Apple Mac Privacy Lockdown: Meta’s Muse Reading iMessages Forces Tighter “Full Disk Access” Rules

  • AI
  • October 3, 2026

A macOS Security Overhaul Ignited by an “AI Reading My Messages” Scandal

Apple announced on Friday (October 2) that it will introduce new controls around macOS’s “Full Disk Access” permission — and the reason it named is the fast-proliferating breed of AI agents. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple wrote. This is the first time a mainstream operating system vendor has tightened system-level permissions specifically because of AI agents, marking the moment desktop AI security moved into the OS layer.

The trigger: Inc. columnist Jason Aten’s late-September claim that Meta’s AI agent Muse on his Mac appeared to know the content of his private messages — even though he insists he never granted permission. Meta strongly disputes this, saying Muse requires explicit user consent to access the Messages app. But with the controversy unresolved, Apple has already moved first.

MacBook Pro keyboard closeup, the device at the center of the AI agent permission controversy
macOS “Full Disk Access” lets an app read files, mail, messages and even browsing history. Source: Wikimedia Commons (CC BY-SA 3.0)

What Is “Full Disk Access” — and Why Do AI Agents Make It Dangerous?

Full Disk Access was designed so that backup tools and disk utilities could work properly. Once enabled, an app can read a user’s files, mail, iMessages, and complete browsing history — effectively handing over the entire digital life on that machine.

Historically, the apps requesting this permission were mostly workhorse utilities. The logic of the AI-agent era is entirely different: these agents are sold precisely on “operating your computer for you” — reading your files, triaging your email, replying to your messages. To do that, they almost inevitably demand the highest tier of system permissions. Apple’s statement cut to the heart of it: “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems… without users’ full knowledge and understanding.”

Circuit board macro, symbolizing system-level permissions and hardware-layer protection
AI agents need deep system permissions to “act on the user’s behalf” — which is exactly where the risk lies. Source: Wikimedia Commons (CC BY-SA 3.0)

The Muse Timeline: From Accusation to Denial to Apple’s Move

September 20: Jason Aten first reported that Muse seemed to know about conversations taking place in his private messages, raising questions about the privacy boundaries of AI agents.

September 30: Meta publicly pushed back, insisting that Muse accessing Messages requires two conditions — Full Disk Access enabled in System Settings and explicit approval of “Messages” inside Muse. Meta implied Aten may have misunderstood permissions he himself had granted. The he-said-she-said remains unresolved.

October 2: Apple announced the Full Disk Access crackdown. While the statement never names Meta or Muse, the timing and context point squarely at the controversy. Reuters reported that Apple plans to make it “more obvious when AI agents ask to access all of the data on Macs.”

Notably, this isn’t an isolated reaction. Apple’s decision also followed a Wired report that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. Desktop AI-agent security has escalated from isolated incidents to a systemic risk.

Apple’s Answer: “Very Explicit User Action”

According to Apple, going forward only users who “genuinely wish to grant an app this extraordinary level of access” will be able to complete the grant — and only through a “very explicit user action”. In other words, the buried, one-click-give-it-all consent flow is on its way out.

“Addressing this is critical,” Apple wrote. “We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.” The company did not share specifics on timing or technical details, and did not respond to TechCrunch’s inquiry.

The Bigger Question: Where Are the Permission Boundaries for AI Agents?

The real story here isn’t whether Muse actually read anyone’s messages — it’s the structural problem the saga exposed: when an AI agent’s selling point is “full authority to act as you,” who bears responsibility for privacy?

For Meta, Muse is the key product in its battle against OpenAI’s Dots for the “personal AI agent” market, and deep permissions are what make it powerful. For users, an AI that can read every message and file carries a far higher trust bar than a chatbot. Industry observers note that the shock over “an AI agent reading messages” partly reflects how opaque consent flows have always been — many people simply don’t remember what they agreed to.

Smartphone messaging app screen, AI agents reading private messages raises privacy concerns
The dispute over AI agents reading private messages has put consent transparency in the spotlight. Source: Pollinations.ai (AI-generated)

Practical Steps for Users

Before Apple’s new controls ship, Mac users can take a few immediate steps:

  • Audit existing grants: Open System Settings → Privacy & Security → Full Disk Access and review which apps hold it. Remove anything you no longer use.
  • Stay alert with AI agents: Before installing any AI agent, check exactly what permission scope it requests and whether your data is processed in the cloud.
  • Watch for updates: Apple’s new controls are expected to arrive with a future macOS update — pay attention to how the consent flow changes.

Conclusion: The Convenience-Privacy Balance Wobbles Again

From browser cookies to app tracking, every paradigm shift has revived the convenience-versus-privacy debate. What makes AI agents different is that they’re not asking for your location or an advertising ID — they’re asking for all of your digital life. Apple’s move reasserts the OS gatekeeper role, but the real test is whether users will hand over that master key in exchange for AI convenience.

The battle for the Mac has only just begun.

Related Posts

  • October 2, 2026
Google Sends TPU Chips to Space: First Step Toward Orbital AI Data Centers

Google has launched its first TPU-powered experimental satellite into low Earth orbit aboard a SpaceX rocket, testing whether AI chips can reliably compute in space. The MVP satellite carries four TPUs, runs on 1 kW of solar power in 15-minute cycles, and works alongside Gemini. It is the opening move of Project Suncatcher — Google’s plan for solar-powered orbital data centers, targeting an 80+ satellite constellation and cost parity with ground facilities by the mid-2030s.

  • October 1, 2026
OpenAI Launches Dots: Always-On AI Agents With Their Own Cloud Computer Take On Meta’s Muse

Google launches Gemini 4 Argon, its most powerful AI model yet, releasing it first to trusted cyber defenders via the Fairwind Program. With an industry-leading 1M-token output limit, frontier long-horizon reasoning, autonomous vulnerability patching, and benchmark wins across DeepSWE, Vals and AutomationBench, Argon also fires a price war at $2/M input tokens.