explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR — what people are asking
  • What is established
  • What is disputed
  • Why Full Disk Access is the pressure point
  • Do a five-minute Mac audit
  • What this means for people building agents
  • How this fits the Muse story so far
  • What people are asking
  • Honest limitations
  • Bottom line
  • Related on explainx.ai
← Back to blog

explainx / blog

Apple to Tighten Mac Full Disk Access for AI Agents After Meta Muse Messages Dispute

Apple, Meta Muse, AI Agents, Privacy, macOS

Apple says macOS will make AI agents' full-data requests harder to grant after a columnist accused Meta's Muse of reading Messages. Facts, dispute, and how to audit your Mac.

Oct 3, 2026·8 min read·Yash Thakker
add explainx.ai
go deep
Apple to Tighten Mac Full Disk Access for AI Agents After Meta Muse Messages Dispute

Apple said on October 2, 2026 that it will change macOS so that AI agents asking for full data access are easier to spot and harder to approve by accident. The announcement followed an accusation that Meta's Muse read private messages on a Mac without the user having enabled Full Disk Access.

The facts of that accusation are disputed. Apple's response is not, and it affects every AI agent that runs on a Mac.

TL;DR — what people are asking

table · 2 cols
QuestionAnswer
What did Apple say?It will add controls so granting an app full data access requires very explicit user action, and make agent requests more obvious
When?No version or date given in the reporting
What triggered it?Inc columnist Jason Aten's claim that Muse read his Mac Messages
What is the claim?Muse read private messages although he had not enabled Full Disk Access; coverage cites 187,000+ rows synced
What does Meta say?Both Full Disk Access and the Messages connector must be enabled; access is strictly opt-in
Is it resolved?No. The dispute is open and no independent technical finding is public in the sources I reviewed
What should I do?Audit Full Disk Access today (steps below)
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

What is established

Three things are on the record:

  1. The accusation. Jason Aten of Inc magazine said Muse accessed private messages on his Mac and that he had not turned on Full Disk Access. Tom's Hardware and AppleInsider reported the claim, and one write-up described the agent referring to confidential messages it had not been granted access to.
  2. Meta's response. Spokesperson Andy Stone said you must enable both Full Disk Access and the Messages connector for Muse to read Messages, and that the setting can be revoked at any time. Another outlet reported Meta saying users have to opt in three separate times, once through a macOS settings screen apps cannot set on their own.
  3. Apple's response. Reported by Reuters, Apple said it will modify macOS to make it more obvious when AI agents request full data access and add controls so that only very explicit user action can grant it. Apple also said, "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

What is disputed

Whether Muse read the messages without permission is the live disagreement. Aten says he had not enabled Full Disk Access. Meta says the access cannot happen without it. The two statements cannot both describe the same machine unless something else explains the data — a prior grant that was forgotten, a different permission path, a bug, or a misreading of what synced.

There is also a number in play. Reports cite more than 187,000 rows synced from the local Messages database, and Meta has been quoted denying that Muse read 187,000 messages. A row in a database is not the same as a message read by a model, so the figure should not be repeated as "187,000 messages read."

I did not find an independent forensic analysis in the sources reviewed. Until one appears, the responsible reading is that a serious claim was made, a specific rebuttal was offered, and Apple judged the underlying permission model worth changing.

Why Full Disk Access is the pressure point

On macOS, Full Disk Access is the permission that lets an app read data across your whole account — Messages, Mail, Safari history, and files from other apps. It exists for legitimate tools such as backup software. Apple's mobile systems sandbox apps from one another by default; the Mac is more permissive, and some developers have been using Full Disk Access in ways that carry risk.

For an AI agent the permission is especially potent. A conventional app that holds Full Disk Access reads what it was written to read. An agent decides at run time what to read, based on a prompt that may itself be manipulated. That combination is why Apple's quote focuses on autonomy.

This is the same class of problem we covered when OpenAI shipped Mac integrations — see ChatGPT's Apple Messages integration on Mac — and when we assessed whether Meta Muse is safe after its launch. The permission model has been the weak point in both.

Do a five-minute Mac audit

You do not need to wait for Apple's change. Here is what to check today.

  1. Full Disk Access. System Settings → Privacy & Security → Full Disk Access. Review every app with the toggle on. Turn off anything you do not recognize or have not used in a month.
  2. Files and Folders. In the same Privacy & Security area, check which apps can reach Desktop, Documents, Downloads and network volumes.
  3. Automation. Review which apps can control other apps. An agent with automation rights can drive Mail or Messages without Full Disk Access.
  4. Accessibility and Screen Recording. Agents that operate your screen need these. Remove any you do not actively use.
  5. Connectors inside the app. Muse and similar agents have their own in-app connectors for Messages, Mail and Calendar. Check those too; the macOS toggle is only one of the gates.
  6. Where the Messages database lives. Your iMessage history is stored in a local database in your Library folder. Any process with Full Disk Access can read that file, which is why the permission is sensitive.

If you run coding agents or desktop automation, the same audit applies. Our shadow AI privacy risk guide covers how to inventory what has access to what at a team level.

What this means for people building agents

If you ship an agent for macOS, the direction of travel is clear:

  • Ask for the narrowest permission. Prefer scoped access to a specific folder or API over Full Disk Access.
  • Make requests legible. Apple's change aims to make agent access requests more obvious. Design your onboarding so that a user can see why you need access and what you will read.
  • Keep an access log. If a user asks "what did you read?" you should be able to answer. A simple per-run record of files and databases touched settles most disputes.
  • Assume the dispute will be about evidence. The Muse case turns on what happened on one machine, which nobody can reconstruct without logs.

For the local-first alternative, Underdog's on-device personal AI takes the opposite architecture: models run on the Mac, and the vendor argues content never goes to a cloud service. That reduces one risk — remote processing — but not the local-permissions question, which still needs careful scoping.

How this fits the Muse story so far

Muse has had a fast run: it hit the top of the App Store (Muse number one on the App Store), launched with a hosted-agent security model (Muse and Sentinel VM), and then drew a wave of privacy questions. This week's developments also include Meta's Gadgets SDK and Home Link devices. The throughline is a consumer agent that wants broad access, and a platform owner — Apple — deciding the access model needs to be stricter.

What people are asking

Did Muse actually read people's iMessages?

That is the disputed question. The accusation is serious and specific; Meta's rebuttal is also specific. No independent technical finding was available in the sources I reviewed.

Will Apple's change break my existing agents?

Apple has not published a version, a date or a technical description. Expect developers to get documentation first. Agents that already use narrow permissions should be least affected.

Is Full Disk Access ever necessary?

For backup tools and some system utilities, yes. For most agents, a narrower grant would do. If an agent asks for Full Disk Access on first launch with no explanation, that is a reason to pause.

Does this apply to iPhone?

The reporting frames the problem as a Mac issue, since iPhone and iPad apps are sandboxed from one another by default. The accusation concerned a Mac app.

Should I uninstall Muse?

That is your call. A reasonable middle path is to check that Full Disk Access and the Messages connector are off for it, and re-enable only if you want that feature.

Honest limitations

  • The central accusation is unresolved, and I have not independently reproduced it.
  • Apple's change has no published date or version in the reporting I reviewed.
  • Row counts and message counts are not interchangeable; do not quote them as such.
  • The audit steps use current macOS Settings wording, which can vary by version.

Bottom line

Apple will make Full Disk Access harder to grant to AI agents, after a dispute about whether Meta's Muse read a user's Messages without it. Whatever the facts turn out to be, the lesson holds: audit what has access to your Mac now, and ship agents that ask for the least they need.

Related on explainx.ai

  • Is Meta Muse safe? A verdict
  • Meta Muse launch and Sentinel VM security
  • Meta Muse hits number one on the App Store
  • Muse Gadgets SDK and Home Link
  • ChatGPT Apple Messages integration on Mac
  • Underdog: private personal AI on your Mac
  • Shadow AI workplace privacy risk guide
  • OpenAI Dots always-on agents

Reporting reflects Reuters, Tom's Hardware, AppleInsider and other coverage as of October 3, 2026. Apple has not published implementation details.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Sep 30, 2026

Meta Muse Sent a YouTuber's Address to a Stranger

Jess Weatherbed reported on September 29, 2026 that Meta's Muse personal agent messaged a Facebook Marketplace buyer with tech YouTuber Matt Robb's pickup address, accepted a lowball offer, and only told him after the buyer had already left. This post is the incident record — what Robb authorized, what Muse admitted, and what it changes about Sentinel versus a real consent gate on contact sharing.

Sep 22, 2026

Amazon Blocks Meta's Muse From Shopping on Amazon.com

Amazon has blocked Meta's Muse personal AI agent from shopping on Amazon.com on customers' behalf, after failing to get Meta to voluntarily exclude the site. Amazon's stated reasons: Meta never disclosed that Muse would access its store, the agent doesn't identify itself while browsing, and it appears to capture and store customer credentials. Elon Musk separately noted Amazon can't actually distinguish a human buyer from an agent acting on cookies and IP alone. Here's what's confirmed, what Amazon's block actually does, and what it means for the agentic-commerce fight more broadly.

Oct 3, 2026

Cua Spaces: Cross-Computer AI Agents on Your Desktops

On October 2, 2026, Cua shipped Cua Spaces — a free, source-available macOS app for running AI agents on desktops you can watch, take over, and reach across machines you own. Here is what Spaces are, how cross-computer access works, pricing, and what to set up this week if you already run computer-use agents.