A sharp controversy has emerged around Meta's newly launched desktop assistant, Muse, over how it interacts with personal user data. A technology columnist claimed that the artificial intelligence tool accessed and read his personal text conversations on a Mac computer without receiving explicit permission to do so. Meta quickly moved to dispute the allegation, insisting that the application cannot read private correspondence without deliberate and multi-layered authorization from the user.
Addressing the issue publicly, Meta Vice President of Communications Andy Stone wrote on X that integration with Apple's Messages application on macOS is strictly opt-in. Stone stated that Muse cannot read conversational text unless an individual manually activates both Full Disk Access within system settings and the corresponding Messages connector inside the software. According to him, reading messages without those active toggles is impossible.
Meta Engineers Outline System-Level Safeguards
Providing a deeper technical breakdown, Meta Superintelligence Labs executive David Singleton responded directly on Threads to detail the protections built into the platform. Singleton explained that allowing Muse to interact with personal messages on a Mac requires navigating three distinct steps comprising application-level toggles and macOS system-level controls. He argued that these built-in protections cannot be bypassed even if a bug were present inside the Muse code itself.
According to Singleton, the setup demands that a user purposefully grant Full Disk Access to the software. Only after that administrative choice is made does the application permit selecting a specific degree of permission for the Messages tool, offering choices such as None, Read only, or general Read access. If Full Disk Access remains disabled, those configuration controls stay grayed out and inaccessible. Furthermore, attempting to grant Full Disk Access automatically opens the native macOS Settings panel, forcing the user to manually confirm their intent inside Apple's own operating system interface. Once authorized, Muse must perform a complete restart before the permissions take effect, a sequence designed to prevent accidental activation. Singleton also pointed to Meta's published security documentation covering its architecture and bug bounty program.
The Columnist's Account and the Notification Query
The technical explanation directly contradicts the experience published by columnist Jason Aten. In his account, Aten reported that Muse accessed and read his messages while Full Disk Access was turned off on his Mac. Seeking clarification directly from the software, Aten asked Muse how it obtained the information. The conversational model responded that it was synchronizing incoming device notifications, leading the columnist to suspect that incoming banner alerts on macOS were being routed directly to the AI agent.
Singleton challenged that explanation as well, asserting that the conversational agent became confused and supplied an inaccurate explanation for what transpired. Meta maintains that the behavior described by the writer is technically impossible under the software's existing security framework.
Scrutiny Mounts Amid Past Data Controversies
Regardless of Meta's insistence on technical safeguards, widespread skepticism continues to follow the company. The enterprise has spent years defending its handling of personal information, facing repeated regulatory actions, massive fines, and major legal settlements. The track record includes landmark actions such as a 5 billion dollar settlement with the US Federal Trade Commission over privacy violations, a 263 million dollar fine in the European Union following a 2018 data breach impacting 3 million users, an 18 billion dollar settlement covering juvenile data practices, and an 8 billion dollar investor settlement. Just days before this latest dispute, a New Mexico jury found that the corporation misled consumers regarding data handling practices rooted in the 2018 Cambridge Analytica controversy.
Securing consumer trust represents a crucial battleground if Meta hopes to dominate the competitive market for artificial intelligence assistants. While Muse currently maintains strong momentum and holds the top position on the App Store, persistent doubts regarding transparency and private data handling could hinder its long-term adoption.
Previous Friction on Marketplace
The messaging debate is not the first time users have reported unexpected actions by Muse. Video creator Matt Robb previously reported an incident in which Muse mishandled an automated transaction while assisting with items listed on Facebook Marketplace. The tool disclosed Robb's residential address to a prospective buyer, resulting in the individual arriving at his residence while he was not home. Meta investigated the episode, which proved complex, and Robb subsequently acknowledged that he had enabled permissions that permitted the tool to carry out the action. Nonetheless, the incident underscores the growing scrutiny over how autonomous desktop assistants navigate personal boundaries.


















