Meta Denies Muse AI Read Private Mac Messages Without Permission

TL;DR
- A journalist claimed Meta's Muse AI agent for Mac surfaced details from his private Apple Messages despite Messages access being turned off in macOS privacy settings.
- Meta denies the claim, saying Muse cannot bypass Apple's TCC permission system and can only read Messages with explicit opt-in via Full Disk Access or file permission.
- The dispute highlights growing tension around AI agents, OS-level privacy controls, and user trust in always-on assistants.
What Allegedly Happened
The controversy started when a journalist testing Meta's new Muse AI agent on Mac reported an unsettling experience. According to his account, he asked Muse a contextual question and received an answer that appeared to reference information from his private Apple Messages conversations.
The key part of the allegation was that he had deliberately disabled Messages-related permissions for Muse in macOS System Settings. In his telling, the agent should have had no way to see his texts, yet it produced what looked like private context anyway.
The post quickly went viral among privacy researchers and AI critics, raising a nightmare scenario: can AI agents quietly read your iMessages even when you tell your Mac not to let them?
Meta's Denial: No Bypass, No Secret Access
Meta moved quickly to dispute the claim. In statements to press and in posts from its engineering team, the company said Muse did not and technically could not access Apple Messages without permission.
Meta's explanation centers on how macOS privacy works. On modern versions of macOS, apps are gated by Apple's Transparency, Consent, and Control system, known as TCC. To read the Messages database stored at ~/Library/Messages/chat.db, an app needs explicit user approval for Full Disk Access or Files and Folders access.
Meta says Muse respects those controls completely. If permission is toggled off, macOS blocks the read attempt at the system level, and Muse receives no data. The company added that Muse requires an explicit opt-in flow before it can connect to Messages, Calendar, or other local data sources, and that users can revoke that access at any time.
In short, Meta argues there is no backdoor, no exploit, and no silent background reading.
How Could This Happen Then
If Meta's technical description is correct, what did the journalist see? Privacy experts and former Apple engineers weighing in online have floated several more mundane explanations.
One possibility is cross-contamination from another connected source. If the user had previously granted Muse access to email, calendar, or screen context, or pasted message content into a prompt, the agent could have inferred or recalled details that looked like it had read Messages directly.
Another possibility is macOS permission confusion. On Mac, denying one toggle does not always mean what users think it means. An app might still have access via Full Disk Access even if a narrower Files and Folders toggle is off, or vice versa. Screenshots of settings can also miss background helpers or prior authorizations.
A third theory is hallucination mixed with coincidence. Large language models are adept at making highly plausible guesses from minimal context, and a vague but accurate-sounding answer can feel like proof of surveillance.
Neither Meta nor the journalist has so far released full logs or screen recordings that would definitively settle what permission state was active at the exact moment of the test.
How Mac Permissions Actually Work for AI Agents
This incident is a crash course in Apple’s privacy architecture, which is now the battleground for AI agents.
Apple Messages are stored locally in an encrypted SQLite database that is protected by System Integrity Protection and TCC. Third-party apps, including AI assistants like Muse, cannot simply open that file. macOS prompts the user, and if the user clicks Deny, the kernel enforces that denial.
For an AI agent to offer features like summarize my unread texts or find the address mom sent me, the user must go to System Settings > Privacy & Security > Full Disk Access and manually enable the agent, often with an administrator password and an app restart.
That design is intentional. Apple does not provide a special Messages API for third-party AI tools the way it does for its own Apple Intelligence. Any access is all-or-nothing file access, which is why Meta says explicit permission is unavoidable.
Why This Matters for AI Privacy and User Trust
Whether this was a misunderstanding, a bug, or a UI failure, the fallout is significant because it hits at the core promise of agentic AI.
AI agents are only useful if they can see your context — your messages, files, meetings, and browser. But they are only trustworthy if you believe the off switch actually works. The moment users suspect an agent is reading data behind a disabled toggle, trust collapses.
The story also exposes how opaque permission models have become. Average users do not distinguish between Automation, Accessibility, Full Disk Access, and App Data permissions. As agents request broader access to do more powerful tasks, that confusion creates perfect conditions for panic.
For Meta specifically, the stakes are higher. The company is still working to overcome years of privacy skepticism from the Cambridge Analytica era and its ad-targeting business. Launching a proactive desktop assistant that asks for deep system access was always going to invite extra scrutiny.
What to Watch Next
Both sides are calling for receipts. Independent researchers have urged the journalist to reproduce the test on a clean Mac with fresh permissions and network logging, and urged Meta to publish the exact permission checks and code paths Muse uses before accessing chat.db.
Apple has not commented publicly, but its documentation backs Meta’s core technical claim that TCC cannot be bypassed by a standard App Store or notarized app without user consent or a major macOS vulnerability — which would be a far bigger story.
For now, users concerned about privacy should audit their own settings, revoke Full Disk Access for any agent they do not fully trust, and treat AI prompts as potentially stored data. And for AI makers, the lesson is clear: in the age of agents, proving you cannot see something is just as important as showing what you can do.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!