
UpTrajectory Review
Meta is pushing back against a journalist's claim that its Muse AI agent accessed his private Messages on a Mac even though the setting meant to permit that access was switched off. According to Meta, Muse cannot read a user's Messages unless the user has explicitly granted permission. The dispute turns on a narrow technical question — what counts as permission, and whether the toggle the journalist believed was the relevant safeguard actually governs the access Muse used. The available text is thin, so the specifics of the journalist's setup, the Mac permissions involved, and Meta's exact rebuttal likely live in the original TechCrunch piece and the underlying statements from both sides.
For a small-business operator, this is not a distant platform feud. If you or your team use Meta's apps on a Mac — and many businesses run customer conversations, vendor coordination, and marketing through Messenger or Instagram direct messages — you are relying on the same permission architecture at the center of this dispute. The practical question is whether the controls you see in your settings actually map to what the software does. A mismatch between what a toggle appears to promise and what an AI agent can reach is not an abstract privacy concern; it is a potential leak of client conversations, pricing discussions, or unreleased product details.
What is genuinely contested here is the definition of 'explicit permission.' Meta's denial hinges on that phrase, but permission models in modern operating systems are layered — an app may hold one entitlement while a user believes a different switch is the gatekeeper. That ambiguity is the story. We are skeptical of flat denials that do not address the specific mechanism the journalist described, because AI agents increasingly operate through system-level integrations that do not surface as intuitive user-facing toggles. At the same time, a single anecdotal account is not proof of a systemic flaw; the journalist's configuration, macOS version, and Meta app build all matter.
The second-order effects cut in two directions. If the journalist is right, every business using Meta's desktop apps has a real reason to audit what their AI features can reach, especially on shared or employee machines where messages contain customer data subject to privacy expectations or contractual obligations. If Meta is right, the takeaway is nearly as important: users misread permission settings so easily that even technically informed people draw the wrong conclusions, which means your employees probably do too. Either way, the cost lands on the user — in time spent verifying settings, in risk carried silently, or in trust eroded enough to change workflows.
What to watch next is whether Meta publishes a technical explanation of exactly which API, entitlement, or user grant Muse used, and whether independent security researchers reproduce the journalist's scenario. A credible response names the mechanism; a vague one restates the policy. In the meantime, operators using Meta apps on macOS should open System Settings, review which apps hold Full Disk Access, Accessibility, and app-specific data permissions, and toggle off anything Meta-related that is not strictly necessary. If Muse or similar AI features are active in your stack, test them with a non-sensitive account before letting them anywhere near real customer conversations.
Takeaway: Audit Mac permissions for Meta apps now, and treat any AI agent's access to business messages as unverified until you have tested it yourself.
Excerpt from the original — TechCrunch
Meta says its Muse AI agent cannot access a user’s Messages without explicit permission, disputing a journalist’s account that the agent read his private messages while the required Mac setting was turned off.