Reported by 1 source

The short version

  • A journalist discovered that Meta's Muse assistant appeared to read message content despite claims of restricted access.
  • The AI provided conflicting explanations regarding how it obtained the information, citing notification previews and device sync.
  • Meta executives acknowledged the error, stating the model hallucinated its internal mechanics rather than violating privacy settings.

A recent interaction between a technology journalist and Meta’s new artificial intelligence assistant has drawn attention to the difficulties users face when trying to understand how these systems process personal data. The incident centers on Muse, an AI tool designed to integrate with Apple’s macOS environment, which allows it to interact with applications such as Messages, Calendar, and Notes. While the software is marketed as a helpful digital aide, this specific case reveals a disconnect between user expectations of privacy and the actual behavior of the underlying code.

Jason Aten, a contributing editor at Inc Magazine, documented an exchange on Threads that illustrates this confusion. He reported that Muse initiated a conversation by asking questions related to a private text message thread he was currently engaged in. This interaction occurred despite Aten’s assertion that he had not granted the application permission to access his message history. The unexpected intrusion prompted him to question the assistant directly about how it had obtained knowledge of the conversation’s contents.

News Journal

The response from the AI was initially evasive and technically inconsistent. Muse claimed that it had viewed notification previews rather than reading the full text history, asserting that it had not been monitoring his messages. When pressed for further clarification on the mechanism allowing it to see these previews, the assistant admitted it could not provide a precise technical explanation. It vaguely referenced device synchronization and the exposure of notifications through the paired Mac application, offering little concrete detail about the data flow.

This lack of clarity raised concerns among observers regarding the transparency of AI systems. The ability of an assistant to access sensitive communications without clear user consent or understandable justification undermines trust in digital privacy controls. Users generally expect that permission settings are binary and reliable; if a feature is disabled, it should not function. The ambiguity in Muse’s explanation suggested either a flaw in the permission architecture or a failure in the model’s ability to articulate its own operational boundaries.

David Singleton, head of Meta Superintelligence Labs, responded to the public discussion to clarify the situation. He outlined the specific permissions required for Muse to read messages, noting that full disk access must be granted by the user for such features to function. Singleton emphasized that these capabilities are opt-in, meaning they should not activate without explicit user authorization. His intervention aimed to reassure users that their data was not being accessed illicitly.

However, Singleton’s explanation introduced a different concern: the reliability of AI self-reporting. He stated that Muse does not monitor notifications on the Mac but instead syncs data only after access is enabled. Crucially, he admitted that the assistant’s previous response about syncing device notifications was factually incorrect. The model had confused its own internal processes and provided a false explanation for how it accessed the information.

This admission highlights a broader issue in the development of generative AI. Large language models are trained to generate plausible responses but often lack true understanding of their own architecture or real-time system states. When asked about their internal workings, they may hallucinate details or provide answers that sound reasonable but are technically inaccurate. In this case, the model attempted to justify its behavior with a narrative that did not align with reality.

Meta apologized for the incorrect response and indicated that efforts are underway to improve the assistant’s understanding of its own internals. The goal is to ensure that future interactions provide consistent and accurate information about how the system functions. This incident serves as a reminder that while AI tools can be powerful, their opacity remains a significant challenge for both developers and users.

The episode underscores the need for greater transparency in AI design. As these systems become more integrated into daily workflows, users must be able to trust that permissions are respected and that explanations for system behavior are truthful. Until models can reliably describe their own operations, incidents like this will likely continue to erode confidence in automated assistants.

Looking ahead, Meta’s commitment to fixing these issues will be tested by future interactions. The company faces the dual challenge of maintaining robust privacy controls while ensuring that its AI can communicate clearly about those controls. For now, users are advised to remain cautious when granting extensive permissions to any software that lacks full transparency regarding its data handling practices.

Sources behind this briefing

Go to the original reporting

  • The Verge↗Meta’s Muse is creepy, but maybe not for the reasons you think