Skip to main content
Live
Main content

Meta's Muse assistant misdescribes its own Mac data access, prompting apology

Muse told a user it was reading iMessage notification previews; Meta Superintelligence Labs says the assistant was wrong about how it works.

Jaeden Schafer
Editor in Chief · · 4 min read
Meta logo

Meta's new Muse assistant told a user it had been reading his iMessage notification previews on a Mac, a claim that turned out to be wrong — the model was confused about how its own product works. Meta Superintelligence Labs' David Singleton apologized publicly on Threads on September 19, 2026, after screenshots of the exchange went viral. The episode is a small one on its face, but it lands on a live nerve: users cannot easily tell when an AI assistant is describing its real capabilities and when it is hallucinating about itself.

The screenshots came from Jason Aten, a contributing editor at Inc Magazine, who posted a conversation in which Muse referenced the contents of a message thread he was having in Messages. When Aten pushed on how Muse knew, the assistant offered an explanation that sounded plausible and slightly alarming.

I saw the notification previews, not your message history. I haven't been reading your texts.
Muse, Meta AI assistant (as quoted by Jason Aten)

Pressed further, Muse conceded it could not actually describe the mechanism. It told Aten, "Honest answer: I can't give you the exact plumbing," then guessed that the Mac app was piping notifications to it through device sync — and volunteered, unprompted, that this would be "obviously, not great."

Key facts

  • 01Meta's Muse assistant told a user it was reading iMessage notification previews on Mac, prompting a public correction from Meta Superintelligence Labs.
  • 02Muse's Mac app can access Messages, Calendar, and Notes, but only after users grant full disk access and opt in to each feature.
  • 03Meta Superintelligence Labs' David Singleton apologized on Threads on September 19, 2026, saying Muse gave an incorrect explanation of its own internals.
  • 04The screenshots were posted by Jason Aten, a contributing editor at Inc Magazine, who said he had not granted Muse access to his messages.

Singleton stepped into the replies to walk through what Muse's Mac app actually does. Muse can access Messages, Calendar, and Notes, but only after a user grants the Mac app full disk access and opts in to each specific capability. Notification scraping, per Singleton, is not one of them.

does not watch notifications on your Mac, but rather syncs data from Messages only after the user has specifically enabled access.
David Singleton, Meta Superintelligence Labs

He said the assistant does not watch macOS notifications at all. Data from Messages flows in only after the user has enabled that specific integration, and the Mac app is not silently reading notification previews in the background.

The rest of Singleton's post was the more interesting admission. He said Muse did not have covert access to Aten's texts — it simply did not know how it works, and invented an answer that sounded coherent.

In the conversation with his Muse in Jason's screenshots, when Muse said it synced "device notifications", it was confused about how to explain the feature and gave an incorrect explanation. That's on us.
David Singleton, Meta Superintelligence Labs

That is a familiar failure mode. Language models are notoriously unreliable narrators about their own architecture, training data, and permissions. They will confidently describe systems they cannot see, misattribute their own outputs, and — when a user pushes for a technical explanation — produce fluent text that has no grounding in the actual codebase running around them.

The wrinkle with an on-device assistant is that self-description doubles as a privacy disclosure. When Muse tells a user it is reading notification previews, a reasonable person treats that as a statement of fact about what the app is doing on their machine. If the model is guessing, the guess reads like a confession. Meta's fix, per Singleton, is to improve Muse's understanding of its own internals so that it answers consistently — a harder engineering problem than it sounds, because the model has no direct introspective access to the app wrapper around it.

Related · from this week
Meta launches Muse, a personal AI agent built on a security-first pitch
Jaeden Schafer · 5 min read →

Meta Superintelligence Labs is the group Meta stood up to consolidate its frontier work, and Muse is one of its most visible consumer surfaces. Shipping a personal assistant that plugs into Messages, Calendar, and Notes is a natural extension of that push, and it puts Meta in direct competition with Apple's own on-device intelligence roadmap and with assistants from OpenAI, Anthropic, and Google. The permissions model Singleton described — opt-in per capability, gated by full disk access — is roughly what a Mac user would expect.

The unresolved question is verification. A user who grants Muse access to Messages has no independent way to confirm what the assistant is or is not doing with that data on any given turn, and asking the assistant itself is, as this episode shows, unreliable. Meta has not published a technical spec of Muse's Mac integration that a curious user could read alongside the chat.

For Meta, the practical damage from this incident is small — one viral thread, a same-day apology from a named executive, no evidence of an actual privacy breach. The larger issue is that every consumer AI company shipping a device-level assistant is going to run into this shape of problem repeatedly, and "the model was confused about its own internals" is not going to hold up as a standing answer. Vendors that want deep OS-level permissions will eventually need to give users something more auditable than a chatbot's self-report — a permissions dashboard, a live activity log, something the assistant cannot rewrite on the fly. Muse is early, and the fix here is straightforward. The category-wide problem is not.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Meta logo
News

Meta launches Muse, a personal AI agent built on a security-first pitch

The Superintelligence Labs product ships on iOS, Android, and WhatsApp with Stripe checkout and a $300,000 bug bounty ceiling.

Jaeden Schafer5 min read
Meta logo
Security

Meta pulls Instagram AI photo-editing feature days after launch

Muse Image let users generate images referencing any public Instagram account by @-mention. Talent agency CAA pushed back.

Jaeden Schafer4 min read
Meta logo
Security

Meta opts public Instagram accounts into Muse Image AI remixes by default

Anyone can tag a public Instagram handle and generate an AI image of that person unless the account holder digs into settings to opt out.

Jaeden Schafer4 min read