Handing an app full disk access on macOS is like giving your neighbor a key so they can water the plants while you’re away. You assume they’ll go to the windowsill. You don’t expect them to read your mail, flip through the shoebox of old letters in the closet, and then mention something from it at dinner.
That’s roughly what happened. A tech columnist reported that Meta’s Muse AI agent surfaced content from a private Apple Messages thread he never authorized it to read. Apple’s response, posted to its developer site on October 2, 2026, was a note titled “Updates to Full Disk Access in macOS” promising additional controls to make sure users who grant that level of access actually mean to.
The permission was built for a different era
Full disk access has always been a blunt instrument. It’s one toggle, and flipping it hands an app the keys to message databases, mail stores, browser history, and whatever else lives in the protected corners of your home directory. There’s no granularity. You can’t say “yes to my Downloads folder, no to my texts.”
That worked, more or less, because of who was asking. Backup utilities. Antivirus scanners. Disk cleaners. Tools that needed to see everything by definition, made by companies with reputations to protect and no particular interest in the contents of your group chats. The permission model relied on an unspoken assumption: apps that read everything don’t do anything with what they read beyond their stated job.
AI agents break that assumption in a specific way. An agent’s entire purpose is to read, interpret, and then say something about what it found. The gap between “has access to data” and “actively mining data for conversational material” collapses to zero. The same toggle that let CleanMyMac count your duplicate files now lets a language model build a profile of your private conversations and bring it up unprompted.
Meta says it was opt-in. The user says otherwise.
Meta’s position, per Ars Technica’s reporting, is that Messages reading in the Muse Mac app is opt-in and that the agent can only read what the user allowed. I don’t doubt that a consent screen exists somewhere in that flow. I also don’t doubt the columnist’s account that he had no idea it was happening.
Both can be true, and that’s the actual problem. Consent that technically happened but wasn’t understood isn’t consent in any sense that matters to the person whose texts got read. If your disclosure is buried in an onboarding step that users tap through to get to the feature they came for, you’ve secured legal cover and nothing else.
What a real consent moment looks like
This is where Apple’s change could actually matter, depending on how it ships. The useful version includes:
- Separating “read your files” from “read your messages and mail” so users can grant one without the other
- Showing the request at the moment the agent wants the data, not during install when nobody is paying attention
- Ongoing visibility into what an agent has read, rather than a one-time approval that never expires
- Naming the specific data stores in plain language instead of saying “full disk access”
Apple’s developer note doesn’t commit to all of that. It says new controls are coming to ensure users genuinely intend to grant access. That could mean a scarier dialog box. It could mean real scoping. The distinction is the whole story, and we don’t have it yet.
Why this lands on agnthq’s radar
I test agents for a living, and the pattern I keep hitting is the same: the tool asks for broad system access early, justifies it with capability, and then the capability expands without the permission being revisited. You approved an assistant that could search your files. Six updates later it’s an assistant that reads your correspondence and forms opinions about your relationships.
Nobody lied to you. The permission just kept meaning more than it did when you granted it. And unlike a cloud service, a local agent with disk access isn’t bounded by what you chose to upload. It’s bounded by what’s on your machine, which is everything.
Apple tightening this is the correct move and an overdue one. It’s also a reminder that platform-level permissions are the only real check here. Agent developers compete on capability, and capability means access. Asking them to voluntarily want less of your data is asking them to ship a worse product than their competitor. That’s not a fight self-regulation wins.
If you’re running AI agents on a Mac right now, go open System Settings, find the full disk access list, and look at what’s in there. I’d guess at least one entry surprises you. Until Apple’s new controls actually land, that list is the only consent record you’ve got, and the only one you can do anything about.
🕒 Published: