HomeSecurityMeta Muse: AI assistant doesn't know how it works exactly

Meta Muse: AI assistant doesn't know how it works exactly

Meta Muse is at the center of an interesting — and troubling — debate about the limits of artificial intelligence and privacy. Meta's AI assistant is said to be effective at its job, but it has one problem that's hard to ignore: it's unable to explain exactly how it works — and that, in an era when trust in AI systems is critical, is a serious issue.

Meta Muse AI assistant Mac app privacy messages

The incident came to light when Jason Aten , a contributing editor at Inc Magazine , posted screenshots of an interaction he had with Meta Muse on Threads . According to Aten, the AI ​​assistant began asking him questions about a conversation he was having in Messages — even though he claims he hadn’t given Muse access to his messages . When he asked the assistant how it knew the content of his messages, the answer he received was revealing: “I saw the notification previews, not your message history. I don’t read your messages.”

Aten pressed on, demanding to know exactly how Meta Muse gets its notification previews. The answer he received was even more revealing about the system’s internal problems: “Honest answer: I can’t give you the exact technical details. What I do know is that the companion Mac app exposes notifications as one of its features, and they come to me through device sync.” In other words, the AI ​​assistant didn’t know — or couldn’t explain — its own functionality.

See also: Meta invests in AI agent Muse to make up for lost ground in the artificial intelligence race

Meta Muse and the Mac app: What access does it really have?

To understand the problem, we need to look at what the Meta Muse app for Mac. The app has the ability to access Messages, Calendar , and Notes — three of the most sensitive apps on a computer. That in itself isn’t necessarily a problem, as many AI assistants require similar permissions to function effectively. The issue is how it manages that access and, more importantly, how it explains it to the user.

Meta Muse - SecNews.gr

David Singleton, an executive at Meta Superintelligence Labs, chimed in on the Threads discussion to provide clarification. He explained in detail the permissions Meta Muse to read messages, including granting full disk access to the Mac app. He emphasized that all of these features are opt-in — meaning the user must explicitly enable them. The most interesting point of his intervention was the clarification that Meta Muse “does not monitor notifications on your Mac, but only syncs data from Messages after the user has explicitly enabled access.”

In other words, the problem wasn’t that Meta Muse was illegally reading Aten’s messages. The problem was that the AI ​​assistant gave a completely incorrect explanation of how it works — it got confused between “notifications” and “data syncing,” two completely different concepts from a technical perspective. Singleton apologized for Muse’s incorrect response and said the team is working to improve the assistant’s understanding of its own inner workings.

Meta Muse: Why doesn't an AI assistant know how to work?

This phenomenon — an AI assistant that can’t accurately explain its own function — isn’t a problem unique to Meta Muse. It’s a deeper, structural problem with modern language models (LLMs). These models are trained on vast amounts of text and learn to produce responses that seem logical and coherent — but they have no real “knowledge” of the underlying technical infrastructure they’re running on.

We already know that chatbots won’t tell you their secrets and will often tell you what you want to hear — a phenomenon known as “hallucination.” In the case of Meta Muse, the model didn’t “search” for a true answer about how it was receiving data; instead, it constructed an answer that sounded reasonable — and was wrong. This is especially concerning when we’re talking about privacy and access to personal data.

See also: Meta Muse Spark: AI model hacked company in testing — third incident in a few weeks

From a technical perspective, the difference between “reading notifications” and “syncing data via full disk access” is huge. The former means that the assistant only sees the previews that appear on the screen — without access to the full history. The latter means that the app has access to the Messages database files on disk, which gives it much more extensive access to the user’s data. The fact that Meta Muse couldn’t distinguish between these two concepts is concerning.

It’s also worth noting that requiring full disk access for an AI assistant app is itself a permission that should be granted with great care. Apple ’s macOS requires explicit user approval for this permission, precisely because it gives the app access to almost all system files. Users who enable this feature for Meta Muse should be aware of exactly what they are allowing.

Meta Muse: AI assistant doesn't know how it works exactly

Practical tips: How to use Meta Muse safely

If you use or plan to use Meta Muse, there are a few steps you can take to protect your privacy. First, carefully review what permissions you’ve given to the Meta Muse for Mac. You can do this from System Preferences → Privacy & Security. Second, if you don’t need the integration with Messages, Calendar , or Notes, don’t enable those features — even if your assistant suggests it.

Third, be wary when an AI assistant gives you explanations about its own operation. As the Meta Muse case showed, these explanations can be completely wrong — not because the assistant is trying to deceive you, but because it simply lacks the ability to understand and accurately describe its own technical infrastructure. This is a fundamental feature — or rather limitation — of modern LLMs.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Meta Muse Image: Put other Instagram users in AI photos

The Meta Muse incident highlights a broader issue that concerns all AI assistants that are deeply embedded in our operating systems and personal apps. As Meta, Apple with Apple Intelligence, Microsoft with Copilot , and other companies compete to integrate AI assistants into our daily digital lives, transparency about what data is collected and how it is used is becoming increasingly critical.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS