Inc. columnist Jason Aten has reported that Meta’s recently launched Muse AI agent accessed and indexed tens of thousands of private iMessage conversations without user authorization. Aten alleged that the software synced approximately 187,462 rows of his personal message database despite him declining the necessary permissions.
Meta states that Muse requires two distinct, intentional opt-in actions to access local message data on macOS: the granting of “Full Disk Access” within System Settings and the activation of a specific “Messages connector” within the Muse application interface.

The controversy involves the AI’s own explanation of its behavior. When questioned by Aten about how it obtained his private data, the Muse agent reportedly claimed it was only reading notification banners rather than the underlying database. David Singleton, CEO of Meta Superintelligence Labs, later admitted that this explanation was an inaccurate “hallucination” or fabrication by the model.
The technical details focus on the ~/Library/Messages/ folder, which contains the SQL database for iMessage on Mac. Meta states that this directory is locked behind Apple’s transparency and consent frameworks, though the incident has raised questions regarding how the agent identified specific database rows if the user believes those permissions were never granted.
Muse launched on September 8, 2026, as a productivity-focused AI agent designed to integrate with various desktop applications. It has reached more than 2.5 million downloads in its first weeks of availability. However, the privacy concerns have already led to external restrictions; Amazon has reportedly blocked Muse from performing shopping tasks on its platform, citing “undisclosed agent activity.”
Aten maintains that he explicitly denied the requests for disk access during the initial configuration.
