As artificial intelligence agents grow capable of acting across the full breadth of a person's digital life, the question of what they may quietly read has become urgent. Apple's announcement that it will redesign how Macs handle AI requests for broad data access reflects a deeper reckoning: that consent, to be meaningful, must be understood — not merely clicked through. The dispute, sparked by complaints about Meta's Muse AI reading private messages, reveals how the architecture of permission can outpace the awareness of those granting it.
Apple to Tighten Mac Data Access Controls After Meta's Muse Privacy Concerns
Users clearly understand these risks before granting such access
So what exactly is Meta's Muse doing that upset people?
It's an AI agent that can do things like cancel subscriptions or negotiate better prices on services. But some users said it was reading their private messages without them realizing it.
Did it actually read their messages without permission, or did they grant permission and forget?
That's the contested part. A tech columnist said it happened without him enabling Full Disk Access. Meta says you need to enable both Full Disk Access and a separate Messages connector.
What's the difference between a Mac and an iPhone here?
iPhones sandbox apps—one app can't access another app's data by default. Macs let you grant Full Disk Access, which lets an app see everything.
So the permission system exists. The question is whether users understand what they're clicking.
Exactly. Apple is saying the current warning isn't explicit enough, especially as AI agents get more autonomous.
What's Apple actually changing?
They're adding controls to make it much harder to grant Full Disk Access without really deliberate action. They want users to understand the stakes before they say yes.
But we don't know yet what those controls look like or how much they'll actually change user behavior.
True. Apple just said they're coming. No timeline, no specifics.
Does this solve the Muse problem?
It might prevent similar situations, but it doesn't resolve whether Aten's claim was accurate in the first place.
Le Pouls
- Meta's Muse AI agent drew sharp criticism after users reported it accessed their private messages without their clear awareness, igniting a public debate about what 'opt-in' truly means.
- The tension exposes a longstanding gap between Apple's iPhone and Mac security models — iPhones sandbox apps tightly, while Macs offer a sweeping 'Full Disk Access' setting that some developers have exploited.
- Meta pushed back firmly, insisting Muse cannot read messages unless users deliberately enable both Full Disk Access and a separate Messages connector — but critics argue the layered permissions obscure the real stakes.
- Apple acknowledged that some developers are leveraging Full Disk Access in ways that put users at risk, signaling that the current system fails to make the consequences of granting such access genuinely clear.
- Apple is now moving toward stricter, more deliberate consent mechanisms — requiring unmistakable user action before any AI agent can reach into the full contents of a Mac.
As artificial intelligence agents grow capable of acting across the full breadth of a person's digital life, the question of what they may quietly read has become urgent. Apple's announcement that it will redesign how Macs handle AI requests for broad data access reflects a deeper reckoning: that consent, to be meaningful, must be understood — not merely clicked through. The dispute, sparked by complaints about Meta's Muse AI reading private messages, reveals how the architecture of permission can outpace the awareness of those granting it.
Apple announced Friday that it will overhaul how its Mac operating system handles requests from AI agents seeking access to all data on a user's machine. The decision follows a wave of complaints centered on Meta's Muse, an AI assistant built to perform complex tasks — canceling subscriptions, negotiating service rates — that users say read their private messages without their knowledge.
The controversy exposed a long-standing difference between Apple's mobile and desktop platforms. iPhones use sandboxing to keep apps isolated from one another's data. Macs offer a broader setting called Full Disk Access, which grants applications like backup services the ability to read everything stored on the device. Apple now says some developers have been using this feature in ways that expose users to unintended risk.
Meta's Muse became the focal point of the dispute when technology columnist Jason Aten wrote that the AI had read his private messages — without, he said, ever having enabled Full Disk Access. Meta spokesperson Andy Stone responded publicly that Muse requires users to enable both Full Disk Access and a dedicated Messages connector before it can access messages at all, and that the permission can be revoked at any time.
Apple's statement framed the issue as one that will only grow more pressing as AI systems become more autonomous. The company said it would introduce new controls requiring users to take deliberate, unmistakable action before granting any application this level of reach. The underlying tension — between the genuine usefulness of AI agents that can act across a person's digital life and the risk that broad permissions are granted without full understanding — is precisely what Apple says the current system fails to resolve.
Apple announced Friday that it will redesign how its Mac operating system alerts users when artificial intelligence agents request access to all data stored on their machines. The move follows a wave of complaints about Meta's Muse, an AI assistant designed to handle complex tasks—canceling subscriptions, negotiating better rates on services—that users say accessed their private messages without their clear knowledge or consent.
The distinction between Apple's phone and computer platforms has long been a source of tension. iPhones and iPads use sandboxing, a security architecture that prevents any single app from accessing data stored inside another app without explicit permission. Macs work differently. They offer a "Full Disk Access" setting that, when enabled, allows applications like cloud backup services to read everything on the machine. Users can grant this permission, but Apple now says some developers have been leveraging it in ways that expose people to risk.
Meta's Muse became the flashpoint for this debate. Technology columnist Jason Aten, writing for Inc magazine, claimed the AI agent read his private messages on his Mac—and said he had never activated Full Disk Access. Meta's response, delivered by spokesperson Andy Stone on social media, was direct: accessing Messages through Muse requires users to enable both Full Disk Access and a separate Messages connector. "It can't read your Messages unless you do this," Stone wrote. "And it can be revoked at any time."
Apple's statement, released Friday, framed the problem in broader terms. "Some developers are using the Full Disk Access feature in ways that could put users at risk," the company wrote. The company acknowledged that as AI systems become more capable and autonomous, the dangers multiply. Apple said it would introduce additional controls requiring users to take deliberate, unmistakable action before granting any app this level of access. The company emphasized that users needed to understand what they were permitting before making the choice.
Neither Apple nor Meta offered further comment beyond these initial statements. The dispute sits at the intersection of two competing pressures: the genuine utility of AI agents that can perform tasks across a user's digital life, and the legitimate concern that broad data access—even when technically opt-in—can happen without users fully grasping what they've authorized. Apple's move suggests the company believes the current system does not make those stakes clear enough.
Citations marquantes
You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can't read your Messages unless you do this.— Meta spokesperson Andy Stone
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.— Apple