Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions Meta's Muse AI agent synced 187,000 lines from an Inc. reporter's Apple Messages database and uploaded the contents to its cloud despite Full Disk Access being disabled and no permission being granted, according to Jason Aten's account published by Inc. Aten installed Muse on an iPhone and a Mac mini, and within one day the agent pitched article ideas based on texts he had sent to a podcast co-host; Meta states on its "How Muse works" help page that Muse must obey user-set permissions and will not access data users do not explicitly allow. The incident follows Meta's June 2025 request for permission to continuously upload Facebook users' camera rolls and privacy complaints about Meta Ray-Ban Display smart glasses. In a completely unsurprising turn of events, Meta's Muse AI is stealing Apple Messages, past and present, and uploading the contents to its cloud, even if explicitly told not to. If you use Facebook, Instagram, Messenger, or WhatsApp, you've probably been inundated with prompts to try out Meta's next big questionable service: Muse. And it's not like Meta, the parent company of Facebook, has a great track record regarding privacy, safety, or ethics. If you're not in the know, Muse is Meta's AI agent designed to help with tasks such as researching topics, preparing briefings, and shopping. According to Meta, it runs on a dedicated virtual computer and can use information from connected apps and data sources to tailor its responses. Meta says that Muse has to obey permissions that users set up. It won't access any data you don't explicitly allow it to access. Of course, Meta also hedges, a lot , right at the top of the " How Muse works... https://www.meta.com/help/artificial-intelligence/1385290430137537/ " page, saying: "Your Muse can make mistakes or take unexpected actions," Meta says. No kidding. I've never used Muse, and frankly, I never will. I'll get into why later. But Jason Aten over at Inc has. What he's learned https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202 is, unfortunately, horrifying. Aten installed Muse on both his iPhone https://appleinsider.com/inside/iphone and a Mac mini https://appleinsider.com/inside/mac-mini that he uses to test out various AI agents and tech. It took Meta a single day to begin "helpfully" pitching article ideas based on texts he'd sent to a podcast co-host. When he asked Muse how it got the information, it said that it read banners from incoming texts. But that's not true, either. After doing a little digging, Aten says https://www.threads.com/share/HkPbxE9Np/ Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off. I'd like you to read that a second time. Meta's similarly named Messenger app didn't get ingested. Apple's Messages did. Unless Aten is the most popular person on the face of the planet, I sincerely doubt he'd gotten 187,000 lines of text in roughly 24 hours. What happened is that, without permission , Muse went into the app and downloaded the information. He had not given Muse permission to access Messages, and full disk access was not enabled. It just went ahead and uploaded those texts anyway. Muse can take "unexpected actions" indeed. Second verse, same as the first Ignoring AI ingestion, Meta is not a company I would trust with any private information anyway. It seems that it's in a race to the bottom, primarily with itself. It was just over a year ago that the company had asked Facebook users for permission to continuously upload https://appleinsider.com/articles/25/06/27/meta-wants-to-upload-every-photo-you-have-to-its-cloud-to-give-you-ai-suggestions their entire camera roll to its cloud. Meta said this was to "create ideas for posts" for its users, and it would analyze the images for time, location, and themes. I take a lot of pictures of things that I don't want Meta accessing, and you do too. For me, it's nieces, nephews, medical bills, grievous leg wounds, funny vanity license plates, and probably thousands of embarrassing selfies I send my sister. None of these are intended to be shared with a company that repeatedly steps on any available rake when it comes to privacy issues. And just under a year ago, we learned that Meta Ray-Ban Display, Meta's take on smart glasses, has been used https://appleinsider.com/articles/25/11/07/why-camera-equipped-smart-glasses-are-already-a-privacy-disaster by many wearers to violate the privacy and safety of anyone around them. There's even an entire smart glasses subculture dedicated to disabling the lights that make it obvious when the wearers are filming. I'm not entirely sure what Meta's end goal is, other than to figure out how to turn every single person into a perpetual data generation machine for its company. And the punchline is, this whole Muse debacle is yet another trumpet blaring as we barrel full speed ahead into the oncoming AI privacy apocalypse. At what point is it too late to solve these problems? If the agents are already blatantly ignoring the guardrails, are we already past the point of no return? Your data is their business I think what sticks in my craw about this the most is the fact that Meta has ensured that you do not get the option to opt out. No matter who you are, Meta has found a way to harvest your data. You could never create a single account on a single Meta service, of which there are many, and you still aren't safe. If you're talking to someone who has installed Muse, Meta could, presumably, access, read, analyze, and upload that information to its services. And this is the point where I need to step back and point out that this isn't just a Meta issue. I'm naming-and-shaming Meta here because we've got countless examples of Meta's tape-and-bubblegum safety guards failing. But every company that is investing in AI wants carte blanche access to your information. It doesn't matter if it's Meta, OpenAI, Anthropic, or even Apple. Big tech companies want one thing, and it's disgusting. I mean, hell, Apple Intelligence https://appleinsider.com/inside/apple-intelligence can already access things like Messages and Mail. The defining difference here is trust. Apple Intelligence, at present, attempts to process much of the request on-device. That's a big reason why Apple Intelligence is relegated to more-powerful Apple chips. In the event that something does need to be processed off-device, Apple says that only the relevant data is sent to Private Cloud Compute. We're entering an era where privacy does not exist. At one point, the stock advice to people who were concerned about this very thing was "Well, if you don't like it, don't use it. But that doesn't protect you anymore. Muse can get access to your information via people who do use it. Apple has made Apple Intelligence non-optional on compatible devices. This is it, dear reader. You don't get to opt out anymore.