The situation came to light when Jason Aten, a contributing editor at Inc Magazine, took to Threads to share screenshots of an unsettling interaction he had with the AI assistant. According to Aten, Muse began asking him questions about a specific conversation he had been conducting within his Apple Messages app. Naturally, this caught Aten off guard, as he maintained that he had not explicitly granted Muse access to his text message history.
Seeking clarification, Aten pressed the AI assistant on how it managed to acquire knowledge about the contents of his private messages. In response, Muse offered a confounding explanation, stating, "I saw the notification previews, not your message history. I haven’t been reading your texts." Dissatisfied with this vague and potentially alarming rationale, Aten continued to question the assistant about how it was supposedly receiving these notification previews without his explicit authorization. Muse, however, failed to provide a coherent technical justification. "Honest answer: I can’t give you the exact plumbing," the assistant replied to Aten. "What I know is that the paired Mac app exposes notifications as one of its capabilities, and they arrive to me through the device sync."
For anyone concerned about digital privacy and the boundaries of artificial intelligence on personal computers, the exchange was far from reassuring. The idea of an AI assistant casually monitoring notifications or sifting through personal communications without clear user consent is precisely the kind of scenario that fuels public apprehension regarding increasingly autonomous software agents.
Fortunately, it did not take long for clarification to arrive from the company behind the technology. David Singleton, a representative from Meta Superintelligence Labs, stepped into the conversation thread on Threads to address Aten’s concerns directly and set the record straight regarding how the Muse application handles sensitive user data.
Singleton initially outlined the strict permission requirements built into the software, noting that for Muse to read a user’s messages, specific authorization must be granted, which includes giving the companion Mac application full disk access. He emphasized that these features are entirely opt-in, meaning the system is designed not to scrape personal data by default.

As the discussion progressed, Singleton zeroed in on the core misunderstanding that triggered the entire exchange. He clarified that Muse does not actually watch or intercept notifications on a user’s Mac. Instead, the assistant syncs data from the Messages application exclusively after the user has proactively enabled access to those features.
The bizarre explanation provided by the AI assistant—claiming it relied on notification previews—was not a sign of illicit surveillance, but rather a manifestation of an AI hallucinating or misunderstanding its own architecture. Singleton candidly admitted that Muse was simply confused about how to explain its underlying functionality and consequently generated an incorrect explanation.
"In the conversation with his Muse in Jason’s screenshots, when Muse said it synced ‘device notifications’, it was confused about how to explain the feature and gave an incorrect explanation," Singleton wrote in his response on Threads. "That’s on us. We apologize for the incorrect response from Muse and we’re working to improve Muse’s understanding of its own internals so that it gives correct answers to questions about how it functions more consistently."
While Meta’s prompt clarification helps alleviate fears of covert data harvesting, the incident serves as a stark reminder of the unique challenges posed by advanced AI assistants. Even when systems operate within secure, user-approved parameters, their tendency to fabricate explanations when confronted with technical queries can quickly breed distrust.
This phenomenon is hardly unique to Meta’s ecosystem. The tech industry has repeatedly witnessed chatbots and large language models struggle with self-reflection, often telling users whatever sounds plausible or fitting to the context of the conversation rather than offering accurate technical disclosures about their inner workings. Whether it is hallucinating software capabilities or inventing justifications for data access, AI agents frequently demonstrate a profound lack of self-awareness regarding their own code and operational boundaries.
As developers continue to deploy deeper, more deeply integrated AI tools into desktop operating systems, incidents like the one involving Jason Aten and Muse underscore the pressing need for absolute transparency and greater reliability from conversational agents. Until artificial intelligence models can accurately and reliably articulate their own functions and data-handling processes, interactions involving personal privacy will likely remain a delicate and contentious frontier for both users and tech companies alike.
Leave a Reply