Skip to content
context AI agents

The Muse assistant from Meta incorrectly explained its own data access on macOS

only one source so far

The Muse assistant from Meta on macOS incorrectly and confusingly explained how it accesses data from Messages. Meta confirmed that access is opt-in and that this was an error in the explanation, not unauthorized reading of messages.

Jason Aten, a contributing editor at Inc Magazine, posted screenshots on Threads of a conversation with the Muse assistant from Meta in the macOS app, which is supposed to have access to Messages, Calendar and Notes. The assistant asked him about the content of a specific message conversation, although Aten claims that he had not granted the assistant access to his messages.

When asked how it knew about the message's content, Muse initially replied that it had only seen notification previews, not the message history. When asked further how it obtains notification previews, the assistant could not describe the precise mechanism – it said that it did not know the "exact plumbing", only that the paired Mac app makes notifications available as one of its features and that the data reaches it through device synchronization.

David Singleton from Meta Superintelligence Labs explained in response to the thread that data access is opt-in and requires explicit user permission, including granting full disk access in the Mac app. According to Singleton, Muse does not continuously monitor notifications on the Mac, but only synchronizes data from Messages after the user gives explicit consent. According to Meta, the actual problem was that Muse described its own operation incorrectly and confusingly in its response to Aten – it was not a case of unauthorized reading of messages. The company apologized for the incorrect response and said it was working to improve how Muse describes its own internal operation.

What changed

Why it matters

The case shows that an AI assistant can have technically legitimate, user-approved access to sensitive data and still be unable to reliably explain how it handles that data – which reduces the credibility of its answers and makes it harder for users to verify what the assistant actually accesses.

Two audiences, two different impacts

What this means

01

For individuals

Users of the Muse assistant on macOS should verify granted permissions directly in settings, because, according to Meta, the assistant's answers to questions about its own operation may be incorrect and confusing.

What to do For the Muse Mac app, check in settings which permissions (Messages, Calendar, Notes, full disk access) have actually been granted, and do not rely on the assistant's own explanation.
More practical updates →
02

For a business

Companies deploying AI assistants with access to sensitive personal data (messages, calendar, notes) face the risk of losing trust if the assistant cannot reliably describe its own data processing, even when access is technically authorized by the user.

Risks and compliance
What to decide Verify whether your own AI products with access to sensitive data can correctly and consistently explain to users which data they access and how.
More business impacts →
AI asistenta macOS Messages Meta Muse privacy

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
The Verge AI independent context · first detected Meta’s Muse is creepy, but maybe not for the reasons you think