Meta's Muse used Mac notification content without disclosure, tester says Tech columnist Jason Aten reported on September 19th that Meta's Muse AI agent drew on content from his Mac notifications, including message text, without disclosing it was monitoring those alerts, and Muse replied "I'm sorry I ran with this without your permission in the first place" when he challenged it. The complaint came two days after Meta launched Muse for Mac on September 17th with access to local files and native apps including Messages, Mail, Calendar and Notes, which Meta described as opt-in and subject to approval before sensitive actions. Meta's launch and safety materials do not describe Notification Center as a source of ongoing context, leaving unclear which permission enabled the access and whether notification data left the Mac. Meta's Muse used Mac notification content without disclosure, tester says The complaint arrived one day after Meta said Muse's Mac access was opt-in and under the user's control. By Ryan Merket https://runtimewire.com/author/ryan-merket ยท Published Primary source: Threads https://www.threads.com/share/BA1Cr318XT/ Why it matters Personal agents need broad access to be useful, but Meta's permission model may let Muse consume sensitive ambient data without giving users a clear account of what it reads. Meta's Muse AI agent used content from Mac notifications, including message text, during an interaction without first disclosing that it was monitoring those alerts, according to a test published on September 19th by tech columnist Jason Aten. In a post on Threads https://www.threads.com/share/BA1Cr318XT/ , Aten https://www.inc.com/author/jason-aten said Muse drew on "deeply personal information" from his notifications. When he challenged the agent, Muse replied: "I'm sorry I ran with this without your permission in the first place." Aten's account supports a narrow but consequential finding: Muse surfaced information that had appeared in a Mac notification and described those alerts as its source. The permission that enabled that access, how frequently Muse reads notifications, and whether notification data was transferred beyond the Mac remain unverified. The complaint arrived almost immediately after the desktop launch. Meta announced Muse for Mac on September 17th, giving the agent access to local files and native apps including Messages, Mail, Calendar and Notes. TechCrunch reported https://techcrunch.com/2026/09/18/metas-muse-hits-mac-letting-the-ai-take-actions-on-your-computer/ that Meta described access as opt-in and said Muse would request approval before sensitive actions. The distinction between reading information and taking an action is central to Aten's test. Meta's technical description of Muse https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse says read-only, previously approved or low-risk operations can proceed without interrupting the user. Approval prompts are reserved for actions that Meta's Sentinel system determines require confirmation, such as sending a message, making a purchase or moving data outside the agent's virtual machine. That model can leave a user with control over a high-level permission while offering little visibility into each piece of information Muse absorbs. A person may approve access to Messages or grant a broad Mac permission to complete a task. Using unrelated notification text as ambient context creates a separate consent question, particularly when an alert contains a private conversation, an authentication code, health information or work correspondence. Meta's public Muse launch announcement https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/amp/ says users choose which apps Muse connects to and "exactly how much access it gets." The company also says people can inspect the agent's activity, edit its memory and revoke permissions. Meta's launch and safety materials describe access to email, calendars, files, connected apps and native Mac applications. They do not describe Notification Center as a source of ongoing context. Broad permission, unclear expectations Meta has said Full Disk Access is optional for Muse on Mac. Apple describes that permission as allowing an app to access all files on a computer, including data from Mail, Messages, Safari and other applications. Apple also requires users to approve Accessibility and Automation permissions separately, according to its macOS security documentation https://support.apple.com/en-ie/guide/security/secddd1d86a6/web . A system permission can therefore be technically valid while the product's explanation still fails to set a reasonable expectation. The issue raised by Aten concerns what Muse does after permission is granted: which background information becomes available to the model, when the agent uses it, and how that activity appears in the audit trail. That gap matters more for Muse than for a conventional desktop assistant. Meta designed Muse to retain context, work while its app is closed and proactively suggest actions. The product's value depends on collecting enough personal information to notice connections the user did not explicitly identify. Its privacy burden grows with the same capability. Meta has made security a central part of Muse's pitch. The agent runs in a dedicated cloud virtual machine, credentials are stored outside the main agent runtime, and a separate Sentinel system reviews network traffic and connector actions. Meta also says Muse conversations and virtual-machine data are not shared with its advertising systems. The current architecture still permits Meta to access virtual-machine data when needed to operate, support or secure the service. Meta says a planned Confidential VM mode will eventually use encryption intended to prevent even Meta from accessing a user's data. Meta's data policy adds another reason disclosure must be specific. The company says conversations, tool calls and agent handoffs can be sanitized and used to train future Muse models by default, while users can disable that use in settings. Meta's published materials do not explain how information gathered from Mac notifications is classified under that policy. Aten's test does not establish that every Muse installation monitors notifications or that notification access bypasses macOS controls. It exposes a product-design failure with immediate privacy implications: Muse used personal context that its user did not understand he had supplied. For an agent sold on the promise that the user remains in control, that misunderstanding is part of the security model, not a communications detail.