Most popular now
Advertisement

Meta Unveils AI Agent Muse Collecting Extensive User Data While Apple Tightens Privacy Controls

Meta created SHI-agent Muse
Meta представляє нового AI-агента, який збирає велику кількість даних користувачів, в той час як Apple посилює контроль за конфіденційністю. Photo: НВ — Техно

AI Personal Assistants and Privacy Concerns

According to НВ — Техно: Meta has introduced Muse, an AI-powered personal assistant capable of gathering and storing comprehensive data about users, including information about their family, friends, and social circles. Operating on a cloud-based system tied to the user, Muse accesses sensitive details such as banking, medical records, and messaging. However, security flaws discovered within the system raise concerns about potential data breaches. In response, Apple is ramping up its privacy safeguards to limit data access and mitigate risks linked to AI-driven agents.

Data Architecture and Security Risks

Owned by Meta, the parent company of Facebook and Instagram, Muse leverages cloud technology to connect with a user’s financial accounts, communications, and health information. The AI assistant is programmed to compile profiles not only on the user but also on their relatives, partners, friends, and colleagues, sparking worries about how personal information is handled. Data about other individuals can be sourced from user input, conversations, or linked data streams. Security researcher Peter James examined the file system of his Muse agent and detailed its data storage structure, highlighting key aspects of how information is maintained.

Muse’s memory consists of text files documenting user details, daily logs, situational context, personal experiences, and preferences. A background process scans for new inputs every hour, appending references to evidence. All information is indexed within a searchable database, recording source, confidence levels, and statement status. New entries may overwrite older ones without retraining the AI model. In September 2026, macOS security expert Patrick Wardle uncovered a vulnerability in Muse that allowed tampering with the speech recognition server address and interception of access tokens. Meta promptly patched this issue following its disclosure on Ars Technica.

Apple’s documentation warns about indirect instruction injection risks, which could trigger unintended actions by AI assistants and lead to consequences like financial loss or data deletion. Meta employs a system named Sentinel to monitor Muse’s operations and network requests. The company asserts that Muse’s conversations and virtual machine data are not shared with advertising platforms. Nevertheless, Meta acknowledged in a September architecture update that it retains access to this data for service support, protection, and maintenance.

On October 2, 2026, Apple announced tighter restrictions on Full Disk Access for macOS apps, limiting file access unless explicitly authorized by the user. At WWDC26, Apple detailed methods to remove personal information before data is sent to AI models and to control high-risk tasks initiated by AI. Carissa Velez noted,

"We provide AI systems with far more personal information about ourselves than we receive from them."

Security researcher Patrick Wardle added,

"We can manipulate the agent and exploit its privileges to perform virtually any action."

Apple also cautioned that as AI agents become increasingly capable and autonomous, the risks associated with their extensive access will grow significantly.

This situation underscores the crucial need for stringent oversight of personal data and access restrictions amid rapid AI advancements. Vulnerabilities in platforms like Muse threaten not only individual privacy but also broader digital security. Apple’s proactive measures highlight the urgent demand for robust regulation and enhanced safeguards in handling personal information within emerging AI technologies.

As concerns about data security escalate, it's worth noting that Meta has recently restricted Muse's access to shopping on Amazon due to violations of service agreements. This move highlights the ongoing tension between AI capabilities and compliance with privacy standards. For more details on this development, you can read about Meta's actions regarding AI access limitations.

Advertisement

Read also

Advertisement

Advertisement

Advertisement