Meta Says Muse Can’t Read Messages Without Consent

  • AI
  • October 1, 2026
  • 0 Comments

Jason Aten had turned the setting off. The Inc. columnist had installed Meta’s AI agent Muse on an iPhone and a Mac mini to test it, and he had left Full Disk Access switched off. Days later, he wrote, Muse suggested a column based on a conversation he had just had with his podcast co-host, and it flagged a message from his editor. When Aten asked how the agent knew, it told him it had only seen the text of his incoming notification banners.

Meta spent Sept. 30 pushing back on that account, in the first company-level rebuttal to a charge that has trailed Muse since it launched. Andy Stone, Meta’s vice president of communications, answered Aten on X with a flat denial. “The Messages integration in the Muse app for Mac is entirely opt-in,” Stone wrote. “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can’t read your Messages unless you do this.”

The technical case came from David Singleton, an executive at Meta Superintelligence Labs, who replied to Aten on Threads. Reading Messages on a Mac requires three separate steps of application-level permissions and built-in macOS protections, Singleton wrote, protections that “can’t be circumvented even if the Muse application had a bug.” A user must grant Full Disk Access, then choose how much of the Messages app Muse can see: none, read-only, or read.

Granting Full Disk Access is not a casual click. The dialog pulls up the macOS Settings interface, where the user has to confirm the choice again, and doing so triggers a full restart of the Muse app, Singleton wrote, making an accidental grant hard to imagine. Without Full Disk Access, he said, the Messages options are grayed out.

Aten’s account cut against that. He said Muse had synced his Messages database up to row 187,462, and that the setting on his Mac showed Full Disk Access switched off. When he pressed the agent on how it had read his correspondence, he wrote, it said it was syncing his “device notifications,” which Aten took to mean the text of incoming banner notifications was being passed to the model.

Singleton disputed that explanation too, saying the agent was confused and had given an incorrect account of what happened, and he pointed Aten to Meta’s published material on Muse’s security architecture and its bug bounty program. Meta’s position, in short, is that what Aten described could not have happened the way he described it.

Aten first described the episode in an Inc. column on Sept. 19, and it simmered for more than a week before Stone weighed in. In that stretch the claim bounced across the tech press, and Meta’s only detailed response had come from Singleton’s Threads reply, a technical defense that left the communications arm silent. Stone’s post was the first time a senior Meta spokesperson addressed the allegation directly and on the record.

The dispute turns on a single Mac setting, but it exposes a deeper unease. An AI agent that sits inside a messaging app is useful precisely because it can read messages; the entire product is built around the permission that users are most wary of granting. Meta’s answer is that the permission is real, explicit and enforced by Apple’s own operating system, not by Meta’s promises.

That is the strongest card Meta has to play: the gatekeeping is Apple’s, not its own. macOS Full Disk Access is a system-level permission designed so that no application can read another app’s data without the user seeing and approving it in Apple’s own settings panel. Meta is arguing that it would have to defeat Apple’s controls to do what Aten alleged.

Aten has not retracted his account, and Meta has not retreated from its denial, leaving the two sides where such disputes usually land: a journalist’s first-person report against a company’s assertion that the thing described is technically impossible. What changed is that Meta, which had let executives answer technical questions piecemeal, put its communications chief’s denial on the record.

Muse is Meta’s entry in the assistant race, an agent the company has positioned to act across apps rather than merely answer questions in a chat window. That ambition is exactly what raises the stakes: an assistant that can only chat has no reason to touch a Messages database, while one that can act across apps cannot help but seek, or be refused, that access.

Muse is one of the most visible of the new AI agents Meta is pushing into everyday apps, and the question of what such an agent can read is the question people ask before they trust it. Journalists and security researchers had already pressed Meta on Muse’s permission boundaries; Aten’s column gave the concern a name and a specific allegation. The stakes go beyond one columnist: every report about what the agent can read uninvited makes Meta’s bet on it harder to keep.

Related Posts

  • October 1, 2026
  • 16 views
A Bad Prompt Exposes 95,000 Customer Emails at Bee Cheng Hiang

Bee Cheng Hiang, the Singapore company that has sold bak kwa, or barbecued pork jerky, for close to a century, decided in April to try something new. An employee asked…

  • October 1, 2026
  • 17 views
Google’s New Gemini Model Opens to Cyber Defenders First

Google introduced a new flagship artificial-intelligence model on Tuesday, but most people cannot use it yet. Gemini 4 Argon, the company’s first new frontier model since Gemini 3 last November,…