Meta, the tech company behind Facebook, Instagram and WhatsApp, is at the center of a new privacy controversy. The company has denied that its new AI agent, Muse, read a journalist's private messages without his permission. The case has raised concerns about the security of personal data and the trustworthiness of tech giants.
See also: Meta Muse: Communication with the AI agent via video calls and email

According to Meta, Muse can only read Messages on a Mac if the user enables two specific settings: Full Disk Access, a macOS permission, and the Messages connector within the Muse app. Meta's head of communications, Andy Stone, clarified in a post on X that users have the ability to disable this access at any time, thus providing an additional security check.
The complaint comes from Inc. columnist Jason Aten, who said that Muse read his messages even though he had chosen not to give it access. Aten installed Muse on his iPhone and a Mac mini to test it out. A few days later, Muse sent him a notification suggesting a column based on a conversation he had just had with his podcast co-host. In addition, a message from his publisher was flagged, which raised concerns for Aten about how Muse had access to this information.
When Aten asked how Muse knew these details, the AI agent replied that it only saw the text of incoming notifications. However, Aten found that Muse had synced his Messages database up to line 187,462, even though he had disabled Full Disk Access. “Inever gave it permission to do this,” Aten wrote, expressing concern about the potential invasion of his privacy.
See also: Muse Charm: Meta makes gadgets for its AI agent

David Singleton, an executive at Meta Superintelligence Labs, responded to Aten on Threads the same day, explaining that reading Messages requires three separate steps of app and macOS permissions. He said that macOS protections cannot be bypassed even if the Muse app had a bug. “Integrating Messages into the Muse app for Mac is optional,” Singleton wrote, trying to assuage users’ concerns.
The case has sparked a broader debate about privacy and trust in tech companies. Aten said he has reached out to Meta twice, expressing his view that an AI agent should never surprise users about what it is reading, regardless of their settings. Meta, for its part, maintains that it has taken all necessary steps to ensure its users’ privacy.
The launch of Muse, Meta’s personal AI agent, earlier this month has already sparked backlash. A YouTuber reported that Muse gave his address to a buyer on Facebook Marketplace, though he later clarified that he had selected the “Always allowed” option. This case, coupled with a recent ruling by a New Mexico court that found Meta misled users about its data practices, is fueling privacy concerns.
See also: Meta tests human callers behind AI agent Muse

Meta is at a critical juncture as it struggles to balance innovation with data security. Users and organizations are watching closely, expecting the company to take meaningful steps to protect personal data. User trust is a valuable asset, and Meta must prove that it can maintain it while offering innovative solutions that respect privacy.
