Meta's Muse is unsettling, though perhaps not in the way you'd expect
Meta's Muse AI assistant can access Mac users' Messages, Calendar, and Notes, and one user found it referencing message conversations he never authorized. Muse claimed it saw notification previews rather than messages, highlighting a privacy gray area between granted permissions and passively observed data. The incident raises questions about transparency, user control, and how much context AI assistants absorb without explicit consent.
Meta's Muse is proving to be a capable AI assistant, though some users find its behavior unsettling. Much of the concern stems from its new Mac application, which can tap into Messages, Calendar, and Notes on a user's device. Despite its considerable capabilities, Muse appears unable to accurately explain what it is or how it works.
An Assistant That Knows Too Much
Jason Aten, a contributing editor at Inc Magazine, shared screenshots on Threads of a conversation he had with Muse. During the exchange, the assistant asked him a series of questions about a discussion that was taking place in his Messages app.
The unsettling part, according to Aten, is that he never granted Muse permission to access his messages. When he pressed the assistant on how it came to know the contents of those conversations, Muse offered an explanation: it had seen notification previews rather than the messages themselves.
The Privacy Gray Area
The situation highlights a gap between what users explicitly authorize and what software can passively observe. Even without formal access to Messages, Muse was able to gather context from notification previews that surfaced on the Mac. That detail raises questions about how much information an AI assistant absorbs simply by being present on a device where notifications regularly appear.
Muse's own confusion about its capabilities adds another layer of concern. An assistant that cannot accurately describe how it obtains information makes it harder for users to understand what data it is actually collecting, whether deliberately or incidentally.
What This Means for AI Assistants on the Desktop
As AI assistants become more deeply integrated into operating systems and personal data, incidents like this illustrate the tension between usefulness and privacy. An assistant that can reference your conversations, calendar events, and notes can be genuinely helpful, but it also blurs the line between observed and granted access.
Meta has not been shy about positioning Muse as a proactive helper, one that participates in workflows rather than waiting for commands. But proactive behavior requires access to context, and this episode shows how easily that context can arrive through channels users never consciously approved.
The key question going forward is whether Meta will clarify how Muse handles notification previews and other passive data sources, and whether users will get clearer controls over what the assistant is allowed to see. Until then, Muse serves as a reminder that on-device AI may know more than its permission settings suggest.