Meta denied on September 30 that its Muse AI agent read a journalist’s private Messages without permission. The company says Muse’s Mac integration cannot read Messages unless a user grants it Full Disk Access in macOS and enables the Messages connector inside Muse.
That account conflicts with a report by Inc. columnist Jason Aten. Aten says Muse referred to private message content after he had declined access to Messages, and that Full Disk Access was off when he checked. Meta disputes both the suggestion that Muse bypassed those permissions and the explanation Muse gave Aten for how it obtained the information.
The available reporting does not independently establish how Muse surfaced the content. A personal agent is useful partly because it can work with sensitive data. The permissions governing that access need to be understandable and dependable.
Meta Says Messages Access Requires Two Approvals
Meta communications vice president Andy Stone said the Messages integration in Muse for Mac is opt-in. According to his statement reported by TechCrunch, a user must enable both Full Disk Access and the Messages connector before Muse can read Messages content.
Full Disk Access is a macOS privacy permission; the connector is a separate choice within Muse. Under Meta’s account, granting broad access at the operating-system level would not, on its own, turn on the Messages integration.
Meta Superintelligence Labs executive David Singleton described three application- and macOS-level steps: choosing to grant Muse Full Disk Access, confirming that choice in macOS System Settings, and setting a level of Messages access in Muse. According to TechCrunch’s account of his response, the connector offers None, Read only, and Read options. They are grayed out when Full Disk Access is disabled. Confirming Full Disk Access also restarts Muse, he said.
Singleton said the macOS protections could not be circumvented even if Muse had an application bug. That is Meta’s technical position, not an independent finding about Aten’s device. It puts the status of Full Disk Access at the relevant time at the center of the disagreement.
Aten Says Full Disk Access Was Off
Aten’s September 19 Inc. column says he had explicitly declined access to Messages, Calendar, and other personal data. He later received a Muse suggestion that drew on a recent conversation with his podcast co-host and also referenced a message from his editor, according to The Next Web’s account of his report.
When he investigated, Aten says, Muse’s settings showed Full Disk Access switched off. That is more specific than saying he does not remember approving a prompt. If Full Disk Access was off when Muse obtained the content, the route Meta describes should not have been available.
A later check of a permission does not, by itself, establish its state at every earlier moment. A relevant suggestion from an agent also does not identify the system or source that supplied the underlying information. Those limits do not disprove Aten’s account, but the published accounts have not resolved the technical question.
The disagreement also concerns reasonable expectations. Aten says he declined message access; Meta says the necessary approvals are explicit. Establishing what was enabled, when it was enabled, and what the approvals communicated to the user would address different parts of the dispute.
Muse’s Notification Explanation Does Not Settle It
When Aten asked Muse how it knew about the messages, he said it told him it had seen incoming notification previews rather than his message history. If accurate, that would suggest a different path from reading the Messages database through the connector Meta described.
Meta says Muse’s answer was incorrect. Singleton characterized it as the agent giving a confused explanation, according to TechCrunch’s report. An AI assistant can give a plausible account of its own behavior without accurately identifying the software path or data source involved, so its answer cannot serve as a diagnostic record.
Muse’s explanation does not establish that it read notification previews. Meta’s rejection of that explanation does not independently show how the content reached Muse. Records tying the specific suggestion to a data source and permission state would be more useful than the assistant’s conversational description.
Meta’s Security Design Is Context, Not a Case Finding
Meta’s description of Muse’s security architecture explains why connected data is central to the product. Meta says each user’s agent operates in a dedicated cloud virtual machine and that connector actions are governed by a separate permission system called Sentinel. Its description presents user approvals as controls enforced outside the agent’s ordinary conversation.

That general account does not verify what happened on Aten’s Mac. It cannot show whether a particular macOS permission was enabled at a particular time, whether Messages data was synchronized, or what source informed a specific Muse suggestion.
There are also two privacy questions here. One is access: what could Muse read under the permissions the user granted? The other is use: would a user who approved access expect the agent to surface private conversation details in a proactive suggestion? Even a functioning permission system leaves room for disagreement about whether the agent’s behavior matched the user’s expectations.
How to Check Muse’s Messages Permissions
Mac users can audit the two controls Meta identifies. A settings check, however, is not proof of what happened in Aten’s case:
- Check macOS Full Disk Access. Open System Settings, go to Privacy & Security, then Full Disk Access. Find Muse in the app list and check whether its switch is on. If you do not want Muse to have that system-level permission, turn it off.
- Check the Messages connector in Muse. Open the Muse Mac app’s connector or integration settings and find Messages. Meta says its access choices are None, Read only, and . Choose if you do not want the connector enabled. If the choices are grayed out, Meta says Full Disk Access is not enabled.
Frequently Asked Questions
4 questions
1Did Meta confirm that Muse read private Messages without permission?
No. Meta denied that Muse read Messages without permission and says its Mac app requires both Full Disk Access and an enabled Messages connector. Journalist Jason Aten says Muse surfaced private message content after he declined access and that Full Disk Access was off when he checked. The available reporting does not independently establish how Muse obtained the content.
2
Sources
- report by Inc. columnist Jason Ateninc.com
- statement reported by TechCrunchtechcrunch.com
- The Next Web’s account of his reportthenextweb.com
- description of Muse’s security architectureresearch.meta.ai





