On Friday Apple published four paragraphs about Full Disk Access, the macOS permission that lets an app read everything on your machine. It said it will add controls so that granting it takes “very explicit user action,” and that the stakes rise because “AI agents become increasingly capable and autonomous.” It named no macOS version, no date, no mechanism and no narrower alternative. The post, on Apple’s developer news page, is a statement of intent.
My read: Apple has found the right problem and aimed at the wrong checkbox. Full Disk Access is a master key that exists because the Mac had no better way to let a backup app work. Agents are now using that master key for jobs that need one narrow door, and tightening the key does not create the door. Whether it even addresses the incident that prompted the post is an open question.
A permission built for backup software
Apple’s own explanation is candid. Full Disk Access, the post says, “largely sidesteps” the privacy controls Apple builds into its APIs “in order to allow backup apps to function properly on the Mac.” That is a design from a different era: one grant, everything underneath, for a category of app that needs to copy every file and has no reason to interpret any of them.
Apple’s platform security guide describes the layers above it. Consent is required for files in Documents, Downloads, Desktop, iCloud Drive and network volumes, and the guide says “users should have full transparency, consent, and control over what apps are doing with their data.” The user-facing page for that layer, Control access to files and folders, covers the Desktop, Downloads and Documents folders and does not mention Full Disk Access at all. Apple’s new post says that the data Full Disk Access exposes includes “files, mail, messages, and even browsing history.”
Put those together and the gap is visible. An agent that wants to read your texts to draft a reply has no scoped permission to ask for in anything Apple has published. Nothing in those two pages offers one, which is an inference from absence and not a statement from Apple, but it fits how the post is written. The scoped doors cover folders. The data people actually worry about sits behind the master key. So agent builders reach for the master key, and Apple is now saying that was never what it was for.
The existing bar is also not low. The same guide says Full Disk Access apps “need to be explicitly added in System Settings,” and its table shows the user is not prompted by the app but must edit the privacy settings personally. That is already a deliberate, manual step, which makes the promise of “very explicit user action” hard to read. Either Apple means something harder than a trip to System Settings, or it means a warning on top of the same trip. The post does not say, and the difference decides whether this is a real control or a larger dialog.
The incident, and the part nobody has settled
The trigger was a column by Inc.’s Jason Aten about Meta’s Muse agent, which launched on September 8 and had passed 2.5 million downloads by September 23, according to Decrypt’s follow-up. Aten declined to give Muse access to Messages during setup. Days later, per Decrypt’s first report, Muse was pitching him column ideas built from texts with his podcast co-host and a note from his editor. When he asked how it knew, Muse said: “It’s the incoming notification stream only, not access to your texts.” Aten reports it had in fact synced his Messages database, to row 187,462.
Two facts matter more than the number. The first is that Meta’s own executive David Singleton acknowledged the notification explanation was incorrect. The agent’s account of its own behavior was wrong, which is a useful reminder that an agent’s self-report is not an audit log. The second is the dispute over Full Disk Access. Aten says it was off on his Mac mini; AppleInsider quotes him saying it “was not enabled,” and AI Weekly adds that Messages access nevertheless showed as enabled inside Muse’s own settings pane. Meta’s Andy Stone says reading Messages requires both Full Disk Access and the Messages connector, and Singleton says it takes three separate steps and that macOS protections prevent a bypass even if Muse has a bug. Meta says the scenario should not be possible. Aten says it happened. Nobody has published the evidence that settles it, and Apple’s post does not mention Muse.

That is worth sitting with, because the two possibilities lead to opposite conclusions about Apple’s fix.
If Aten is right and Full Disk Access was off, then a tightened Full Disk Access prevents nothing. Something moved a Messages database off a Mac without the permission Apple’s own guide treats as the gate, and the problem is either in macOS or in how Muse reached the data some other way. Apple would be announcing a fix to a door the data did not leave through. If Meta is right and the permission was on, the control did what it was designed to do. The failure sat in Muse’s own consent layer, which showed Messages as enabled for a user who says he refused it, and Apple cannot see or audit that layer from the operating system. “Very explicit user action” would then add friction to a click the user was already led to make. In neither case does a harder checkbox obviously close the gap.
Who writes the rules
I do not think the post is wrong to exist. John Gruber’s reaction is the fair version of the case for Apple: “A lot of non-technical Mac users do not understand this and cannot be expected to understand this.” People who learned permissions on the iPhone, where apps are sandboxed, hand a Mac app Full Disk Access believing the same walls still stand. They don’t. An agent that reads everything is a worse outcome than a backup tool that does, because the agent decides what to do with it.
Gruber’s worry is the other half. He writes, “I really worry about just how much Apple is going to lock Full Disk Access down,” and the concern is the one a builder should share: a master key that asks for repeated manual authorization breaks the legitimate uses that exist today, and Apple’s post gives no reason to expect it will leave room for them. Four paragraphs commit to nothing, which also means they promise nothing to the developers who depend on the permission. Gruber’s own hope is a middle path that preserves a route for knowledgeable users. He says he is skeptical it will be built.
The week’s other platform decision points the same way. Amazon blocked Muse from shopping on Amazon.com, citing, per The Neuron, that Meta did not get permission, that the agent does not identify itself while browsing, and that it handles customer credentials in ways Amazon considers a security risk. Meta says Muse runs in a dedicated secure virtual machine and asks approval before sensitive actions. Shopify’s Tobi Lütke announced a Muse integration with Shop Pay the same week. Two platform owners, two decrees, one agent, and nothing resembling a shared standard. Each owner is deciding on its own what an agent may touch, and each decision is also a decision about who gets to build one.

That is the real shape of what Apple announced. A rule written by the owner of the operating system is legitimate, and a rule that arrives as four paragraphs with no mechanism is also a rule nobody can build against. The sharper version is that Apple controls both the master key and the narrow doors, and so far it has only talked about the key.
What would actually fix it
The fix that would work is the unglamorous one. Agents need grants that match the job: read this conversation, read the last thirty days, never read anything from these contacts. They need the grant tied to an agent identity the OS can name, so that “what did this app read” has an answer that does not come from the app. Amazon’s complaint that Muse does not identify itself while browsing is the web-side version of the same missing piece. Apple’s post says the right thing about informed consent and then proposes more friction for the all-or-nothing option, when the better move is to make the all-or-nothing option unnecessary.
My bet is that Apple ships a harder prompt first, because a prompt is quick, and that the scoped permissions come later or not at all. If that happens, Full Disk Access gets a scarier dialog, the legitimate backup tools absorb the cost, and agents that want your messages keep needing the master key, with one more click between you and it. Whether the click meaningfully changes who ends up reading your texts is the thing Meta and Aten still disagree about. Apple has not yet said which of them it believes.

AI-generated editorial illustration · TemperatureZero · October 3, 2026
Keep reading the signal
Get the Daily Signal — a concise briefing on what actually matters in AI and the systems around it.
Subscribe FreeContinue the archive