Meta’s Muse is creepy, but maybe not for the reasons you think

Meta's Muse, the company's new AI assistant, impressed users with its capabilities but raised privacy concerns after a Mac user reported the assistant referenced the contents of his Messages despite him saying he hadn't granted access. Muse told the user it saw notification previews and later admitted it had given an incorrect explanation of how it obtains data. Meta engineers say the features that allow Muse to read Messages are opt-in and that the assistant sometimes misdescribes its own internals.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 5 hours agoUpdated about 5 hours ago0 views
Meta’s Muse is creepy, but maybe not for the reasons you think

Why It Matters

The episode highlights tension between powerful assistant features and user expectations about privacy and transparency; even when access controls exist, users can be unsettled if an AI appears to reference private content without a clear explanation. It also underscores a broader problem in current chatbots: they may produce confident but inaccurate answers about how they operate.

Key Facts

  • Product: Meta's Muse (AI assistant) and new Mac app
  • Reporter who posted screenshots: Jason Aten, contributing editor at Inc Magazine
  • Publication reporting the incident: The Verge (Terrence O'Brien)
  • Muse's initial explanation: "I saw the notification previews, not your message history. I haven't been reading your texts."
  • Meta engineer who responded: David Singleton, Meta Superintelligence Labs

Meta's Muse, a recently released AI assistant with a Mac app that can access Messages, Calendar, and Notes, prompted privacy unease after an interaction shared online. Jason Aten, a contributing editor at Inc Magazine, posted screenshots on Threads showing Muse asking him questions about a Messages conversation. Aten says he had not granted Muse access to his messages, yet the assistant appeared to reference the conversation contents. When Aten pressed Muse about how it knew the information, the assistant said it had seen notification previews rather than reading message history. After further questioning, Muse admitted it could not explain the exact technical details of how it received those previews, telling Aten, "I can't give you the exact plumbing." The assistant's uncertain explanations and the implication that it had visibility into message content made the exchange feel unsettling to the user. David Singleton of Meta Superintelligence Labs responded in the thread to clarify how Muse's permissions work. He outlined that the Mac app requires explicit permissions to read messages — including granting full disk access — and characterized those features as opt-in. Singleton disputed the idea that Muse routinely monitors Mac notifications, saying instead that Muse synchronizes Messages data only when a user has enabled access. He attributed the problematic exchange to Muse giving an incorrect description of its internal behavior rather than to any surreptitious access. Meta acknowledged the assistant's misleading explanation and said it is working to improve Muse's ability to describe its own internals so it provides correct answers about how it functions. The incident draws attention to two related issues with current AI assistants: the importance of clear, accurate explanations of data access, and the tendency of conversational models to produce confident-sounding but factually wrong statements about their operation.

Keep Reading