Insights

Apple Just Told Every AI Agent Maker: Full Disk Access Is Over

· Insights

After a Meta agent read a columnist's Messages, Apple is changing macOS Full Disk Access — and admitting agent-era risks grow 'substantially'.

Apple Just Told Every AI Agent Maker: Full Disk Access Is Over

Last updated: October 4, 2026 · 5-minute read

The most important AI-agent policy statement of the month did not come from an AI company. It came from Apple, in a statement about a macOS permissions dialog. Apple confirmed it is changing Full Disk Access — the system-level macOS permission — because "some developers are using Full Disk Access in ways that could put users at risk", and because, in the company's own words, "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially". The release notes show a security model catching up to agents. The backstory shows why it took a scandal to get here.

How a single notification triggered a platform change

The sequence, as reported by Ars Technica's Dan Goodin: two weeks before Apple's announcement, tech columnist Jason Aten wrote that Meta's new general-purpose agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker in Apple Messages. Aten said he never granted Muse access to his messages. Social media did what social media does — and the episode became the first mainstream test of a question every agent company has been quietly deferring: what exactly does an agent see, and who audits the answer?

Meta's rebuttal, from CTO David Singleton, was technically precise: "The Messages integration in the Muse Mac app is opt in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." The implication — the user enabled it, therefore the user is responsible. The rebuttal collapsed under one technical fact. As macOS security researcher Patrick Wardle put it: "with FDA, any (non-root file) is readable, browsing history, browser cookies, chats, etc etc etc." An app holding Full Disk Access does not need a connector to read a Messages database on disk — the connector is a UI story, not a security boundary. Wardle had, days earlier, also disclosed a Muse configuration flaw that let any app on a Mac — including code injected through ClickFix social-engineering attacks — take control of the assistant.

Apple's statement never names Meta or Muse. It does not need to. The timing — 11 days after Wardle's disclosure, on the heels of the uproar — and the specific language about "files, mail, messages, and even browsing history" make the referent clear. Which suggests the platform owner concluded the honest answer to "could the agent read messages" was the one Meta's PR did not give.

Why Full Disk Access was a time bomb

Full Disk Access predates the agent era. It was designed for backup tools, antivirus, disk utilities — software with a clear job and a human-sized scope. Agents broke the assumption. An agent's whole pitch is broad context: your calendar, your mail, your files, your messages, so it can act on your behalf. Handing that to an app with FDA grants a single toggle for everything, and the OS cannot tell "assistant reading today's schedule" from "app scraping a decade of chat logs".

The failure is not that Meta did something the OS forbade. The failure is that the OS permitted so much that the question "did the agent read my messages" had no verifiable answer. When a permission's audit trail cannot settle a public dispute between a columnist and a trillion-dollar company, the permission is the problem.

What good looks like instead

The fix Apple is making points where agent permissions have to go: narrow, per-resource grants with visible traces. An agent that needs today's calendar should hold a calendar-scoped grant, not a disk-wide one. Reading messages should be an event the Messages app mediates and logs, not a file the agent opens directly. And every access should land in a reviewable trail the user can actually read — the same instinct behind the approval gates OpenAI describes for its Dots agents, and behind the local-first argument that the only safe data access is the one that never leaves the machine.

For developers shipping agents today, the practical guidance is uncomfortable but simple: do not design around FDA. Build the narrowest integration you can, make every access explicit and revocable, and assume the platform vendors will keep taking broad permissions away from under you — because Apple just said, on the record, that they will.

The timeline, compressed

One paragraph of receipt-keeping, because the sequence is the story. A columnist publishes what a Meta agent showed him from his Messages. Meta's CTO responds that two explicit settings were required. A security researcher points out the first setting alone exposes every non-root file on the disk — and separately discloses that a Muse configuration flaw could hand control of the assistant to any local app, including ones planted by ClickFix social engineering. Eleven days later, Apple announces it is changing the underlying permission, with language about agents whose risks "will grow substantially", naming no one. If you want a case study in how platform security actually gets made — incident, rebuttal, researcher receipts, platform response — this sequence is the cleanest one the agent era has produced so far.

The take

The Muse episode will be remembered as a trivium about one notification. The better reading: it is the first documented case of the agent-era permission crisis, caught before it became a breach. Apple's statement contains the sentence every agent builder should tape to a monitor — risks "will grow substantially" as agents gain capability and autonomy. Platform owners have noticed. The agents that survive the coming permission tightening will be the ones designed for least privilege from day one, not the ones that apologize best after day one.

More on this site's agent coverage: what survived 90 days of production agent workflows, and the local-AI privacy argument that this whole saga quietly strengthens. Everything else lives in the blog.

---

Not affiliated with Apple, Meta or OpenAI. Sources: Ars Technica (Dan Goodin, Oct 2, 2026), Apple's public statement as quoted there, Patrick Wardle's disclosure, Meta CTO David Singleton's public response.

ansaribilal.com — technology, tested in public.