Meta Muse AI Faces Privacy Questions Over Access To Private Messages

Meta's new AI agent Muse is receiving attention not only for what it can do but also how much personal information it can access.

Meta Muse AI agent privacy concerns over messages | Photo Credit: https://www.meta.com
Meta Muse AI agent privacy concerns over messages | Photo Credit: https://www.meta.com

The issue was raised after a private message made on an Apple device was reported, and the conversation about privacy and permissions for AI agents intensified.

Muse is designed as a personal AI agent that can perform tasks beyond a traditional chatbot. Meta says it can browse the web, interact with connected applications, complete certain tasks and retain information shared with it.

Users can also select which services Muse is allowed to connect to, the company said.

The privacy concerns began when technology journalist Jason Aten reported that Muse appeared to refer to information from his private iMessage conversations while suggesting a work task.

It was then that the AI had accessed information stored in the Messages application without the expected level of permission.

Meta has rejected the suggestion that Muse can simply access private messages without authorization. According to Meta communications executive Andy Stone, the Messages integration on Mac is optional.

Users need to enable Full Disk Access and the Messages connector before Muse can access content from Messages.

The problem is particularly acute in that AI agents are designed to work across multiple applications. Unlike AI chatbots, those systems can interact with different services and sources of information on the user’s device. That is why permissions are so important for them in how they work.

Meta says Muse uses a dedicated Secure VM, or virtual machine, to separate connected data and credentials from other systems. The company has also stated that conversations and data stored inside the virtual machine are not shared with Meta's advertising systems.

For sensitive activities, Muse is designed to involve the user before taking action. Meta says actions such as sending emails or making purchases can require confirmation, while the system maintains an audit trail of activity.

Also, Apple has talked about concerns over AI applications that want to have access to sensitive data and can access a wide range of data on Mac computers.

The company is also likely to introduce more safeguards for applications seeking to access sensitive data, such as messages, emails, and browsing information.

Meta also announced a new privacy-focused feature for Muse called Confidential VM. The new system will encrypt the virtual machine with user data and conversations with Muse and have the user at the center responsible for the encryption key.

The situation serves as a reminder of AI agents’ biggest challenges. And that is not just because an AI system can be more useful, but also because it can be more personal. And so we need clear permission controls and transparency in these systems to do so.

For people who are considering AI agents like Muse, reviewing connected services and device permissions is a necessary prerequisite before the technology can be used to work with personal information.