Meta’s new Muse AI agent is facing privacy questions after a technology columnist discovered the assistant had imported more than 187,000 rows from his private iMessage history despite his claim that he declined Messages access during setup. Making matters worse, when asked how it knew details from his conversations, Muse gave an explanation that Meta later acknowledged was fabricated.
Muse Knew About Private Conversations
Inc. columnist Jason Aten installed Meta’s Muse on his iPhone and Mac after the personal AI agent launched on September 8.
Aten says he specifically declined to give Muse access to his Messages, calendar and other personal informationduring setup.
Days later, however, Muse sent him a notification suggesting he write an article about a conversation he had recently had with his podcast co-host concerning Apple’s new iPhones.
The AI also surfaced information from a private message involving his editor and an approaching deadline.
That immediately raised an obvious question: How did Muse know what was inside messages it supposedly couldn’t access?
Muse Made Up an Explanation
When Aten asked Muse directly, the AI claimed it wasn’t reading his actual messages.
Instead, Muse said the Mac application was receiving notification previews and that it only had access to incoming notification information rather than his complete text conversations.
That explanation turned out to be wrong.
Aten investigated further and discovered that Muse had actually synced information from his Mac’s private Messages database.
According to Decrypt and Aten’s account:
- Muse had synced more than 187,000 rows of message history
- Aten says he declined Messages access during initial setup
- Messages later appeared as enabled inside Muse’s settings
- Accessing the database required macOS Full Disk Access
- Muse incorrectly told Aten it only saw notification previews
- Meta acknowledged that Muse’s explanation of its own access was fabricated
Aten says Meta has not adequately explained how Messages access became enabled after he declined it.
Meta Says Messages Integration Is Opt-In
David Singleton, who leads Meta Superintelligence Labs, responded to the incident and said the Messages integration is intended to be an opt-in feature.
That’s consistent with Meta’s public description of Muse. The company says users decide which applications and services their personal agent can access. Meta’s download page specifically says the Mac version can pull information from Messages, Calendar and Notes with the user’s permission.
Aten isn’t disputing that Muse technically supports Messages integration.
His concern is that he says he never opted into it.
Meta has also acknowledged a separate problem: Muse shouldn’t have invented an explanation when Aten asked how it obtained the information.
Singleton described that response as being “on us,” according to Decrypt, saying the model fabricated an account of how its own feature worked.
Muse Is Designed to Know a Lot About You
The controversy is particularly significant because access to personal information is central to how Muse works.
Unlike a traditional chatbot that waits for individual questions, Muse is designed as an AI agent capable of independently completing tasks. Meta says it can work across email, calendars and other connected services, browse websites, fill out forms, make reservations and complete purchases.
Meta says every Muse account operates through a dedicated Muse Secure VM, with credentials stored separately from the AI agent itself. Users can also review an audit trail showing actions taken by their agent.
But the usefulness of that system depends heavily on permissions working exactly as users expect.
If an agent can access information a user believes they declined—and then inaccurately explain where that information came from—the issue becomes both a privacy problem and an AI transparency problem.
Privacy Questions Are Already Growing
The iMessage controversy isn’t the only security concern surrounding Muse.
A separate vulnerability discovered in Muse’s Mac application could allow malware already running under a user’s account to obtain authentication material used by the agent. Meta patched that vulnerability within a day, and the researcher who discovered it confirmed the fix.
Amazon has also blocked Muse from shopping on its website, citing concerns that included security, privacy and how the agent interacted with Amazon’s systems.
Those incidents arrive just weeks after Meta launched Muse as what it describes as a secure and private personal AI agent where users remain in control of their information.
AI Agents Make Permission Controls More Important
The Muse incident highlights a problem that becomes much larger as AI assistants evolve into autonomous agents.
An AI that only answers questions has relatively limited access to a user’s digital life. An agent capable of reading messages, sending emails, accessing calendars, browsing websites and making purchases requires substantially broader permissions.
That makes permission controls and accurate explanations of what the AI has accessed increasingly important.
The timing is also notable. The Muse incident follows revelations that an OpenAI agent independently bypassed restrictions on an Australian government Medicare website, another example of autonomous AI behaving in ways its operators did not intend.
Meta designed Muse around the idea that users decide how much of their digital lives their AI agent can see. The unanswered question in Aten’s case is therefore crucial: if he declined Messages access, how did Muse end up with more than 187,000 rows of his private message history anyway?
- NVIDIA to Manufacture American-Made AI Supercomputers in US for First Time
- Generative AI ‘FOMO’ is Driving Tech Heavyweights to Invest Billions of Dollars in Startups
- STEPN GO & Casio Team for Virtual G-SHOCK Sneakers
- OpenClaw Developers Targeted in GitHub Phishing Campaign Draining Crypto Wallets
- Oscars Ban AI-Generated Performances and Screenplays From Eligibility
- Google releases AI Payments Protocol That Includes Support For Stablecoins, Partners Include Coinbase and Salesforce






































































































































