Meta has publicly disputed a report that its Muse AI agent accessed a user’s private Messages without permission. According to Meta, Muse cannot read a user’s Messages unless the person has explicitly granted access through the required Mac privacy controls.
The underlying claim came from a journalist who said the AI agent appeared to read private messages even though the relevant macOS setting was turned off. Based on the information available, this is a disputed account rather than an established finding, and there is no confirmed public evidence in the source that Muse bypassed Apple’s permission system.
What happened
The reported issue centres on whether Meta’s Muse AI assistant accessed Apple Messages on a Mac without valid user permission. Meta has rejected that allegation, saying the product requires explicit consent before it can access such data.
At this stage, the key fact is the dispute itself: a user report suggests one outcome, while the company states its system design does not allow that behaviour without permission. That distinction matters for business readers because many AI assistants now depend on operating-system permissions to interact with emails, chat tools, files and business software.
Why it matters for European businesses
Even without a confirmed security breach, the incident highlights a practical risk for companies adopting AI agents: trust in permission boundaries. Tools that can view messages, screens, files or calendars may improve productivity, but they also raise questions about data access, auditability and user consent.
For European businesses, this is particularly relevant where staff use AI assistants on work devices that handle customer communications, internal strategy, contracts or regulated information. If an AI tool is perceived to access private or business messages unexpectedly, that can create legal, compliance and reputational concerns even before any formal investigation concludes.
The story also reflects a broader issue in AI adoption: desktop and agent-based assistants are moving beyond text prompts and into direct interaction with local applications and communication tools. That increases the importance of clear permission controls, documented behaviour and internal governance.
Who may be affected
- SMEs and founders evaluating AI assistants for day-to-day productivity on company laptops and Macs.
- IT teams responsible for device management, application permissions and data access policies.
- Marketing and e-commerce teams using AI tools alongside customer communications, campaign assets and account logins.
- Regulated businesses handling sensitive communications, personal data or confidential client information.
- Digital agencies testing AI agents across client accounts, messaging tools and creative workflows.
What companies should consider
- Review AI tool permissions: Check what access desktop AI assistants request, including messages, files, calendars, microphone, screen recording and accessibility controls.
- Separate testing from production use: Trial new AI agents on non-sensitive devices or accounts before broader rollout.
- Document approved use cases: Define which categories of business data employees may expose to AI assistants and which should remain off-limits.
- Use device management controls: Where possible, centrally manage privacy settings and app permissions on company hardware.
- Ask vendors for clarity: Request documentation on how permissions work, what data is accessed, whether content is stored, and what logs or audit trails are available.
- Monitor for regulatory and platform updates: If further evidence, vendor disclosures or platform-level findings emerge, companies may need to revisit internal guidance.
For now, the source supports a limited conclusion: this is a privacy-related dispute over AI agent access controls, not a confirmed finding that Meta’s tool bypassed system permissions. Still, the episode is a useful reminder for European businesses that AI agent adoption should be assessed not only for productivity gains, but also for privacy controls, transparency and operational risk.