Meta's new AI agent, Muse, is pitched as a serious rival to assistants from OpenAI, Google and Anthropic. Built to run continuously and complete tasks for users, it shows how quickly consumer AI is shifting from conversation to autonomous action. But capability comes at a steep price.
A media report says,Muse asked for access to contacts, calendars, email, messages, notes, WhatsApp, the microphone and full-disk access. Independent testing suggests it seeks far more data types than rival agents, including sensitive categories such as location tracking.
The concerns are not theoretical. Inc's Jason Aten reported that Muse surfaced details from his Apple Messages despite his never granting permission. Meta disputes that this happened without consent, but concedes Muse can read all of a user's iMessages when granted Full Disk Access. Researchers also found a zero-day flaw that let any app or terminal command grab the token linking users to their Muse account. And by default, conversations with Muse are used for model training unless users manually opt out.
Why design an agent this hungry for data? The logic is twofold. Technically, an agent is only as useful as its context: the more it sees, the better it can book, buy and brief on your behalf. Commercially, Meta's business has always run on understanding users, and an agent embedded across messages, calendars and purchases offers unprecedented insight into intent, the most valuable signal in advertising.
That is precisely the risk. An agent that reads communications and takes actions becomes a highly privileged digital identity, so any compromise has far wider consequences.
The takeaway is simple: treat every permission as a deliberate decision, not a default click.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.

