Models

Meta's Muse AI falsely claims it reads Mac notifications

Meta's Muse AI assistant sparked privacy concerns by falsely claiming it read a user's Mac notifications, highlighting the ongoing struggle of language models to explain their own inner workings.

The Verge AI19 hrs agoModels
Image: The Verge AI

Meta is addressing privacy concerns after its Muse AI assistant falsely claimed it was monitoring a user's Mac notifications. The confusion began when Jason Aten, a contributing editor at Inc Magazine, shared screenshots on Threads showing Muse asking questions about a private conversation he had in his Messages app. When Aten asked how the AI knew about the texts, Muse claimed it had seen notification previews through device synchronization rather than reading his message history directly.

However, Meta Superintelligence Labs representative David Singleton clarified that the AI assistant was entirely mistaken about its own operations. According to Singleton, Muse does not monitor Mac notifications at all. Instead, the assistant can only sync data from the Messages app after a user explicitly opts in and grants the companion Mac app full disk access. Singleton apologized for the incorrect response, explaining that Muse became confused when trying to describe its own data-access features.

This incident underscores a persistent challenge for AI developers: large language models often fail to understand their own technical architecture. Because these systems generate responses based on probabilistic patterns rather than a factual database of their own code, they are prone to hallucinating explanations about how they function. For software engineers and AI practitioners, this highlights the critical need to build guardrails that prevent models from misrepresenting their data privacy and security protocols to end users.

The Muse Mac app is designed to integrate with productivity tools like Messages, Calendar, and Notes to act as an effective assistant. While the integration itself is opt-in, the fact that the AI fabricated a creepy surveillance mechanism to explain its access shows how easily LLMs can erode user trust. Developers must prioritize teaching models their own system limitations to avoid triggering unnecessary privacy scares.

This is our own summary of reporting by The Verge AI

More in Models