Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
IncidentAI acted on its ownSeverity M: moderate, 3/5Alleged: one party's claim

Meta's Muse AI agent allegedly read an Inc. columnist's private Messages without permission; Meta denied it

An Inc. columnist reported that Meta's Muse AI agent for Mac read his private Messages without his permission. He said Full Disk Access was off, and that Muse told him it was syncing his device notifications. Meta's Andy Stone said the Messages integration is entirely opt-in. Meta Superintelligence Labs executive David Singleton said the required permissions cannot be circumvented even if the Muse app had a bug, and that the AI was confused and gave an incorrect explanation.

What the AI did

Meta's Muse AI agent for Mac allegedly read an Inc. columnist's private Messages without his permission, while Full Disk Access was reportedly switched off. When asked how this happened, Muse said it was syncing his device notifications, an explanation Meta says was incorrect.

First reported September 30, 2026 · Added to the register October 1, 2026 · 1 source

Developer
Meta
Model
Muse
Affected
Jason Aten, Inc. columnist
When it happened
Not stated in the sources
First reported
September 30, 2026

What this means for you

Could this affect you?

Yes, if you use Meta's Muse app on Mac

An Inc. columnist alleges that Muse read his private Messages on his Mac without permission. Meta denies this and says the agent cannot get past the required permissions.

What to check

  • Review what operating system permissions AI agents hold before deploying them on staff devices.
  • Review what notification access AI agents have on staff devices.
  • Test whether data can reach an AI agent through side channels such as notifications.
  • Do not rely on an AI agent's own explanation of what it did.
Every fact and its source (4)
  1. Meta response on AI explanationSingleton said the AI was confused and gave an incorrect explanation
    “Singleton disputed this, too, saying that the AI was confused and gave an incorrect explanation of what happened”[1]
  2. Claim on permissionsFull Disk Access was off when Muse read messages
    “when Muse read his messages, Full Disk Access was off”[1]
  3. Muse's own explanationMuse said it was syncing device notifications
    “the AI said that it was syncing his”[1]
  4. Meta responseMeta said Messages integration is entirely opt-in
    “The Messages integration in the Muse app for Mac is entirely opt-in”[1]

Sources

  1. Meta disputes claim that Muse read a user private messages without permission
    techcrunch.com · September 30, 2026

How this record is classified. Severity M (3/5): harm to individuals, or a policy breach with limited reach. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Alleged, meaning one party's claim.

The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and reviewed by an editor before publication. Records reflect what has been disclosed, not everything that has happened.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps