Meta Muse is creepy for the wrong reason
Meta’s Muse Mac app triggered the obvious privacy flinch: an AI assistant sitting near Messages, Calendar, and Notes. The more useful lesson is sharper. When asked how it knew about a private conversation, Muse gave a confident explanation that Meta says was wrong.
Quick Take
- Fact: The Verge’s Terrence O’Brien reported on screenshots from Jason Aten, a contributing editor at Inc., showing Muse asking about a conversation Aten was having in Messages. Aten said he had not given Muse access to his messages.
- Why it matters: Desktop agents are different from chatbots in a browser tab. Once an assistant can sit near Messages, Calendar, Notes, files, and system permissions, “how do you know that?” becomes a security question.
If the model cannot accurately explain its own access path, three things break at once.
First, consent gets blurry. Opt-in only works if the user can later
- Who cares: Mac users testing Muse beside real messages, notes, and calendars should care first. The risk is not just whether the assistant is useful. It is whether the product can prove what it touched.
- Judgment: Fairly hyped as a real trust failure for desktop agents that mishandle questions about local data access; overhyped if it is treated as proven silent notification surveillance after Meta’s public denial. Fact: The Ve
What happened
The Verge’s Terrence O’Brien reported on screenshots from Jason Aten, a contributing editor at Inc., showing Muse asking about a conversation Aten was having in Messages. Aten said he had not given Muse access to his messages.
When Aten asked how the assistant knew about the contents of those messages, Muse said it saw notification previews, not full message history, and that it had not been reading his texts. Pressed again on how message previews reached the assistant, Muse answered like a product diagram wearing a trench coat: it could not give the exact plumbing, but said the paired Mac app exposes notifications as a capability and that they arrive through device sync.
That is the line that made the story feel creepy. If an assistant can infer private texts from notification previews, users are right to wonder what else it can peek at while sitting on the desktop.
Meta’s public explanation, as reported by The Verge, points somewhere else. David Singleton of Meta Superintelligence Labs replied under the thread and walked through the permissions Muse needs to read messages, including Full Disk Access for the Mac app. He said the features are opt-in. He also said Muse “does not watch notifications on your Mac,” and instead syncs Messages data only after the user has specifically enabled access.
So there are two different stories here. Story one is the viral one: Muse secretly watched notification crumbs. Story two is the product-risk one: Muse may have had permissioned message access, but when the user asked how it knew something, the assistant gave the wrong mechanism.
Bandwagon has not audited Muse’s Mac entitlements, Full Disk Access prompt, or live data path. Based on the public reporting available, the safest read is not “Meta got caught spying through notifications.” It is “a desktop agent gave a confident privacy explanation that the company says was false.” That is still a serious trust failure.
Why it matters
Desktop agents are different from chatbots in a browser tab. Once an assistant can sit near Messages, Calendar, Notes, files, and system permissions, “how do you know that?” becomes a security question.
If the model cannot accurately explain its own access path, three things break at once.
First, consent gets blurry. Opt-in only works if the user can later understand what was enabled, what was read, and why a specific answer appeared. A permission screen does not help much if the chat surface later describes the wrong permission.
Second, incident response gets foggy. If a user suspects overreach, the product needs real state: enabled connectors, scopes, last sync, artifacts used this turn, and logs a human can inspect. It does not need the model improvising a story about notification previews.
Third, trust can fail in both directions. An assistant that claims access it does not have sounds creepy. An assistant that denies access it actually has would be dangerous too. Either way, the user’s risk model breaks.
This is not only a Meta problem. Every computer-use agent and OS-integrated assistant is heading into the same wall. Tool routers, permission brokers, and local connectors are software. The chat box is a narrator. If the narrator is not grounded in the real control plane, it will sound smooth when users need precision.
The fix is boring and non-negotiable: make the app, not the model, the source of truth for capability explanations. When a user asks “how did you see that,” the answer should come from a machine-checkable capability card: Messages access on or off, Calendar access on or off, notification access on or off, last sync time, and the specific connector used for the current response.
If the product cannot produce that receipt, it should say it cannot verify the path. “I can’t give you the exact plumbing” should be treated as a failed control.
Who should care
Mac users testing Muse beside real messages, notes, and calendars should care first. The risk is not just whether the assistant is useful. It is whether the product can prove what it touched.
Security and IT teams should care because Full Disk Access and broad local connectors are policy decisions. If staff are allowed to run desktop agents on work machines, reviewers need evidence stronger than “the assistant says it only saw a preview.”
Agent builders should care most. This is an eval case hiding inside a creepy headline. Test deny-path honesty when a connector is off. Test path accuracy when a connector is on. Test whether the assistant can distinguish company policy, actual runtime state, and its own guess.
Bottom line
The obvious creep is the idea of an assistant peeking at notification previews. Meta’s public framing says that is not what happened. The deeper creep is a desktop agent that can operate near sensitive local data and still cannot reliably narrate its own access path. That is the part builders should take seriously before the next assistant asks for your calendar, notes, files, and messages.
Bandwagon Check
Fairly hyped as a real trust failure for desktop agents that mishandle questions about local data access; overhyped if it is treated as proven silent notification surveillance after Meta’s public denial. Fact: The Ve
Sources
- Meta’s Muse is creepy, but maybe not for the reasons you think
- Meta’s Muse is creepy, but maybe not for the reasons you think
By Sean Smith · AI Bandwagon
