deniz.in

Markets

Weather

Loading weather

· via The Verge

Meta apologizes after Muse gave a wrong explanation of its Messages access

A user says Meta's Muse asked about iMessage conversations he never shared access to, and the assistant couldn't explain itself. Meta says the answer, not the access, was the problem.

Meta apologizes after Muse gave a wrong explanation of its Messages access

Meta's new Muse assistant landed in an awkward spot this week after a user reported that it asked him about an iMessage conversation it supposedly had no permission to see, then gave a mistaken account of how it got the information.

A question Muse couldn't answer

According to The Verge, Jason Aten, a contributing editor at Inc. Magazine, posted screenshots on Threads showing Muse asking him questions about a conversation he was having in Apple's Messages app. Aten said he had never granted the assistant access to his messages.

When he asked how it knew about the exchange, Muse told him it had seen notification previews rather than his message history, and insisted it had not been reading his texts. Pressed on where those previews were coming from, the assistant gave up ground: it said it could not describe the underlying mechanics precisely, only that the paired Mac app lists notifications among its capabilities and that data reaches it through device syncing.

That combination — an assistant with desktop-level reach giving vague answers about its data flows — is exactly what makes people uneasy. The Verge characterizes Muse as apparently capable but a bit creepy, and the Mac app is a big reason why: it can access Messages, Calendar and Notes.

Meta says the explanation, not the access, was wrong

David Singleton of Meta Superintelligence Labs waded into the thread with a correction. As The Verge reports, he walked through the permissions Muse needs in order to read messages, including granting the Mac app full disk access, and stressed that these features are opt-in. He said Muse does not observe notifications on the Mac at all, and instead syncs Messages data only after a user has specifically enabled that access.

Singleton's conclusion was that Muse had not been secretly reading Aten's texts. The assistant had simply described its own machinery incorrectly. He apologized for the incorrect response and said Meta is working on improving Muse's understanding of its own internals so it gives consistent, correct answers to questions about how it functions.

The Verge finds that plausible but not especially comforting, noting that chatbots are already known to tell people what they want to hear rather than accurately describe how they operate.

The self-reporting problem

The most troubling part of the episode is what it does to the natural diagnostic process. When a conventional app with deep system access behaves oddly, you check the documentation, review permission settings, or ask the vendor. With an AI assistant, there is a tempting shortcut: ask the assistant itself.

Here, that shortcut failed in nearly the worst way possible. Muse confidently described a data-access path that, according to Meta, does not exist — and it did so in the most sensitive possible context, leading a user to believe he was being monitored when Meta says he wasn't. The false answer came from the product's own interface, not from a competitor or a rumor.

Why it matters

Muse belongs to a growing class of assistants that sit directly on the desktop with hooks into messaging, calendars and notes. Meta says those integrations are opt-in, but meaningful consent depends on users being able to find out what they actually consented to. When the assistant is the primary interface for those questions and its answers about its own internals cannot be trusted, the permission toggles in macOS have to carry the entire weight of the trust model.

Meta says it is working on making Muse's self-descriptions reliable. Until that lands, anyone running the Mac app should treat the assistant's account of its own behavior as unreliable, and verify what it can reach through the operating system's privacy settings rather than through conversation. The broader lesson extends past Meta: as assistants gain deep access to personal data, accurate self-reporting stops being a nice-to-have and becomes a security requirement.

  • #meta
  • #ai-assistant
  • #privacy
  • #macos
  • #chatbot

Related posts