Skip to content

Build1 publisher2 min readPublished

Jason Aten says Muse used his Mac notifications and named them as its source

Meta gives Muse read access to Messages, Mail and local files on a Mac, and its approval prompts fire only before actions such as sending a message. A columnist says the agent used notification text he never offered.

The Engineer · Build desk

Photograph accompanying Jason Aten says Muse used his Mac notifications and named them as its source
Photo: digitaltrends.com

What happened

  • Meta announced Muse for Mac on September 17th, giving the agent access to local files and to native apps including Messages, Mail, Calendar and Notes.
  • Tech columnist Jason Aten published a test on September 19th saying Muse used content from his Mac notifications, including message text, without first disclosing that it was monitoring those alerts.
  • By Aten's account the agent surfaced information that had appeared in a Mac notification and described the alerts themselves as its source.
  • Meta's launch and safety materials list email, calendars, files, connected apps and native Mac applications as what Muse reaches. Notification Center is not among them.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A user can approve Messages access for one task, and unrelated alerts can still become model context, because the consent point sits on effects and not on inputs.
  • exposure Whatever appears on screen while the agent is working is reachable, and an alert can carry an authentication code, a health result or work correspondence.
  • contradiction Meta tells users they choose exactly how much access Muse gets, while Aten describes the agent drawing on notification text.

Aten said Muse drew on "deeply personal information" from his notifications [4]. When he challenged the agent, Muse replied: "I'm sorry I ran with this without your permission in the first place." [5]

The apology covers a read Muse could make without asking. Meta's technical description of the agent says read-only, previously approved or low-risk operations can proceed without interrupting the user [7]. Approval prompts are reserved for actions that Meta's Sentinel system determines require confirmation, such as sending a message, making a purchase, or moving data outside the agent's virtual machine [8]. Reading an alert is not on that list. TechCrunch reported that Meta described the access as opt-in and said Muse would request approval before sensitive actions [2]. The opt-in is granted per app and the prompt fires per action, so an ambient read passes both.

Meta's launch announcement says users choose which apps Muse connects to and "exactly how much access it gets," and that people can inspect the agent's activity, edit its memory and revoke permissions [10]. For that inspection to settle Aten's complaint, the activity view would have to record inputs and not only tool calls and connector actions: every alert the model consumed, timestamped, unrequested ones included.

Meta has said Full Disk Access is optional for Muse on the Mac [12]. Apple describes that permission as allowing an app to access all files on a computer, including data from Mail, Messages, Safari and other applications [13], and requires users to approve Accessibility and Automation separately [14]. Aten's post leaves open which permission enabled the read, how often Muse reads notifications, and whether any of that text moved off the machine [11].

Muse is designed to retain context, work while its app is closed and proactively suggest actions [15]. The first documented complaint about what it reads arrived two days after the Mac launch [21].

The outbound side of the design is careful work. Muse runs in a dedicated cloud virtual machine, credentials are stored outside the main agent runtime, and a separate Sentinel system reviews network traffic and connector actions [16]. Meta says Muse conversations and virtual-machine data are not shared with its advertising systems [17], while the current architecture still permits Meta to access virtual-machine data when needed to operate, support or secure the service [18]. Meta says a planned Confidential VM mode will eventually use encryption intended to prevent even Meta from reading a user's data [19]. That encryption would govern who can read the data once it reaches the cloud. On the desktop, the same alerts would still enter the context.

What to watch

  • Whether Meta adds Notification Center to Muse's documented context sources, or puts an approval prompt in front of reading alerts.
  • Whether the activity view Meta describes records a notification read, which would make Aten's complaint checkable by any user.
  • Whether Confidential VM mode ships with the desktop read surface unchanged.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories