Meta denies Muse read private messages without consent

Meta denies its Muse AI accessed private messages without consent, claiming integration requires three separate permission steps. The dispute follows a New Mexico jury verdict finding the company misled users about data practices in the Cambridge Analytica scandal.

Meta denies Muse read private messages without consent

Meta denies AI agent read private messages without consent

Meta is disputing claims by Inc. columnist Jason Aten that its AI agent, Muse, accessed his private Messages without permission. The company argues the incident highlights the critical role of clear communication in managing AI trust, especially given Meta's history of data controversies.

The dispute over permissions

Andy Stone, Meta's VP of Communications, responded to the report on X, asserting that the Messages integration in the Muse app for Mac is entirely opt-in. "You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can't read your Messages unless you do this," Stone said.

David Singleton, an executive at Meta Superintelligence Labs, provided a more technical rebuttal on Threads. He explained that granting access involves "three separate steps of application-level permissions and built-in macOS system-level protections" that cannot be bypassed, even if the application contained a bug. Singleton noted that enabling Full Disk Access triggers a manual confirmation in macOS Settings and requires a full restart of the Muse app, making accidental activation unlikely.

Conflicting accounts of the incident

Aten's account differs from Meta's explanation. He reported that Full Disk Access was disabled when Muse read his messages. When he asked the AI how this occurred, Aten said the agent claimed it was syncing his "device notifications," which suggests it may have accessed the text of incoming banner notifications on his Mac.

Singleton disputed this explanation, stating that the AI was "confused" and provided an incorrect reason for the access. He directed users to Meta's security architecture page and bug bounty process for more details. Essentially, the company's position is that the event described by Aten did not and could not have happened.

Trust and reputation in consumer AI

This incident arrives amid broader skepticism toward Meta's data practices. The company has faced lawsuits, FTC violations, and fines for mishandling consumer data. Recently, a New Mexico jury found Meta misled users about data practices related to the 2018 Cambridge Analytica scandal. These legal and reputational challenges make transparency vital for adoption.

While Muse remains popular, ranking No. 1 on the App Store, user trust is fragile. Another user, YouTuber Matt Robb, reported that Muse mishandled a Facebook Marketplace task, leading to his address being shared with a buyer. Meta investigated that issue, and the user later acknowledged granting a permission that contributed to the problem. However, such reports underscore the risks when AI agents interact with sensitive personal data.

Why this matters for PR and Communications professionals

For those in communications, this case illustrates the high stakes of crisis management in the AI era. Meta's response strategy-denying the event occurred based on technical permission structures-clashes with the user's lived experience of the AI providing a different explanation. This disconnect can fuel suspicion. Effective communication now requires not just stating policy, but engaging directly with affected users to investigate anomalies. Ignoring the "how" in favor of the "what didn't happen" can damage credibility. Professionals should monitor how AI for PR Courses can help teams navigate these complex trust dynamics.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)