OTWopentechwire
Tech Intelligence, Openly Wired
Policy

Apple Rewrites Disk Access Rules After Meta AI Reads Private Messages

Cupertino is narrowing a system-level permission that let third-party agents silently scrape Apple Messages - a fix that arrives only after public outcry over an unsolicited notification from Meta's Muse.

HP
Hana Park
Semiconductors Reporter · Seoul
Oct 7, 2026
7 min read
Apple Rewrites Disk Access Rules After Meta AI Reads Private Messages
Credit: Aurich Lawson

A Privacy Loophole Exposed by an Unwelcome Notification

On a Friday in late September, tech columnist Jason Aten received a notification from Meta's Muse, the company's general-purpose AI agent. The message referenced a conversation he had held with a colleague over Apple Messages. Aten had not granted Muse explicit permission to read his messages, and he believed those threads were protected. The incident ignited a debate across social media about the scope of access users are inadvertently granting AI assistants, and whether existing permission models are sufficient when those assistants can scrape calendars, emails, shopping accounts, and private message histories.

Two weeks later, Apple announced it is revising the way macOS handles full-disk access permissions, specifically to prevent third-party applications from abusing the privilege to reach message histories. The change represents a rare mid-cycle tightening of a system-level permission, and it underscores the tension between the convenience of ambient AI and the opacity of consent flows in modern operating systems.

The Mechanics of the Breach

Full-disk access is a macOS permission designed for utilities that legitimately need to read across the file system: backup tools, security scanners, and forensic software. Once granted, it allows an application to bypass the usual sandboxing restrictions and read nearly any file on the machine, including databases that store Apple Messages, Mail indices, and Safari browsing history.

Meta's Muse requires two steps to access Messages. First, a user must enable full-disk access for the Muse application at the macOS system level. Second, the user must activate a Messages connector within Muse itself. Meta CTO David Singleton defended the design in a public statement, arguing that both steps require manual user action and that the company is transparent about what Muse can see once those permissions are in place.

Yet Aten's experience suggests the consent flow is less clear than Meta's engineering team intended. Many users grant full-disk access without fully understanding its breadth, particularly when an AI agent presents the request as a prerequisite for calendar or email integration. The second toggle, buried inside Muse's settings, may appear to users as an opt-in for a specific feature rather than a gate to their entire message archive.

Apple's Response and the Limits of Permission Granularity

Apple's forthcoming change will subdivide full-disk access into narrower permissions. Applications that need to read system logs or backup directories will request only those paths. Access to Messages, Mail, and Safari data will require separate, named permissions, each accompanied by a distinct dialogue box that spells out what the application intends to read.

The new permission model will debut in macOS 15.2, expected in late October. Existing applications that hold full-disk access will retain it until the user updates the app or the system prompts a re-authorisation. Apple has not yet published detailed documentation on the new permission tiers, but engineers familiar with the beta builds report that the Messages permission will be labelled explicitly and will trigger a warning if an application attempts to read the Messages database without it.

This approach mirrors the way iOS segregates access to Photos, Contacts, and Location. It also echoes the privacy controls that Android introduced in version 11, when Google split the broad "Storage" permission into narrower scopes. The difference is that macOS has historically offered fewer permission tiers, on the assumption that desktop users are more technically sophisticated. The Muse incident suggests that assumption no longer holds when AI agents are involved.

The AI Agent Dilemma

The broader question is whether permission dialogues alone can adequately govern AI agents. Unlike a traditional application, which performs a defined task when the user clicks a button, an agent operates continuously in the background, making inferences and surfacing information proactively. That behaviour is valuable when the agent reminds you of a meeting or drafts a reply based on context from your inbox. It becomes invasive when the agent reads a private message thread and uses it to generate an unsolicited notification.

At Opentechwire, we have tracked the consent models of several ambient AI platforms over the past year. Most rely on coarse-grained permissions inherited from operating systems designed in the pre-agent era. OpenAI's desktop client for ChatGPT requests screen recording access to enable visual context; Anthropic's Claude desktop app asks for Accessibility permissions to automate workflows. In each case, the permission name describes a technical capability, not the use case the agent will apply it to. A user who grants screen recording to enable a coding assistant may not realise the same permission allows the agent to capture every frame of a video call or every page of a financial document.

The solution will likely require a new permission layer that describes agent behaviours rather than file paths. Instead of "full-disk access," an agent might request "continuous access to email and messages for proactive suggestions" or "one-time access to calendar for scheduling." These descriptions would need to be enforced at the operating system level and audited regularly, not simply asserted by the application.

Meta's Defence and the Transparency Gap

Meta's rebuttal focused on the mechanics: Muse does not access Messages unless the user completes both permission steps. That claim is technically accurate, but it sidesteps the question of whether users understand what they are consenting to. The full-disk access dialogue in macOS does not enumerate the data types the requesting application intends to read. It presents a binary choice: grant access to everything, or deny the application.

In the case of Muse, the Messages connector toggle appears alongside connectors for Google Calendar, Gmail, and Slack. To a user, it may look like a list of optional integrations, each independent of the others. The interface does not make clear that the Messages connector, once enabled, will scan the entire message archive and feed it into Muse's context engine. Nor does it explain that Muse may surface that context proactively, outside the user's direct queries.

Singleton's statement included a commitment to improve the clarity of Muse's permission requests, though he did not provide a timeline or specifics. Meta has faced similar scrutiny over data access in the past, particularly around Facebook's use of contact and location permissions on mobile. The company has consistently argued that its practices are lawful and that users have control, while critics have pointed to dark patterns and consent fatigue as factors that undermine informed choice.

Implications for the Agent Ecosystem

Apple's decision to narrow full-disk access will force other AI agent developers to redesign their permission flows. Notion AI, Microsoft 365 Copilot, and Salesforce's Einstein GPT all offer desktop integrations that rely on broad file-system access to index documents and communications. Those integrations will need to request the new, granular permissions, and users will see more dialogue boxes as a result.

That friction may slow adoption, but it also creates an opportunity for differentiation. Agents that can deliver value with narrower permissions, or that offer transparent logs of what data they access and when, may earn user trust more readily than those that require blanket access. Apple's own Intelligence suite, integrated into macOS 15, uses on-device processing and does not request full-disk access; it reads Messages and Mail through private APIs that do not expose the underlying database files. That architectural choice is now a competitive advantage.

The regulatory environment is also shifting. The European Union's Digital Services Act and the proposed AI Act both contemplate consent requirements for systems that process personal data to generate recommendations. California's Delete Act, which took effect in September, requires companies to honour data deletion requests across all their services, including AI agents. If an agent has scraped a user's message history, and the user later requests deletion, the company must purge not only the raw messages but also any embeddings, summaries, or derived context stored in the agent's memory.

What Comes Next

Apple's full-disk access revision is a reactive measure, but it signals a broader reckoning with the permission models that underpin ambient AI. Operating systems were designed to gate access to files and hardware, not to govern how applications use the data they collect or how long they retain it. As agents become more capable and more autonomous, the gap between technical permissions and user expectations will widen.

The next generation of operating systems will need to treat agent behaviour as a first-class concern. That might mean runtime monitoring of which data an agent reads and when, with a log accessible to the user. It might mean automatic expiry of permissions after a set period, forcing agents to re-request access and justify continued need. It might mean sandboxing agent memory so that context gathered from one data source cannot be mixed with context from another without explicit consent.

For now, the Muse incident has delivered a clear lesson: the tools that make AI agents useful, full-disk access chief among them, are also the tools that make them dangerous. Apple's fix addresses one vector, but the underlying problem, consent in an age of continuous inference, remains unsolved.

Read next
Policy

Apple Tightens macOS Permissions as AI Agents Push Full Disk Access to the Limit

Linh T. Pham · 6 min
Policy

AWS Drops NDAs as Data Centre Permits Face Triple-Digit Moratorium Wave

Linh T. Pham · 5 min
Policy

Anthropic Shuts Down VPN Workarounds for Claude in Hong Kong

Arjun S. Mehta · 5 min
Spot something wrong? Email corrections@opentechwire.com. We log every correction publicly.