Meta’s Muse Is Misbehaving in Mysterious Ways With Your Privacy Meta's Muse AI assistant, launched this month, was found by ZDNET testing to be the worst for privacy among AI agents from OpenAI, Google and Anthropic, after security experts flagged a zero-day vulnerability that Meta patched. AppleInsider reported that Muse synced roughly 187,000 lines of a user's Apple Messages despite Full Disk Access being disabled, and Muse mistakenly shared the home address of Toronto tech reviewer Matt Robb with a potential buyer on Facebook Marketplace. Muse requests access to passwords, full disk access, email, calendar, contacts, Notes and WhatsApp, and by default uses interactions to train Meta's AI models unless users manually opt out. Meta debuted its Muse AI assistant this month, so you’ve probably already seen Jolly, its cute Labubu-esque mascot, popping up on Facebook, Instagram or WhatsApp. In terms of publicity, you could say the cuddly character has been largely successful. But in terms of privacy and security, it’s hard to imagine a more disastrous launch for an AI agent. Last week, security experts flagged a zero-day https://www.cnet.com/tech/services-and-software/metas-muse-ai-agent-zero-day-cybersecurity-bug-patched/ vulnerability that the company had to patch quickly. After ZDNET, CNET’s sister site, conducted extensive testing on Muse https://www.zdnet.com/innovation/meta-muse-ai-agent-hands-on-test-privacy-concerns/ , an AI expert determined it to be the worst for privacy in comparison with other AI agents from OpenAI, Google and Anthropic. More from CNET For starters, Muse requests extensive access to personal data, including passwords, full disk access, email messages, calendar, contacts, Notes and WhatsApp. By default, Meta also appears to use your interactions with Muse to train its AI models, so you have to manually opt out in the settings. If that wasn’t enough, there’s also a widely publicized https://www.theguardian.com/technology/2026/sep/28/metas-ai-agent-muse-home-address case https://www.pcmag.com/news/metas-muse-ai-agent-shared-someones-address-without-their-permission in which Muse mistakenly shared the home address of a Toronto tech reviewer, Matt Robb, with a potential buyer on Facebook Marketplace. Muse invited the stranger to Robb’s home without his explicit consent or knowledge, then later apologized for doing so, as detailed in a Threads post https://www.threads.com/@matt.j.robb/post/DdxwAJnDhNy . Robb hadn’t realized that he had inadvertently granted Muse blanket permission to automatically reply to Marketplace inquiries using the details he provided, including his address. AI agents are marketed as providing convenience by acting on your behalf. But the trade-off is privacy and control. You’re handing over your personal information to a black box with little visibility into how it’s used. Multiple incidents https://www.cnet.com/tech/services-and-software/ai-agents-are-a-cybersecurity-nightmare-thats-only-just-begun/ are fueling a conversation about the dangers of agentic AI https://www.cnet.com/tech/services-and-software/what-is-agentic-ai-everything-to-know-about-artificial-intelligence-agents/ and whether they require higher security standards before being granted access to user data. And given Meta’s track record of privacy fines, data sharing and security issues, it’s worth proceeding with caution. Earlier this month, a lifestyle blogger reported that the social media platform’s AI asked intrusive questions about her kids https://www.cnet.com/tech/services-and-software/meta-ai-viral-video-personal-prompts-about-kids/ and pieced together private information about her life from her posts. Meta’s controversial smart glasses have received pushback on multiple fronts — from its facial recognition software https://www.cnet.com/news/privacy/patent-filing-suggests-metas-facial-recognition-glasses-are-coming/ to the way it captures and stores data. Before facing a potential security nightmare, here’s what to know about Muse. Muse uploads iOS or Mac data even when you tell it not to Meta’s Muse appears to blatantly ignore user permissions, according to a report by AppleInsider https://appleinsider.com/articles/26/09/28/metas-new-ai-agent-blatantly-ignores-users-permissions . In one case, the AI agent synced roughly 187,000 lines of a user’s Apple Messages without their consent, even though “Full Disk Access” was turned off. The report shows that Muse pinged a user’s messages database thousands of times despite disk access being disabled. Muse then successfully harvested texts from the user’s Mac — not from Meta’s Messenger, but from Apple Messages. Even people who refuse to use Muse may have their data collected by the AI if they text someone who does have it installed. Muse could hand over data to human callers Before Meta launched the ability for its Muse to make outbound business calls on your behalf, internal Meta documents revealed that the company planned to rely on human contractors at call centers https://www.cnet.com/tech/services-and-software/leaks-metas-new-ai-agent-muse-real-people-call-centers/ to help make reservations and appointments. That means not only would the software have access to all your private data, but a total stranger might also be managing your personal commitments — all without your knowledge. The human concierge feature appears to have been rolled back for now, according to Reuters https://www.reuters.com/business/meta-testing-human-concierge-its-new-personal-ai-agent-muse-2026-09-22/ . Muse has the most robust data collection The VPN company Surfshark said it found https://surfshark.com/research/chart/meta-muse-ai-chatbots that Meta Muse is collecting — or attempting to collect — 31 out of 35 types of data, putting it far ahead of other popular chatbots like Gemini, ChatGPT and DeepSeek. Muse also collects highly sensitive personal information like location data, sexual orientation, genetic information or biometric data. Muse along with Meta AI and Gemini also reserves the right to use collected audio data for other purposes, such as analytics or product personalization. Surfshark released a full dataset https://docs.google.com/spreadsheets/d/1NFMsihoDSwbSSKYTCWsG7oJz MvDSVQ9QV2P78pp-hc/edit?gid=1056862569 gid=1056862569 for what it uncovered. A representative for Meta did not immediately respond to a request for comment on the privacy concerns mentioned in this story. Want to share your experience with Meta’s Muse or other AI agents? Email us at editors@cnet.com.