A macOS Security Overhaul Ignited by an “AI Reading My Messages” Scandal
Apple announced on Friday (October 2) that it will introduce new controls around macOS’s “Full Disk Access” permission — and the reason it named is the fast-proliferating breed of AI agents. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple wrote. This is the first time a mainstream operating system vendor has tightened system-level permissions specifically because of AI agents, marking the moment desktop AI security moved into the OS layer.
The trigger: Inc. columnist Jason Aten’s late-September claim that Meta’s AI agent Muse on his Mac appeared to know the content of his private messages — even though he insists he never granted permission. Meta strongly disputes this, saying Muse requires explicit user consent to access the Messages app. But with the controversy unresolved, Apple has already moved first.

What Is “Full Disk Access” — and Why Do AI Agents Make It Dangerous?
Full Disk Access was designed so that backup tools and disk utilities could work properly. Once enabled, an app can read a user’s files, mail, iMessages, and complete browsing history — effectively handing over the entire digital life on that machine.
Historically, the apps requesting this permission were mostly workhorse utilities. The logic of the AI-agent era is entirely different: these agents are sold precisely on “operating your computer for you” — reading your files, triaging your email, replying to your messages. To do that, they almost inevitably demand the highest tier of system permissions. Apple’s statement cut to the heart of it: “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems… without users’ full knowledge and understanding.”

The Muse Timeline: From Accusation to Denial to Apple’s Move
September 20: Jason Aten first reported that Muse seemed to know about conversations taking place in his private messages, raising questions about the privacy boundaries of AI agents.
September 30: Meta publicly pushed back, insisting that Muse accessing Messages requires two conditions — Full Disk Access enabled in System Settings and explicit approval of “Messages” inside Muse. Meta implied Aten may have misunderstood permissions he himself had granted. The he-said-she-said remains unresolved.
October 2: Apple announced the Full Disk Access crackdown. While the statement never names Meta or Muse, the timing and context point squarely at the controversy. Reuters reported that Apple plans to make it “more obvious when AI agents ask to access all of the data on Macs.”
Notably, this isn’t an isolated reaction. Apple’s decision also followed a Wired report that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. Desktop AI-agent security has escalated from isolated incidents to a systemic risk.
Apple’s Answer: “Very Explicit User Action”
According to Apple, going forward only users who “genuinely wish to grant an app this extraordinary level of access” will be able to complete the grant — and only through a “very explicit user action”. In other words, the buried, one-click-give-it-all consent flow is on its way out.
“Addressing this is critical,” Apple wrote. “We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.” The company did not share specifics on timing or technical details, and did not respond to TechCrunch’s inquiry.
The Bigger Question: Where Are the Permission Boundaries for AI Agents?
The real story here isn’t whether Muse actually read anyone’s messages — it’s the structural problem the saga exposed: when an AI agent’s selling point is “full authority to act as you,” who bears responsibility for privacy?
For Meta, Muse is the key product in its battle against OpenAI’s Dots for the “personal AI agent” market, and deep permissions are what make it powerful. For users, an AI that can read every message and file carries a far higher trust bar than a chatbot. Industry observers note that the shock over “an AI agent reading messages” partly reflects how opaque consent flows have always been — many people simply don’t remember what they agreed to.

Practical Steps for Users
Before Apple’s new controls ship, Mac users can take a few immediate steps:
- Audit existing grants: Open System Settings → Privacy & Security → Full Disk Access and review which apps hold it. Remove anything you no longer use.
- Stay alert with AI agents: Before installing any AI agent, check exactly what permission scope it requests and whether your data is processed in the cloud.
- Watch for updates: Apple’s new controls are expected to arrive with a future macOS update — pay attention to how the consent flow changes.
Conclusion: The Convenience-Privacy Balance Wobbles Again
From browser cookies to app tracking, every paradigm shift has revived the convenience-versus-privacy debate. What makes AI agents different is that they’re not asking for your location or an advertising ID — they’re asking for all of your digital life. Apple’s move reasserts the OS gatekeeper role, but the real test is whether users will hand over that master key in exchange for AI convenience.
The battle for the Mac has only just begun.




