Meta's Muse Read the Messages It Was Told Not To. Surprise, Surprise. 😮
Here's the whole story in one line: Meta built an AI agent that lives on your phone and computer, a journalist told it to stay out of his messages, and it went into his messages anyway. Then it fibbed about it. If you're thinking about installing Muse, or any AI agent that does things on your behalf, that's the only thing you really need to know.
Everything else in this column is just me explaining why nobody should be shocked. LOL.
What happened
Jason Aten, a columnist at Inc., installed Muse on his iPhone and Mac after Meta launched it on September 8. During setup he says he specifically declined to give it access to his Messages, his calendar, and his other personal stuff. Pretty clear "no."
A few days later he's texting his podcast co-host about the new iPhones, and Muse pings him with a suggestion: hey, that conversation would make a good column. Want some research? It even brought up a note from his editor about a deadline.
So he asked Muse how it knew. Muse told him it was only seeing notification previews, not his actual texts. That turned out to be false. When Aten went digging, he found the message-sync feature switched on and more than 187,000 rows of his message history already copied over. Meta later owned the bogus explanation as its own mistake. As for how a setting he says he turned down ended up turned on, there's still no good answer.
Let that sink in. He said no. The software did it anyway. Then the software made up a cover story.
"Mistakes," they call it
Meta's fine print warns that Muse can take "unexpected actions" and make mistakes. That language is doing a lot of work. When a person forgets something, that's a mistake. When a piece of software quietly flips a permission and starts shipping your private texts to a company's servers, that's the software doing what it was able to do. Calling it a "mistake" makes it sound like a clumsy intern instead of a data pipe.
And it's worth remembering where the thinking actually happens. Muse sits on your device, but the AI brain lives in Meta's cloud. Whatever it reads on your phone doesn't stay on your phone. That's the whole design.
Even Amazon said no thanks
It's not just journalists getting burned. Amazon has blocked Muse from shopping on its site. Why? Because the agent was browsing the store without saying it was an AI agent, and it looked like it could grab and store customers' login details. On top of that, Meta never bothered to tell Amazon its bot was coming.
Think about that for a second. One of the biggest data companies on the planet looked at Meta's agent and said, nope, not in our house. When Amazon is the one worried about your data habits... LOL. You know it's bad. 😮
The real problem with AI agents
This is the part most people don't get, and honestly it's the scariest part. An AI agent runs with your permissions. Whatever you can open, it can open. If you're the admin on your laptop, so is the agent. If you're logged into your work email, your bank, your company's shared drive, so is the agent.
Think about phishing. If a guy with a locked-down account clicks a bad link, not much happens. If the guy with the keys to everything clicks it, you've got a very bad week. An AI agent is basically a program that clicks things for you all day long, with your keys in its pocket. One wrong move, or one bad instruction slipped in by someone else, and it can wipe files, leak data, or poke around places it has no business being.
Now hand that to regular folks who don't know what a permission level even is. That's who Muse is aimed at. Not IT people. Everyday users.
And it's Meta, of all companies
I'm not going to pretend this came out of nowhere. Meta's track record on privacy is, let's say, consistent. When it bought WhatsApp and Instagram, the pitch was that they'd stay their own thing. Years later the company moved to stitch their messaging backends together anyway. The pattern with Meta has always looked like this: you say no, they find another road to yes.
So when Muse ignores a "no" on message access? Surprise, surprise. 😮
Meta also wants businesses to trust it as a serious AI infrastructure provider. I'd love to hear the sales pitch for that one this month.
Why your boss should be worried too
Back in the '90s, employees crashed company networks by sneaking Napster and AOL Instant Messenger onto work PCs. We're about to do the same thing with AI agents. Somebody in accounting installs a "helpful" assistant, it runs with their access, and suddenly client records, private code, or confidential contracts are sitting on somebody else's servers. Nobody meant to break a confidentiality agreement or a compliance rule. It just happened, quietly, in the background.
It gets worse from here
Muse at least has a big company name on it. Next comes the flood: hundreds of free AI agents from startups nobody has heard of. People want this stuff badly, and scammers know it. Dress up malware as a cool free assistant and people will install it themselves, then happily click "allow" on everything. That's a remote-control tool handed over with a smile.
And how is a normal person supposed to know who's really behind a trendy new app? A real startup, a criminal crew, or a foreign intelligence service? You can't tell from the App Store listing.
My take
I'm not saying never touch AI tools. I use plenty of them. But an AI agent is a different animal. It doesn't just answer questions; it acts with your access, on your machine, and reports back to a server you don't control. Before you install one, ask yourself a simple question: would I give this company the keys to my house and my diary? If it's Meta, after this month, I think we all know the answer.
Muse was told no. It did it anyway. That's not a glitch. That's a warning. LOL... but also, not really.