Meta has disputed allegations that its Muse AI agent accessed user messages without permission, asserting that the integration is entirely opt-in. Andy Stone, Meta’s head of communications, clarified on X that Muse cannot read Messages unless users enable both Full Disk Access in Apple’s macOS settings and the specific Messages connector within the app. This statement responds to reports from Inc. columnist Jason Aten, who claimed Muse synced his local Messages database up to row 187,462 despite his Mac showing Full Disk Access as disabled. Aten noted that Muse generated content based on private text exchanges, initially claiming it only viewed notification pop-ups, an explanation later corrected by David Singleton, leader of Meta Superintelligence Labs.

The controversy centers on the operational boundaries of personal AI agents launched by Meta on September 8, which had surpassed 2.5 million downloads by September 23. While Singleton maintained that reading Messages requires three separate permission steps and that macOS protections prevent bypassing these safeguards even with bugs, Aten’s experience highlights potential discrepancies between stated privacy controls and actual data synchronization. The dispute extends beyond messaging access; Amazon began blocking Muse on September 21, citing concerns that the agent does not identify itself while browsing and may capture customer credentials. Meta countered that Muse has no visibility into passwords or payment methods. This friction mirrors previous regulatory actions, such as a federal judge’s preliminary injunction on March 10 blocking Perplexity’s Comet from purchasing on Amazon for users.