
Apple’s Full Disk Access Problem Is Bigger Than Meta’s Muse
The permission screen is where my excitement about desktop AI agents hits the brakes. Let an assistant organize a project folder? Excellent. Give it broad access to messages, email, and browsing history because it wants to be “helpful”? Suddenly, the demo feels less like a productivity breakthrough and more like handing a stranger my unlocked laptop.
I want these tools to work. That’s precisely why Apple’s move interests me: useful autonomy needs boundaries stronger than a chatbot’s promise to behave.
The backup-app exception meets the eager assistant
On October 2, 2026, Apple [announced forthcoming changes to Full Disk Access](https://developer.apple.com/news/?id=p6zjojqw), explicitly connecting the risks of broad data access to increasingly autonomous AI agents.
<> Apple says the additional controls will require “very explicit user action” before an app receives Full Disk Access./>
This is an announcement, not a shipped fix. Apple has not specified a release date, affected macOS versions, or interface details; it has also announced no per-conversation permissions, expiring grants, or separate read/write controls.
Full Disk Access exists for good reasons. Backup software needs to reach protected data. Endpoint-security products do too: Palo Alto Networks documents the permission as necessary for full Cortex XDR protection on Macs following changes introduced in macOS 10.15.
But an agent is a different customer for that privilege. A backup app copies data according to a defined workflow. An assistant can interpret it, combine it, and proactively surface something you never asked about.
Same access. Very different consequences.
Muse, Messages, and the missing forensic story
The controversy centers on Meta’s Muse agent. On September 19, Inc. columnist Jason Aten reported that Muse suggested a column using a private conversation with his podcast co-host and referenced a message from his editor. Aten said he had refused Messages access.
He also reported synchronization of his local Messages database up to row 187,462, with Full Disk Access appearing disabled. That identifier is not a count of messages read or uploaded.
On September 30, Meta communications chief Andy Stone disputed the allegation, saying both macOS Full Disk Access and Muse’s Messages connector must be enabled. Meta executive David Singleton also rejected the agent’s explanation that it had obtained information from notification banners.
The access path and permission state at the relevant time remain unresolved; the reporting establishes no independently verified macOS bypass. Apple’s notice does not name Meta.
Still, the product-design problem is clear: technical authorization is not the same as task-specific intent. “You can access this” does not mean “please mine it for unsolicited suggestions.” Your correspondents never clicked that permission button either.
Build the boundary outside the model
My objection isn’t that agents should never touch personal data. It’s that blanket access is a lousy default for narrowly defined tasks.
Developers already have better building blocks:
- Start with selected files or folders. macOS App Sandbox supports open/save panels and security-scoped bookmarks, including persistent read-only access.
- Make refusal a working state. Denied access should reduce functionality gracefully, not trigger an onboarding hostage situation.
- Explain both permission layers. An app’s connector toggle and macOS authorization are separate controls.
- Enforce access outside the LLM. Use narrowly authorized tools and auditable operations, rather than asking the model whether its next action feels permissible.
That last point deserves emphasis. In their July 15, 2026 preprint, [Alexandra E. Michael and Franziska Roesner](https://arxiv.org/abs/2607.13718) examined 21 proposed permission systems and five commercial agents, identifying tensions between understandable interfaces, user burden, and deterministic enforcement. More prompts alone aren’t the answer. Permission fatigue is real; clicking “Allow” should not become muscle memory.
I expect desktop agents to compete increasingly on legible restraint: showing what they accessed, why they accessed it, and which authorization allowed it. Apple’s extra friction will push vendors toward narrower workflows, but the exciting breakthrough will come from agents that accomplish useful work without demanding the keys to everything. The best assistant won’t be the one that knows the most about you. It’ll be the one you can trust with exactly enough.

