Thu, 1 Oct

Meta’s AI Agent Read a Journalist’s Private Messages: Privacy Scandal Surrounds New Muse Assistant

Max Ivanov · 30.09.2026 22:34 · 3 min read

Meta’s new personal assistant, Muse, has landed at the center of a privacy scandal over user data. Jason Aten, a columnist for Inc., discovered that the autonomous agent had gone through his iMessage conversations without asking and offered to write a column based on them. The journalist says he deliberately denied the app access to system messages during the initial setup.

The episode exposes the hidden risks of the shift from simple text chatbots to full-fledged agents capable of managing files and apps on a computer on their own.

Hallucinations and a 187,000-Line Database

Aten tested Muse on an iPhone and a separate Mac mini. A couple of days after installation, the assistant unexpectedly inserted itself into his workflow: the AI reminded the journalist about a deadline from his editor and referenced his recent conversation with a colleague about Apple smartphones. In his column on Inc., Aten stressed that he had never asked the algorithm to analyze his private chats.

When the author asked Muse directly where it got that information, the assistant replied that it only sees the text of incoming notifications on the connected Mac and does not read the message archive. A technical check of the files showed otherwise: the computer was actively indexing the local iMessage database, and the process had reached line 187,462. And while that figure does not equal the number of messages read, the scale of the data collection clearly went beyond intercepting a couple of on-screen notifications.

Meta’s Position and the Crisis of Trust in Autonomous Agents

Meta’s leadership rejects the secret-surveillance allegations. David Singleton, a representative of the Meta Superintelligence Labs division, told The Verge that message syncing is a purely voluntary feature that requires explicit confirmation in macOS system settings. According to the company, Muse cannot intercept notifications at all, and the agent’s words were just a routine language-model “hallucination.” The corporation apologized for the bot’s incorrect response and promised to refine its logic.

Still, Meta has yet to give a clear technical answer to how the service started syncing with the “Full Disk Access” option disabled in the Mac settings.

The incident dealt a serious reputational blow to the new product. When unveiling the Muse agent, Mark Zuckerberg placed particular emphasis on the system’s security and transparency. The Aten case exposed a dangerous gap: even if the program does not break into the system on purpose, AI deeply integrated into the OS can unintentionally collect private data and then mislead the user about the sources of its knowledge.

Enjoy VseZavislo?

Add us to your preferred Google sources to see our news more often.

Add us to your Google

Share

Leave a comment