A Privacy Incident That Caught Apple’s Attention
Apple announced Friday that it is changing how macOS handles full-disk access permissions, a direct response to third-party AI agents exploiting a system-level setting to reach data most users assumed was private. The move follows a wave of public backlash that began when tech columnist Jason Aten disclosed that Meta’s general-purpose AI agent, Muse, sent him a notification referencing a private conversation he had with a co-worker over Apple Messages.
Aten said he never deliberately gave Muse permission to read his messages. He had assumed they were off-limits. That assumption turned out to be wrong – and the fallout from his disclosure has now pushed Apple to intervene at the operating system level.

What Muse Actually Did, and How It Got In
Meta CTO David Singleton stepped in two weeks after Aten’s account went viral, offering a rebuttal that framed the situation as a user-consent issue rather than a data breach. His argument: accessing Apple Messages through Muse requires two separate, manual steps from the user. The first is granting full-disk access, a macOS permission that sits at the system level and covers far more than just messages. The second is enabling a Messages connector setting directly inside the Muse app itself.
Singleton’s position was that both steps require deliberate action, making the permissions opt-in by design. That argument has some technical merit. Full-disk access is not granted automatically – macOS prompts users before any app can acquire it. But critics pointed out that the permission’s name gives little indication that it opens the door to message history, calendar data, emails, or anything else an AI agent might want to ingest. A user agreeing to full-disk access for one purpose has no reason to assume it hands over their private correspondence as a side effect.
The broader problem is structural. Full-disk access was built long before AI agents existed as a product category. It was designed to give backup tools, antivirus software, and similar utilities the broad read access they need to do their jobs. When that same permission applies to a general-purpose AI assistant that can act on data, summarize it, and surface it in notifications, the original intent of the permission breaks down entirely.
Apple’s Friday announcement targets exactly that gap. By adjusting how macOS handles full-disk access in the context of third-party applications, Apple is drawing a harder line between what an app is allowed to see and what a user has explicitly chosen to share. The company has not yet published a full technical breakdown of the change, but the direction is clear: message histories are being carved out of what full-disk access can reach.

The Social Media Reaction That Made This Move Inevitable
Last week’s social media response to the Muse incident was large enough that Apple could not reasonably ignore it. The consensus that formed was blunt: AI assistants with access to calendars, emails, messages, shopping accounts, and other connected services carry real risk when permissions are unclear or when users underestimate what they have agreed to share.
The comparison that circulated widely was to a skill saw. The tool is useful, but it causes serious damage when handled without full awareness of what it does. That framing – AI agents as power tools that most people are operating without proper understanding – stuck, and it put pressure on both Meta and Apple to respond with something more than a clarification blog post.
What Changes for Mac Users Going Forward
Apple’s intervention means that developers building AI agents for macOS will face tighter constraints on what data they can access through system-level permissions. The specific mechanics of the new restrictions are still being detailed, but the intent is to prevent full-disk access from functioning as a skeleton key that unlocks personal message archives as a side effect of broader system permissions.
For users who already have Muse installed and have granted it full-disk access, it is worth revisiting the permissions panel in System Settings. Full-disk access can be revoked for individual applications, and the Messages connector setting inside Muse can be disabled independently. Both steps are reversible, but neither happens automatically – Apple’s upcoming changes will affect new permission grants rather than retroactively adjusting what existing installations can already reach.
The question now sitting with developers is where Apple draws the next line. AI agents derive most of their value from contextual awareness – knowing who you talk to, what appointments you have, what you recently purchased. Restricting data access makes agents less capable. Apple has to weigh that against the cost of users discovering, after the fact, that a notification from an AI assistant is referencing a private conversation they never consciously chose to share. Aten’s experience with Muse suggests that cost can arrive without warning.

The two weeks between Aten’s original account and Apple’s Friday announcement is the relevant detail here. A single viral incident involving AI acting on data it should not have seen moved one of the most controlled hardware and software ecosystems in the consumer market to rewrite its permission architecture. That speed either reflects how seriously Apple took the backlash, or how quietly embarrassing it was to have a Meta product doing something inside macOS that Apple’s own privacy messaging says should not be possible.






