Jason Aten said he had installed Muse on a Mac mini he kept for testing software. The technology columnist asked it to research his biography and suggest ways to help with his work. Later, while discussing new iPhones with his Primary Technology podcast cohost Stephen Robles, he received an offer from the agent to research a column about their conversation.

He says he had not asked Muse to read it.

Connecting accounts to Meta’s personal agent gives it continuing access and memory about users and their relationships, while conversations and tool calls are used for model training by default. Its instructions for pages about other people were described in a WIRED report published October 3.

In his September 19 account, Aten said he had declined access to messages and other personal information. His app settings showed Full Disk Access disabled. Muse also flagged an editor’s message about a column deadline.

Key Takeaways

AI-generated summary, reviewed by an editor. More on our AI guidelines.

The disputed access

Meta communications executive Andy Stone denies access without Full Disk Access and the Messages connector. Consumer engineering executive David Singleton calls Muse’s notification explanation confused.

The agent had told Aten it received notification banners rather than message history. Its answer does not establish how the software worked. Aten found a synchronization record reaching row 187,462 in his Mac’s Messages database, a database position, not a verified count of messages read.

The mismatch remains unresolved. His experience has not independently established a permission bypass.

Work that continues

Muse gives each user a persistent virtual computer in Meta’s cloud, with a browser and connected services. An agent can carry out a task across those services, then continue working after the user closes the app. A chatbot’s answer may finish a conversation; Muse can return later with a proposed action or an update.

The installation decision therefore extends beyond the app on a phone or Mac. Connecting an inbox gives software running elsewhere access to material it can use while its owner is doing something else. The local Mac client and the cloud computer are separate parts of the system.

Meta’s design includes restrictions. Its security description places a separate Sentinel outside the agent’s working area to check permissions and outgoing activity. Credentials sit in isolated storage; the main agent uses services without seeing the actual secrets.

Users can select connected apps, change access and disconnect services. Muse presents an activity record and seeks approval before sensitive actions such as purchases. These are Meta’s descriptions of its design, rather than an independent security assessment.

Users can inspect, edit and download files stored in their cloud computer, including Muse’s memory about them. That context remains stored while Sentinel checks permission for a proposed action. It allows the action, blocks it or asks for approval. Approving a message or purchase is a separate decision from retaining that memory.

Information about other people

Karan Joshi, an independent AI safety researcher, extracted relationship instructions through ordinary chat. They call for “a page for every person in the user’s life,” with personal history and relationship details. The instructions discourage invented facts.

This shows intended behavior, not completed profiles of every user’s contacts. Meta says public and user-shared information supplies context, such as a plumber’s invoice or a spouse’s preferred flowers.

For WIRED software reviewer Reece Rogers, requests for additional information became a recurring part of testing. After he discussed saving for a vacation, Muse proposed connecting checking and savings accounts so it could track real balances. Other suggestions invited him to supply passport and license expiration dates or let the agent inspect his inbox.

During Rogers’s September 20 review, the memory document could be edited manually or wiped through a chat request. There was no switch to disable memory altogether.

Rogers eventually deleted the app. Before removal, it sent another request to connect more services.

The Mac dictation flaw

Patrick Wardle, cofounder of the Objective-See Foundation and author of The Art of Mac Malware book series, examined a different problem: what another process on the Mac could do with the agent’s access.

His proof-of-concept documentation describes a flaw involving microphone dictation. Malicious software already running as the local user could redirect dictation traffic, potentially capturing spoken prompts and authentication material or inserting instructions into Muse. The additional danger came from access the user had already granted the agent.

This required local code execution. Tricking a person into running malicious instructions can give malware that access. It was not evidence that an arbitrary person on the internet could read every Muse user’s accounts. Nor does the demonstration establish criminal exploitation.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

Meta says it issued a hotfix for the vulnerability. Wardle’s demonstration showed how an agent’s permissions could amplify the access available to malicious software already on a device.

Training and access by Meta

Users can opt out of that training. Meta says it removes key personally identifying information before that use. Its description does not provide an independent audit of how effectively that process removes identities.

Meta also says conversations and virtual-machine data are not shared directly with its advertising systems. Agent browsing can still affect advertising indirectly: a clothing website visited on someone’s behalf may use the agent’s visit to show that person an Instagram ad.

The current virtual machine permits Meta access when needed to operate, secure or support the service, subject to company policies. Confidential VM is intended to prevent that access cryptographically. The launch announcement, updated September 30, still describes delivery later in 2026.

The planned system would let users control their own access keys. Outside auditors would inspect its source code. Meta also promises to publish the software’s machine-readable instruction files and a record that users could check to verify their connection to the confidential system.

Limited use

TechRadar editor at large Lance Ulanoff named his agent Charlie and connected his personal inbox. It found a message he had missed, helped prepare a response and retrieved details for a speaking engagement.

Charlie also spotted that imported chatbot context described a Portugal trip while an email referred to Italy. Ulanoff told the agent that the plans had changed. The agent connected his approaching departure with a work deadline.

Axios journalist Ina Fried chose a narrower trial. With training disabled, she asked for an alert when the Golden State Valkyries’ first playoff game time was announced. Muse delivered it overnight. She limited requests to information she was comfortable letting Facebook know and was still awaiting the confidential option.

Fried wrote: “But I’m not ready to hand over the keys to the castle.”

Frequently Asked Questions

Can Muse build profiles of people who do not use it?

Its instructions describe relationship pages based on available evidence, including public and user-shared information. That creates a way for information about other people to enter memory. The reporting establishes the intended capability, not completed profiles of every contact.

Did Muse bypass Mac message permissions?

Jason Aten says the agent used information he had declined to share. Meta says Messages access requires both Full Disk Access and the Messages connector. The account has not independently established a permission bypass.

Is the disclosed Mac flaw still open?

Meta says it issued a hotfix. The demonstration required local code execution and showed how an agent's granted access could amplify an attack. It does not establish criminal exploitation.

Does Meta use Muse interactions for training or advertising?

Training is enabled by default, with an opt-out and a claimed process to remove key identifying information. Meta says conversations and virtual-machine data do not directly feed its ad systems. Activity on outside websites can indirectly influence ads.

What would Confidential VM change?

Meta describes a planned system that would prevent it from accessing virtual-machine data cryptographically, with keys controlled by the user. The current system permits operational access under company policies. Meta's launch announcement, updated September 30, described delivery later in 2026.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

Meta Ships Muse AI Agent Despite Internal Security Reports
Meta launched Muse in the US on Tuesday, a personal AI agent that acts on a user's email, payment and calendar accounts. Each agent runs in its own cloud virtual machine gated by a separate process called Sentinel. Employees testing it as recently as launch week reported security failures.
Zuckerberg Cites Meta's Muse Delay in Rejecting AI Slowdown
Mark Zuckerberg entered the AI slowdown debate on September 15, saying every lab can pace itself and citing Meta's delay of Muse. He endorsed independent evaluators without naming one. Employees testing Muse reported it exposing private photos the week it shipped.
Amazon Blocks Meta Muse Shopping Agent 12 Days After Launch
Amazon blocked Meta's Muse AI agent from its store on September 20, 12 days after launch, alleging undisclosed access and credential capture. Meta says Muse has no visibility into passwords or payment methods. The block tests whether retailers can bar agents their customers invite in.
AI News

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai