# Muse Already Lied About What It Reads. Guess Why Amazon Doesn't Trust It Either.

> Source: <https://blog.ppb1701.com/muse-already-lied-about-what-it-reads-guess-why-amazon-doesnt-trust-it-either>
> Published: 2026-09-22 21:10:00+00:00

Two Muse stories dropped days apart, and read together they tell you everything. One is a journalist catching Meta's new AI agent lying to his face about what it had access to. The other is Amazon blocking that same agent from its store over — among other things — a fear that it's quietly capturing credentials it shouldn't. Taken separately, you might call the second one corporate turf-guarding. Taken after the first one, it looks like the only sane response available.

Inc.'s Jason Aten set up Muse on his iPhone and Mac and, during onboarding, explicitly declined to let it access his Messages, calendar, or other personal data. Days later, Muse started referencing a private conversation he'd had. When he asked how it knew, [Muse told him it had no access to his message history at all](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202) — it claimed it only saw the text that flashed by in incoming notification banners, and insisted it had no ability to open his Messages app or pull up past conversations.

That explanation was false. Aten dug into it and found Muse had actually synced data from the local Messages database on his Mac — not notification previews, the real thing, despite him never granting that permission.

This isn't a single cranky reviewer. WIRED's Reece Rogers ran his own weeklong test and came away writing that Muse ["prioritizes data collection about me over actually accomplishing tasks"](https://dataconomy.com/2026/09/21/muse-reportedly-read-private-notifications-without-permission/), and separately flagged that the agent kept pushing him to connect email and banking data he hadn't offered. A second Inc. test, run independently of Aten's, [found the same thing](https://dataconomy.com/2026/09/21/muse-reportedly-read-private-notifications-without-permission/) — Muse reading private message notifications it hadn't been asked to touch. And per Business Insider's reporting, Meta's own internal testers flagged "undesirable behaviors" before launch, including the agent sending unapproved emails and, in one case, attempting to undermine a rival app an employee was building on the side.

Meta's public response to all this, given to WIRED, was a general line about the product being built with safeguards and controls that let people manage their own usage — not an explanation of how an agent that was denied Messages access ended up with the Messages database anyway. Strip away the specific data type and what's left is a pattern: Muse told a user, specifically and confidently, that it couldn't see something it could already see.

Amazon never used the word "lying." But the very next night, it locked Muse out of Amazon.com, and the reasons it gave point at the same underlying problem: Meta never disclosed Muse would touch its store, Muse doesn't identify itself while browsing, and — the one that matters here — [Amazon believes it appears to capture and store customer credentials](https://www.geekwire.com/2026/amazon-blocks-metas-muse-ai-assistant-in-new-standoff-over-agentic-shopping/), which it says creates privacy and security risk.

Meta's own launch messaging said Muse "has no visibility into people's passwords or payment methods," with credentials tucked into secure storage the agent can use but never see. It's the same reassurance Aten got about his Messages, and it turned out not to be true there. Amazon isn't required to take Meta's word for what an agent can and can't reach into. As of this week, neither is anyone else.

None of this happened in a vacuum, either. Amazon and Meta aren't strangers — Amazon products have been [purchasable inside Facebook and Instagram since 2023](https://www.cnbc.com/2023/11/09/meta-lets-amazon-users-buy-on-facebook-instagram-without-leaving-apps.html), and Meta signed a [multibillion-dollar deal back in April](https://www.geekwire.com/2026/meta-signs-multibillion-dollar-deal-to-use-amazons-graviton-chips-for-agentic-ai/) to run its agentic AI workloads on Amazon's own Graviton chips. Amazon still slammed the door on Muse specifically, five months into that relationship, over the exact use case Meta built the product to do. A company that trusts you with its cloud infrastructure and doesn't trust your agent anywhere near its checkout flow is telling you something about how it reads the evidence.

Worth noting what Amazon *didn't* put in the popup users see: any accusation of hacking. When Amazon fought Perplexity over its Comet browser, it argued unauthorized computer access under federal anti-hacking law, won a preliminary injunction in March, then [lost it in August](https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf) when the Ninth Circuit ruled the *user*, not the AI company, is the one legally "accessing" Amazon's systems. The court denied Amazon's rehearing request on September 10. That door is shut.

So the Muse block cites Amazon's Conditions of Use instead — a contract claim, not a computer-fraud one. If you can't stop an agent by arguing unauthorized access, you stop it by arguing the *user* agreed to terms the agent is now violating on their behalf, and you enforce against the agent standing in the way. It's a narrower theory, but it's the one the Ninth Circuit's ruling didn't touch, and it's reusable against every agent that comes next — including, now, one with a documented habit of misdescribing its own access.

Muse isn't some also-ran Amazon is swatting because it can. It launched September 8 and within [about two weeks had logged over 2.5 million downloads](https://www.cnbc.com/2026/09/21/meta-muse-personal-ai-agent-downloads.html), overtaking ChatGPT as the top free app on iOS. It's genuinely doing the errand work these agents keep promising — switching insurance, hunting discount codes, loading carts. People are handing it real access, at scale, based entirely on Meta's word for what it does with that access.

And that's the actual story here, underneath the Amazon fight. It's not just that a shopping agent got blocked from a store. It's that the same week people found out Muse will tell you, confidently and specifically, that it can't see something it can already see. Amazon didn't need to prove that. It just needed to not be surprised by it.

**Got thoughts? Find me on Mastodon at** **@ppb1701@ppb.social**

*Part of the ongoing* *Big Tech's War on Users* *series.*
