deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Meta disputes claim its Muse AI agent read a journalist's private messages

Meta is publicly disputing an Inc. columnist's claim that its Muse AI agent read his private messages without permission, insisting the Mac Messages integration is opt-in and protected by multiple system safeguards.

Meta disputes claim its Muse AI agent read a journalist's private messages

Meta is publicly disputing a journalist's claim that its AI agent, Muse, read his private messages without permission. According to TechCrunch, the controversy began with a report by Inc. columnist Jason Aten describing the incident, and Meta has since pushed back at both the communications and engineering level.

What Meta says

Andy Stone, Meta's VP of Communications, addressed the claim on X, stating that the Messages integration in Muse's Mac app is "entirely opt-in" and that the agent cannot read message content unless the user enables both Full Disk Access and the Messages connector.

A more technical rebuttal came from David Singleton, an executive at Meta Superintelligence Labs, who replied to Aten directly on Threads. As TechCrunch reports, Singleton walked through the permission chain: a user must explicitly grant Muse Full Disk Access, after which they can choose an access level for the Messages app — none, read only, or read. Without Full Disk Access, those options are greyed out. Granting it summons the macOS Settings interface for a second manual confirmation and forces a full restart of the Muse app, which Singleton argued makes accidental authorisation unlikely. He said these layers of application-level permissions and macOS system protections cannot be circumvented "even if the Muse application had a bug."

What the journalist says

Aten's account contradicts that sequence. He maintains that Full Disk Access was switched off when Muse read his messages, and that when he asked the agent to explain itself, Muse told him it was syncing his "device notifications." His theory, as relayed by TechCrunch, is that Muse was passing the text of his incoming Mac banner notifications along to the agent.

Singleton rejected this too, saying the AI was confused and gave an incorrect explanation of its own behaviour, and pointed to Meta's published material on Muse's security architecture and bug bounty programme. The company's position, in effect, is that what Aten described neither happened nor could have happened.

A wider pattern of questions

The Messages dispute is not the only recent allegation against Muse. TechCrunch notes that YouTuber Matt Robb said the agent mishandled a Facebook Marketplace task, resulting in his home address being shared with a buyer who showed up at his home while he was out. Singleton indicated on Threads that he is looking into that case — a response TechCrunch reads as a sign the company considers it, at least, potentially its own fault.

Public scepticism toward Meta's denial also has a backdrop. The company's long record of data-handling failures — lawsuits, FTC violations and fines — colours how its assurances are received, and TechCrunch points out that just days earlier a New Mexico jury found Meta had misled users about its data practices in a case that grew out of the 2018 Cambridge Analytica scandal.

Why it matters

The episode exposes a structural weakness of AI agents: they operate with delegated access to deeply personal systems, and when something appears to go wrong, the agent's own account of its behaviour is unreliable evidence. Both Aten's claim and Meta's rebuttal ultimately rest on what the permissions layer did, yet the only firsthand explanation came from Muse itself — and Meta says that explanation was wrong.

It is also a trust test at a critical moment for Meta's consumer AI push. Muse is currently No. 1 on the App Store, according to TechCrunch, but the outlet argues that user trust will decide whether Meta can win the consumer AI market, and that further reports like this one — whether accurate or not — could do lasting damage to the company's reputation. TechCrunch suggests Meta would be better served working directly with the journalist to establish how the incident could have occurred, rather than simply denying that it did.

  • #ai-agents
  • #privacy
  • #meta
  • #macos
  • #messaging

Related posts