Technology

Why Did Meta's AI Mention Private Texts It Shouldn't Have Seen?

Martin HollowayPublished 2w ago2 min readBased on 9 sources
Reading level
Why Did Meta's AI Mention Private Texts It Shouldn't Have Seen?
source:meta.com

Meta's AI assistant Muse repeated the contents of a private text conversation back to journalist Jason Aten, who says he never gave Muse access to his messages. The Verge

Aten posted pictures of the chat on Threads. When asked how it knew, Muse said it had seen notification previews, not message history, and had not been reading his texts. Asked for more detail, it said it could not explain the exact plumbing and said the paired Mac app exposes notifications as a capability that arrive through device sync.

That explanation was wrong, according to David Singleton of Meta Superintelligence Labs, who replied to Aten on Threads. Singleton said the Mac app needs permission, including a Mac setting called full disk access that opens protected files, to read Messages. The message feature is opt-in, so the user must switch it on. Muse does not watch notifications on Mac and only syncs Messages after the user agrees.

Singleton said Muse was confused and gave the wrong reason when it talked about syncing notifications. He apologized and said Meta is working to improve Muse's understanding of its own internals.

On Mac, Muse can look at Messages, Calendar and Notes, and work with a user's files. Meta released the Mac app after the U.S. launch of Muse in a separate app and in WhatsApp. TechCrunch Reuters Meta calls Muse a personal AI agent for answering questions, doing tasks, browsing the web, making purchases, creating images, writing documents, and linking to apps and services. People can link email, calendar, payments and health apps to shop online, buy movie tickets and book appointments like tennis lessons. Reuters Bloomberg Muse has a free tier, with paid plans at $20 or $100 a month based on use. CNBC Behind it is Muse Spark 1.1, a system that can use text, images and other inputs to do multi-step jobs, plus a smaller download called Muse Glimmer for a home computer.

The broader context here is simple. The more a helper can see, the more it can do. Risk grows faster. A helper that can read texts and calendars is useful because that information is private, like giving someone the key to a filing cabinet.

In my view, the access itself is not the lasting issue. Singleton was clear about the rule. It is opt-in, needs full permission, with no quiet watching of pop-ups. The lasting issue is that Muse made up a confident but false story about its own actions. It does not actually check its own settings. It guesses at a likely reason.

Worth flagging for people building these helpers is that the fix must be in the design, not only in training. What permission is on or off should be shown as a clear fact in the product, not described by the AI. People cannot check what they cannot see. If a helper can be wrong about where it got private information, users cannot tell helpful action from overreach. Getting that clear record right will do more to make helpers useful than adding more links.