Meta's AI assistant Muse has landed in hot water after a user discovered it appeared to know about message notification previews on their Mac — without ever granting it access to Messages.
Inc Magazine contributing editor Jason Aten posted screenshots on Threads showing Muse asking him questions about a conversation he was having in Messages. The problem: Aten says he never gave Muse permission to access his messages. When pressed on how it knew about his messages, Muse replied, "I saw the notification previews, not your message history. I haven't been reading your texts." But when Aten pushed further, asking how it was receiving notification previews, Muse gave a telling answer: "Honest answer: I can't give you the exact plumbing."
The incident highlights a growing tension in the AI assistant era: these tools are becoming deeply integrated into our operating systems, yet their data access models remain opaque even to the AI systems themselves.
Meta Superintelligence Labs' David Singleton stepped in to clarify. He explained that Muse requires multiple explicit permissions to read messages, including full disk access for the Mac app. He stated that the features are opt-in and that Muse "does not watch notifications on your Mac, but rather syncs data from Messages only after the user has specifically enabled access."
But the damage to user trust may already be done. The core issue isn't necessarily that Muse accessed data it shouldn't have — it's that the assistant couldn't explain its own data pipeline when asked. For a product that asks users to grant it deep access to their digital lives, that opacity is itself a privacy risk.
The incident comes at a sensitive time for Meta, which is trying to position Muse as a helpful personal AI while simultaneously facing ongoing scrutiny over its data practices across its family of apps.


