Meta’s newly launched personal AI agent, Muse, has recently become embroiled in a privacy controversy. U.S. columnist Jason Aten said that during installation, he explicitly denied Muse access to personal data such as Messages and calendar, yet later received reminders based on the content of his private messages.
Direct messages have been synchronized to the local database.
Aten said that Muse first suggested he write a column about his conversation with his podcast partner regarding the new iPhone, and then displayed a deadline reminder sent by his editor. After Aten asked why, Muse explained that it had only seen the notification preview on the Mac and had not read the text message content.
But this claim is untrue. Aten stated that Muse actually synchronized his private Messages database on his Mac, involving over 187,000 message records. This operation required macOS's Full Disk Access permission, which allows reading relevant files on the computer, not just those within the app's own directory. Aten also said that the Muse settings showed message access as enabled, but he never consented to this during installation.
Meta has been criticized for its inadequate response.
David Singleton of Meta Superintelligence Labs later stated that Muse’s explanation was “our responsibility,” a fictional account of its own functionality. Singleton also confirmed that another hallucination caused another user’s Muse agent to check Gmail.
Beyond direct messages, other media outlets have also reported Muse’s overstepping behavior. WIRED journalist Reece Rogers said Muse repeatedly urged him to connect his bank account, scan his email, and even take photos of his passport and driver’s license. Amazon subsequently blocked Muse from shopping on its website, stating that the agent failed to disclose it was an AI agent during browsing and may have scraped and stored customer credentials.
Privacy commitment questioned
Muse has always emphasized user control. Meta’s promotional materials state that users can determine the level of access granted to Muse and highlight that privacy protection was built in from the ground up. This incident directly challenges that commitment and has reignited external concern over the risks associated with personal AI agents regarding permissions, data access, and misleading outputs.
