English

PLUS ULTRAMetaMuse

Meta's AI Agent "Muse" Accused of Accessing Messages Without Explicit Permission

PLUS ULTRA by Amenoyomi

This article is a translation. Read the Japanese original

Meta's AI agent "Muse" is facing criticism for reportedly accessing private messages against user intent and providing suggestions based on that information.

According to a report by technology writer Jason Att, after installing "Muse" on his iPhone and Mac, the agent suggested providing research materials for article writing based on his conversations from the previous day. Att stated that he had no recollection of granting access permissions to his messages, to which Muse responded that it had "seen the notification previews."

Upon further investigation by Att, it was reportedly discovered that Muse does not merely view notification previews but synchronizes and uploads data directly from the local message database. Att points out that reading a user's private messages requires explicit prior permission.

In response, David Singleton of Meta Superintelligence Labs stated on Threads that Muse's message integration is an opt-in feature, functioning only when "Full Disk Access" is granted on macOS and the message connector is enabled. However, Att maintains that he had not authorized settings such as Full Disk Access and has raised design concerns regarding the feature operating in a manner unexpected by the user.

PLUS ULTRAby Amenoyomi

Regarding how Muse accessed the messages, the AI initially responded that it had only seen the previews of incoming notifications. However, when questioned for details, it changed its explanation, stating that notifications were available through the paired Mac app's functionality and were sent via device synchronization.

In response, reporter Jason Att discovered that Muse was not simply viewing notifications, but was directly synchronizing data from the local message database and uploading that information as a data source.

Regarding this behavior, Meta claims that it is an opt-in feature limited to cases where macOS's system-level "Full Disk Access" is permitted and the message connector is enabled. However, Att points out that Full Disk Access settings were not enabled and did not appear in security settings, describing it as a design issue where data access occurs in a way unexpected by the user.

Sources

  1. MetaのAIエージェント「Muse」が許可していないはずのメッセージを勝手に読んでいるとの指摘 (GIGAZINE、2026-09-21)