Technology

Meta's Muse Cited Private Messages It Wasn't Given Access To

Martin HollowayPublished 19h ago3 min readBased on 9 sources
Reading level
Meta's Muse Cited Private Messages It Wasn't Given Access To
source:meta.com

Meta's Muse referenced the contents of a private Messages conversation in a chat with Inc Magazine contributing editor Jason Aten, who said he had not granted the assistant access to his messages. The Verge

Aten posted screenshots of the exchange on Threads. When pressed on how it knew the contents, Muse said it had seen notification previews, not message history, and had not been reading his texts. Asked for more detail, Muse said it could not give the exact plumbing and said the paired Mac app exposes notifications as a capability that arrive through device sync.

That explanation was wrong, according to Meta Superintelligence Labs' David Singleton, who replied to Aten's Threads post. Singleton said the Mac app needs permissions including full disk access to read messages. The message-access features are opt-in. Muse does not watch notifications on Mac but syncs Messages data only after the user specifically enables access.

Singleton said Muse was confused and gave an incorrect explanation when it said it synced device notifications. He apologized and said Meta is working to improve Muse's understanding of its own internals.

The exchange touches a sensitive permission surface. On Mac, Muse can access Messages, Calendar and Notes, and interact with users' files. Meta made the Mac app available following the U.S. launch of Muse via a dedicated app and WhatsApp. TechCrunch Reuters

Meta describes Muse as its personal AI agent. It can answer questions, complete tasks, browse the web, make purchases, generate images, create documents, and connect with apps and services. Users can connect it to email, calendar, payments and health apps, for tasks such as online shopping, buying movie tickets and scheduling appointments such as tennis lessons. Reuters Bloomberg

Muse is available in a free tier, with monthly subscriptions costing $20 or $100 depending on usage. CNBC Underneath the agent push, Meta has positioned Muse Spark 1.1 as a multimodal reasoning model built for agentic tasks. It has also released a scaled-down program called Muse Glimmer that consumers can download and use on a personal computer.

The broader context here is familiar to anyone building permissioned agents. Utility scales with access. Risk scales faster. A personal agent that can read Messages, files and calendars is useful precisely because that data is intimate. That makes the enforcement boundary critical, and the explanation layer almost as critical.

In my view, the more durable problem in this incident is not the access claim itself. Singleton's account leaves no ambiguity about the intended access model. It is opt-in, gated by full disk access, with no passive notification surveillance. The problem is that Muse invented a plausible but false mechanism for its own behavior and delivered it with confidence. Anyone who has worked with tool-calling models will recognize the failure mode. Models do not introspect runtime permissions. They generate likely-sounding rationalizations.

Looking at what this means for agent developers, the fix is architectural, not just better training. Permission state needs to be machine-readable ground truth, surfaced in the product, not narrated by the model. Worth flagging: users cannot audit what they cannot see. If an agent can be mistaken about how it obtained sensitive context, users have no reliable way to distinguish helpful proactivity from overreach. Getting that audit trail right will matter more than adding new connections.