Apple said on October 2, 2026 that it will change macOS so that AI agents asking for full data access are easier to spot and harder to approve by accident. The announcement followed an accusation that Meta's Muse read private messages on a Mac without the user having enabled Full Disk Access.
The facts of that accusation are disputed. Apple's response is not, and it affects every AI agent that runs on a Mac.
TL;DR — what people are asking
| Question | Answer |
|---|---|
| What did Apple say? | It will add controls so granting an app full data access requires very explicit user action, and make agent requests more obvious |
| When? | No version or date given in the reporting |
| What triggered it? | Inc columnist Jason Aten's claim that Muse read his Mac Messages |
| What is the claim? | Muse read private messages although he had not enabled Full Disk Access; coverage cites 187,000+ rows synced |
| What does Meta say? | Both Full Disk Access and the Messages connector must be enabled; access is strictly opt-in |
| Is it resolved? | No. The dispute is open and no independent technical finding is public in the sources I reviewed |
| What should I do? | Audit Full Disk Access today (steps below) |
What is established
Three things are on the record:
- The accusation. Jason Aten of Inc magazine said Muse accessed private messages on his Mac and that he had not turned on Full Disk Access. Tom's Hardware and AppleInsider reported the claim, and one write-up described the agent referring to confidential messages it had not been granted access to.
- Meta's response. Spokesperson Andy Stone said you must enable both Full Disk Access and the Messages connector for Muse to read Messages, and that the setting can be revoked at any time. Another outlet reported Meta saying users have to opt in three separate times, once through a macOS settings screen apps cannot set on their own.
- Apple's response. Reported by Reuters, Apple said it will modify macOS to make it more obvious when AI agents request full data access and add controls so that only very explicit user action can grant it. Apple also said, "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
What is disputed
Whether Muse read the messages without permission is the live disagreement. Aten says he had not enabled Full Disk Access. Meta says the access cannot happen without it. The two statements cannot both describe the same machine unless something else explains the data — a prior grant that was forgotten, a different permission path, a bug, or a misreading of what synced.
There is also a number in play. Reports cite more than 187,000 rows synced from the local Messages database, and Meta has been quoted denying that Muse read 187,000 messages. A row in a database is not the same as a message read by a model, so the figure should not be repeated as "187,000 messages read."
I did not find an independent forensic analysis in the sources reviewed. Until one appears, the responsible reading is that a serious claim was made, a specific rebuttal was offered, and Apple judged the underlying permission model worth changing.
Why Full Disk Access is the pressure point
On macOS, Full Disk Access is the permission that lets an app read data across your whole account — Messages, Mail, Safari history, and files from other apps. It exists for legitimate tools such as backup software. Apple's mobile systems sandbox apps from one another by default; the Mac is more permissive, and some developers have been using Full Disk Access in ways that carry risk.
For an AI agent the permission is especially potent. A conventional app that holds Full Disk Access reads what it was written to read. An agent decides at run time what to read, based on a prompt that may itself be manipulated. That combination is why Apple's quote focuses on autonomy.
This is the same class of problem we covered when OpenAI shipped Mac integrations — see ChatGPT's Apple Messages integration on Mac — and when we assessed whether Meta Muse is safe after its launch. The permission model has been the weak point in both.
Do a five-minute Mac audit
You do not need to wait for Apple's change. Here is what to check today.
- Full Disk Access. System Settings → Privacy & Security → Full Disk Access. Review every app with the toggle on. Turn off anything you do not recognize or have not used in a month.
- Files and Folders. In the same Privacy & Security area, check which apps can reach Desktop, Documents, Downloads and network volumes.
- Automation. Review which apps can control other apps. An agent with automation rights can drive Mail or Messages without Full Disk Access.
- Accessibility and Screen Recording. Agents that operate your screen need these. Remove any you do not actively use.
- Connectors inside the app. Muse and similar agents have their own in-app connectors for Messages, Mail and Calendar. Check those too; the macOS toggle is only one of the gates.
- Where the Messages database lives. Your iMessage history is stored in a local database in your Library folder. Any process with Full Disk Access can read that file, which is why the permission is sensitive.
If you run coding agents or desktop automation, the same audit applies. Our shadow AI privacy risk guide covers how to inventory what has access to what at a team level.
What this means for people building agents
If you ship an agent for macOS, the direction of travel is clear:
- Ask for the narrowest permission. Prefer scoped access to a specific folder or API over Full Disk Access.
- Make requests legible. Apple's change aims to make agent access requests more obvious. Design your onboarding so that a user can see why you need access and what you will read.
- Keep an access log. If a user asks "what did you read?" you should be able to answer. A simple per-run record of files and databases touched settles most disputes.
- Assume the dispute will be about evidence. The Muse case turns on what happened on one machine, which nobody can reconstruct without logs.
For the local-first alternative, Underdog's on-device personal AI takes the opposite architecture: models run on the Mac, and the vendor argues content never goes to a cloud service. That reduces one risk — remote processing — but not the local-permissions question, which still needs careful scoping.
How this fits the Muse story so far
Muse has had a fast run: it hit the top of the App Store (Muse number one on the App Store), launched with a hosted-agent security model (Muse and Sentinel VM), and then drew a wave of privacy questions. This week's developments also include Meta's Gadgets SDK and Home Link devices. The throughline is a consumer agent that wants broad access, and a platform owner — Apple — deciding the access model needs to be stricter.
What people are asking
Did Muse actually read people's iMessages?
That is the disputed question. The accusation is serious and specific; Meta's rebuttal is also specific. No independent technical finding was available in the sources I reviewed.
Will Apple's change break my existing agents?
Apple has not published a version, a date or a technical description. Expect developers to get documentation first. Agents that already use narrow permissions should be least affected.
Is Full Disk Access ever necessary?
For backup tools and some system utilities, yes. For most agents, a narrower grant would do. If an agent asks for Full Disk Access on first launch with no explanation, that is a reason to pause.
Does this apply to iPhone?
The reporting frames the problem as a Mac issue, since iPhone and iPad apps are sandboxed from one another by default. The accusation concerned a Mac app.
Should I uninstall Muse?
That is your call. A reasonable middle path is to check that Full Disk Access and the Messages connector are off for it, and re-enable only if you want that feature.
Honest limitations
- The central accusation is unresolved, and I have not independently reproduced it.
- Apple's change has no published date or version in the reporting I reviewed.
- Row counts and message counts are not interchangeable; do not quote them as such.
- The audit steps use current macOS Settings wording, which can vary by version.
Bottom line
Apple will make Full Disk Access harder to grant to AI agents, after a dispute about whether Meta's Muse read a user's Messages without it. Whatever the facts turn out to be, the lesson holds: audit what has access to your Mac now, and ship agents that ask for the least they need.
Related on explainx.ai
- Is Meta Muse safe? A verdict
- Meta Muse launch and Sentinel VM security
- Meta Muse hits number one on the App Store
- Muse Gadgets SDK and Home Link
- ChatGPT Apple Messages integration on Mac
- Underdog: private personal AI on your Mac
- Shadow AI workplace privacy risk guide
- OpenAI Dots always-on agents
Reporting reflects Reuters, Tom's Hardware, AppleInsider and other coverage as of October 3, 2026. Apple has not published implementation details.
