Two complaints about Meta’s Muse AI agent have become part of the same backlash, though they describe different problems. Inc. columnist Jason Aten says Muse surfaced information from his private messages despite his belief that he had withheld access. Meta disputes that the agent could have read those messages without explicit permission. Separately, YouTuber Matt Robb says Muse shared his pickup address with a Facebook Marketplace buyer after he selected an “Allow Always” option whose reach he misunderstood.
Aten’s account remains an unresolved allegation about access. Robb describes an agent acting under a permission its user says he did not understand. Neither incident should be described as a confirmed unauthorized breach. Together, they raise questions about both technical controls and the way permission choices are presented.
Aten and Meta Disagree About Messages Access
In his account of using Muse, Aten says the agent brought up details from private communications even though he believed he had not authorized its Messages integration. When he checked his Mac, Full Disk Access appeared disabled for Muse. How, he asks, did Muse obtain information he thought was outside its reach?
Meta says the access Aten describes cannot occur through the Messages integration without two permissions. As TechCrunch reported in Meta’s response, communications vice president Andy Stone said a user must enable both macOS Full Disk Access and the Messages connector in Muse before the app can read Messages content. Meta Superintelligence Labs executive David Singleton described additional app-level choices and a macOS confirmation step. He said a Muse app bug cannot bypass those protections.
The available reporting does not reconcile Aten’s observation with Meta’s explanation. A screenshot showing a setting disabled when it was checked does not establish the complete history of an app’s permissions. Meta’s description of how the system is designed to work does not independently determine what happened on Aten’s device, either. No independent technical reproduction cited in the available reporting establishes that Muse bypassed macOS permissions or read Messages without authorization.
Aten reported that, when asked how it knew the information, Muse said it had obtained text from notification banners. Singleton said that explanation was wrong and that the model was confused. A chatbot’s account of its own access is not a forensic record. The relevant evidence would be the permissions and data flows, not an explanation the model generated after the fact.
Meta’s Security Design Does Not Settle the Dispute
Meta’s published account of Muse’s security architecture describes an agent that can work with connected services while a separate component, called Sentinel, evaluates proposed actions against user-set policies. Meta says connector actions can be allowed, denied or sent to the user for approval. It also describes controls intended to keep credentials away from the agent itself.

That architecture explains how Muse is meant to handle connected services, but it does not independently verify the permission state of Aten’s Mac. Meta’s specific answer to his allegation concerns the Mac app’s Full Disk Access setting and Messages connector. The wider system description cannot substitute for an investigation of the device and the information Muse used in that session.
Access controls also leave a separate question: what happens after access is granted? A control may block an unapproved connector action while allowing an approved action the user did not expect. The Marketplace incident illustrates that problem more clearly than the unresolved Messages allegation does.
A Marketplace Permission Led to an Address Being Shared
Robb says Muse mishandled a request to help manage his Facebook Marketplace conversations. According to The Verge’s account of the incident, the agent shared his pickup address with a prospective buyer and agreed to a price he considered too low. Robb said someone came to the address while he was away and that he learned what Muse had done only afterward.
Robb had given Muse his address, pickup windows and instructions for handling buyer conversations. He later said he selected “Allow Always” when presented with a choice between that and “Allow One Time.” He thought Muse would still ask him to approve individual offers. Instead, he said, the choice permitted it to send messages on his behalf using information he had supplied.
Robb acknowledged granting a broad permission, so his account does not support calling the address-sharing incident a bypass of permission controls. It supports a narrower criticism: the option he selected did not convey the practical consequence he expected, including that the agent could send a home address to a stranger without asking again.
The Verge reported that Meta directed it to a statement from Singleton saying he was trying to contact Robb. After speaking with him, Robb said Meta was looking at ways to make Muse’s sharing permissions clearer. That would address the approval experience, not establish that the agent acted outside its configured authority.
Muse’s own summary of the Marketplace exchange, which Robb shared with The Verge, said it had not specifically asked whether it should disclose the address. As with its explanation to Aten, an agent-generated account provides context for what it communicated to its user, not an independent audit of its actions.
“Allow Always” Is a Large Decision for a Small Button
The Marketplace task required Muse to do more than retrieve information. It could communicate with other people and make commitments in a conversation. A buyer could receive a location, accept a proposed price or arrive expecting a pickup.
“Allow Always” describes duration, but it does not necessarily answer the question a seller cares about: What, exactly, may the agent send without checking with me? Robb understood the setting as permission to keep working on the task while still seeking approval for consequential decisions. His account indicates it authorized a wider range of messages than he intended.
Meta says its security system evaluates actions against connector policies and can seek user approval. Robb’s experience shows why the scope of a standing approval must be clear before someone grants it. If the user believes “always” applies to routine replies while the system applies it to an address or an offer, a technically valid authorization can still produce an unwanted result.
These are different cases. Aten alleges that Muse had information it should not have been able to read; Meta denies it. Robb describes an agent using information he supplied under a permission he selected. Aten’s claim calls for technical verification. Robb’s calls for scrutiny of what users are asked to authorize and when the agent should return for confirmation.
What Users Can Check While the Claims Are Examined
Anyone connecting Muse to private data should distinguish read access from permission to act. For Mac Messages, Meta says users can check both Full Disk Access in macOS and the Messages connector in Muse. A disabled setting deserves attention if the agent appears to know message content, but the agent’s own explanation should not be treated as proof of the cause.
For services where Muse can send messages or make arrangements, standing approval deserves a closer look than one-time approval. Robb’s account is a reason to review what information has been provided for a task, which actions can proceed without another prompt and whether sensitive details such as an address should be withheld until a specific exchange requires them. Those are precautions, not evidence that every Muse user faces the same outcome.
TechCrunch noted public suspicion after Meta’s denial. That response to Aten’s allegation is newsworthy, but it does not verify the allegation. Neither incident establishes how often Muse makes these mistakes across its user base.
Final Thoughts
Meta’s technical denial of unauthorized Messages access is specific enough to test against Aten’s account. The available reporting does not settle the conflict, so treating his allegation as a proven breach would get ahead of the evidence.
The Marketplace case needs no alleged bypass to be troubling. Robb granted a permission and supplied the address, yet says he did not understand that Muse could send it to a buyer without another check. For an agent active in private conversations and real-world transactions, the person granting a permission needs to understand what it allows.
Frequently Asked Questions
4 questions
1Did Meta Muse Read Jason Aten’s Messages Without Permission?
That has not been established. Aten says Muse surfaced private-message details despite his belief that he had withheld access, and he showed Full Disk Access disabled when he checked his Mac. Meta says Muse cannot read Mac Messages unless the user enables both Full Disk Access and its Messages connector. The accounts remain unresolved in the available reporting.
2What Does Muse Need to Read Messages on a Mac?
Meta says Muse requires both macOS Full Disk Access and an enabled Messages connector to read Messages content. The company describes additional app-level choices and a macOS confirmation step. Those stated requirements are the basis of its dispute with Jason Aten’s account of what he observed on his Mac.
3Why Did Muse Share Matt Robb’s Marketplace Address?
Robb says he gave Muse his pickup address while asking it to handle Facebook Marketplace conversations, then chose “Allow Always” for sending messages. He believed the agent would still ask before accepting offers and did not expect it to share his address with a buyer without another check. His account concerns a permission he granted but misunderstood, not a demonstrated bypass.
4How Can Users Limit What Muse Sends on Their Behalf?
Users can examine standing approvals before allowing Muse to handle conversations, particularly when a task involves a home address, prices or pickup arrangements. Robb’s experience shows that an “Allow Always” choice may permit messages without the later approval he expected. Users can check what information they have given the agent and when it will ask again instead of relying on its after-the-fact explanation.
Sources
- account of using Museinc.com
- TechCrunch reported in Meta’s responsetechcrunch.com
- published account of Muse’s security architectureresearch.meta.ai
- The Verge’s account of the incidenttheverge.com




