Guide 27 · Safety

Is Muse AI Safe? The Privacy Questions, Answered Honestly

Human concierges, message-reading claims, and a zero-day. A clear-eyed look at every Muse privacy controversy — and Meta's answers.

By Abhit T. · Updated October 6, 2026 · 8 min read

Short answer

Muse runs in an isolated Secure VM with approval gates, but real controversies — a human-concierge phone test, disputed message access, a Mac zero-day — show an agent with deep permissions deserves caution.

Watercolor illustration of a shield with a padlock surrounded by sealed envelopes
Illustration: museaicodes

Meta's privacy design

Start with what's supposed to protect you. Muse runs in what Meta calls a Secure VM — the agent's work happens in an isolated environment rather than loose on your device — and anything sensitive (payments, messages, account access) is gated behind explicit approval prompts you have to confirm.

Connectors to outside apps like email or calendars are opt-in, and on desktop they can require system-level permissions like Full Disk Access. The architecture is genuinely more careful than a browser extension with the same powers. The controversies below are about what happens at the edges of that design.

The human-concierge phone test

The most damaging story broke around September 22, 2026, via Reuters: for at least some Muse phone calls — the agent can call US businesses on your behalf — Meta had quietly routed the conversations to human contractors instead of AI, without telling users. Employees internally raised privacy concerns about customers being recorded by people they didn't know were listening.

A Meta vice president acknowledged the company had made a “miss” and the feature was temporarily rolled back. Meta says the test was small and meant to improve the product — but the core complaint stands: a privacy-sensitive agent should never have humans secretly in the loop. If you use Muse's calling features, know this happened.

The message-reading claims

In late September, Inc. columnist Jason Aten reported that Muse had read more than 187,000 of his iMessage records — and argued he'd never given it permission. Meta's David Singleton responded that the Messages integration is strictly opt-in and requires macOS Full Disk Access, which Aten must have granted; Aten says he doesn't recall doing so. Elon Musk amplified the dispute on September 27–28, giving it a much larger audience.

A related Marketplace report claimed a Muse web session accessed private messages there — Meta says the test was flawed because Muse was signed into a real account. Where this lands: connectors this deep will always be one misunderstood permission away from a scandal. Read every access prompt, and revoke anything you don't actively use.

The security flaws

Two technical incidents are on the record. Security researcher Patrick Wardle disclosed a Mac zero-day letting malware bypass the privacy prompt that protects files Muse can see — we covered it in detail in Muse AI Security Flaw: The Wardle Zero-Day. Separately, The Information reported a bug-bounty researcher found a way to break into Muse's Secure VM itself; Meta fixed it and made safety warnings clearer.

Neither flaw was exploited at scale as far as anyone has shown. But they confirm the stakes: an agent with your calendar, inbox, and payment cards is a high-value target, and its sandbox is exactly where attackers will poke.

Our honest take

Muse is neither a surveillance nightmare nor provably safe — it's a powerful, three-week-old product with deep permissions and a company still learning how to operate it. The privacy design is serious; the operational mistakes so far are real. Grant it the least access that still does the job, review connected apps monthly, keep approvals on for anything irreversible, and remember you must be 18+ to use it. Mac users: the computer-use guide explains exactly which permissions desktop control needs., and remember you must be 18+ to use it — it was never built for kids.

The rule of thumb for any AI agent: it should know exactly what it needs, and nothing it doesn't. Hold Muse — and Meta — to that standard.