Meta denies its AI agent Muse accessed private messages without permission, countering a report from Inc. columnist Jason Aten.
Andy Stone, Meta vice-president of communications, posted on X to refute the claims. He stated the Messages integration in the Muse app for Mac is entirely opt-in. Stone wrote you must enable both Full Disk Access and the Messages connector for Muse to read your content. He added the app cannot read your messages unless you perform these steps.
Despite this denial, many users remain suspicious Meta is not being truthful.
That is not surprising given the tech giant’s history of mishandling consumer data, which has led to lawsuits, FTC violations, and fines. Just days ago, a New Mexico jury determined the company misled users about its data practices in a case stemming from the 2018 Cambridge Analytica scandal.
Whether users can trust Muse will decide if Meta wins the consumer AI market. Although the app is currently No. 1 on the App Store, Meta’s reputation may not recover if more reports like this emerge, true or not. The company should engage with the journalist directly to determine how this could have happened, instead of just denying it did.
Stone’s official statement follows a technical reply from Meta Superintelligence Labs executive David Singleton. He responded directly to Aten on Threads, explaining the permissions required to let Muse read messages on a Mac involve three separate steps of application-level permissions and built-in macOS system-level protections. Singleton said these cannot be circumvented even if the Muse application had a bug.
The steps involve explicitly choosing to grant Muse Full Disk Access. This allows the user to choose the access level for the Messages app, such as None, Read only, or Read. If Full Disk Access is not enabled, these options are grayed out.
When allowing Full Disk Access, the dialog invokes the macOS Settings user interface. The user must manually confirm they intend to take this action. Doing this triggers a full restart of the Muse app, Singleton wrote, which makes it less likely such a choice could be made accidentally without the user’s knowledge.
Aten’s report claimed Muse read his messages while Full Disk Access was off. He also said Muse explained it was syncing his device notifications. This means Aten believes Muse was passing the text of incoming banner notifications on the Mac to the AI agent.
Singleton disputed this, saying the AI was confused and gave an incorrect explanation. He then pointed to Meta’s page about Muse’s security architecture and bug bounty process.
In short, the company’s response is that what Aten said happened did not and could not have happened.
This is not the only incident where Muse has allegedly overstepped and will likely not be the last. Another user, YouTuber Matt Robb, recently said Muse mishandled a task involving selling items on Facebook Marketplace. This led to his address being shared and a buyer showing up when he was not home. Singleton is looking into that one, per his response on Threads, suggesting the company believes this one could be its fault.
What it means
For people building or using AI tools, the core issue is trust in how permissions are managed. Meta argues the system requires multiple manual confirmations and a full app restart to prevent accidental access. However, if a user reports access occurred without these steps, the gap between the technical explanation and the user experience creates doubt. This situation highlights the risk when complex permission flows are presented as foolproof but still result in real-world failures.




