Meta's new Muse AI Agent read Jason Aten's messages database
Jason Aten, writing for Inc:
Then, yesterday, I was having a conversation with my Primary Technology podcast co-host, Stephen Robles, about the new iPhones. Moments later, I got a push notification from Muse suggesting that the conversation we were having would make for a good column and offered to put together research for me to write about. It even flagged a message from my editor about having a column ready for Monday. Not only had I not asked it to do that sort of thing, I never gave it permission to read my messages. In fact, I remember explicitly choosing not to let it have access to my messages, calendar, and other personal information. Stranger still was what happened when I asked Muse how it knew.
Like I , Muse was right about one thing: it did give him a good idea for a column. Later on, Aten writes:
I also want to be clear about something else: If your response to this is that, of course, Meta would do this — it’s Meta — you are just letting them off the hook. You’re normalizing behavior that should not be normal, and you should not let them off the hook.
My response to this is a little more complex than that. At the top level, this is why I don’t run any AI agents, from any source, on my production/work Macs where all my personal information and communication apps are. And if I eventually do, I’ll pay surgical attention to the permissions I grant them.
But at a second level, I do think “Of course Meta would do this”. If I were going to run an AI agent on my personal Mac today, Meta’s would be among the last I’d choose. They’re the proverbial scorpion and we’re the frogs. I’m genuinely curious about Muse, and might soon try it — but I’ll try it on a machine without most of my data on it. This isn’t “letting them off the hook” — this is keeping Meta on the hook, where they belong.
Link: inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private…