Meta's new personal AI agent, Muse, launched to a splashy keynote at Connect 2026 — but it's also running into exactly the kind of trust problem industry watchers warned about. According to the Wall Street Journal, “Meta's AI Agent Has a Trust Problem,” and the company can “ill afford any user-privacy hiccups” given the current climate of concern around AI agents.
What Actually Went Wrong
Two separate incidents fed the backlash. First, a companion feature called Muse Image let users generate AI images of other people simply by @mentioning their public Instagram account — using those people's public profile photos without notifying them. The reaction was fast and negative enough that, per multiple reports, Meta rolled the feature back.
Second, a report published by Inc.com (titled “Meta's New Muse AI Agent Read My Private Messages. I Never Asked It To”) described the agent accessing private iMessages the user hadn't authorized it to read, sparking discussion on Reddit's r/technology about how much system-level access an agent needs to do its job.
Meta's Response — and Its History
Meta's chief AI officer Alexandr Wang told CNBC that Muse runs inside “its own isolated environment” within Meta's infrastructure, and that it “never sees your actual passwords or payment details and asks before doing anything sensitive.” Meta VP of engineering David Singleton added that the company will scrub “critical personally identifying information” before using agent conversations to improve its AI models — implying that, by default, some conversation data does feed back into model training unless a user opts out.
The skepticism isn't happening in a vacuum. As TechCrunch pointed out, Meta carries real baggage here: a 2011 FTC settlement over deceiving users about privacy, a record-breaking $5 billion FTC settlement in 2019, and a 2023 FTC charge for violating that same 2019 privacy order. For a company with that track record, a privacy misstep in its flagship new AI product lands harder than it would for a newer entrant.
What This Teaches Businesses Building Their Own AI Agents
Muse's rocky first week is a useful case study, not just a Meta story. The lesson generalizes to any business deploying an AI agent — on a website, in WhatsApp, or on a support line: users will forgive a bot for getting an answer wrong, but they will not forgive it for accessing something they didn't knowingly grant access to. Being explicit about what data an agent can see, asking before it touches anything sensitive, and giving users a real opt-out aren't nice-to-haves; they're the difference between an agent people adopt and one they actively distrust.
That's also why, when businesses evaluate an AI agent vendor, the access model matters as much as the conversational quality — a well-scoped agent that only touches what it's explicitly permitted to will earn more real usage than one that's technically more capable but vague about its own boundaries.
Frequently Asked Questions
Is Muse Image still available?
Reports indicate Meta rolled back the Muse Image feature after the backlash over generating images from other people's public photos without notifying them.
Does Muse read my private messages?
Meta has not confirmed the private-message-access incident reported by Inc.com as intended behavior; Meta's official position, per its chief AI officer, is that Muse operates in an isolated environment and asks before doing anything sensitive.
Does Meta use my Muse conversations to train its AI?
Per a Meta VP of engineering's comments to CNBC, personally identifying information is meant to be scrubbed before conversation data is used to improve Meta's AI models — suggesting some conversation data is used for training by default.
Has Meta had privacy issues before?
Yes. Meta has settled with the FTC over privacy issues multiple times, including a 2011 settlement, a record $5 billion settlement in 2019, and a 2023 charge for violating that 2019 order.