muse can read Messages content and that the protections cannot be bypassed by an app bug.

Why are people skeptical of Meta’s denial?

Many users are skeptical because Meta has a long history of privacy controversies, lawsuits and fines. That track record makes some people less willing to accept the company’s explanation at face value when a new report suggests sensitive data may have been exposed.

How is this dispute affecting Meta’s AI strategy?

The dispute could hurt trust in Muse at a time when Meta is trying to build a consumer AI product people will let into their personal data. Even if the app is popular now, privacy doubts can slow adoption if users worry the assistant may overreach.

Share this 🚀