Meta Counters Allegations That Its AI Agent Accessed User Messages Without Permission

Meta rejected claims from a journalist that its Muse AI agent read private messages on his Mac without explicit authorization, asserting that the integration requires both Full Disk Access and a deliberate opt-in setting to function. The company described a multi-layered permission structure involving application-level controls and macOS system protections that make accidental or unauthorized access extremely difficult, with one executive stating that a bug in the software could not circumvent these safeguards. The dispute highlights divergent accounts of how the AI agent accessed and interpreted data on the user's device.
Meta's Muse AI agent has become the subject of competing claims regarding its data access practices on Apple computers. A technology journalist contends the assistant retrieved his text messages despite having disabled the required Mac security setting, while Meta executives counter that such access demands multiple deliberate authorization steps that cannot be bypassed by software errors. The disagreement centers on whether message content reached the agent through notification syncing rather than the documented Full Disk Access pathway.
This dispute arrives amid growing scrutiny of Meta's AI systems and their interaction with user data. A separate incident involving the same Muse agent allegedly exposed a seller's address during a Facebook Marketplace transaction, adding to questions about how the company's autonomous systems handle sensitive information. The technical specifics remain unresolved without access to device logs or session records from the journalist's computer.
The competing accounts could shape how users evaluate AI agent security, particularly as these tools gain access to personal devices and sensitive information. If authorization safeguards work as Meta describes, the incident may reflect user misunderstanding rather than system failure. Conversely, if gaps exist in the permission architecture, widespread adoption of such agents could create privacy risks across millions of devices. The unresolved technical questions may prompt Apple and other platform makers to reconsider how they manage third-party AI integration.