A journalist says Meta’s AI agent read his private iMessages while the Mac setting required to do that was switched off. Meta says that’s technically impossible. Both of those statements are now sitting in public, and only one of them can be right.
That’s the story in a sentence. But the reason I want to walk through it with you isn’t to pick a winner. It’s because this particular argument is a preview of the kind of confusion a lot of us are going to run into as AI agents move onto our actual devices.
What actually happened, as far as we know
Inc. columnist Jason Aten reported an issue with Muse, Meta’s AI agent, involving access to his private messages. TechCrunch then reported that Meta is refuting the claim. Meta VP of Communications Andy Stone said Muse needs two things to read Messages content: macOS Full Disk Access and the Messages connector. His point was that those two requirements can’t be worked around, even if the Muse app itself had a bug.
Decrypt reported something adjacent and more specific: that Muse had synced messages from the Mac’s private Messages database, which does require Full Disk Access, a system-level permission. David Singleton, an executive at Meta Superintelligence Labs, responded that this was an opt-in feature.
So you have a dispute about whether a permission was on, and a separate conversation about whether the user understood they had turned it on. Those are not the same argument, and I think that distinction is where most of the heat is coming from.
Why “opt-in” is doing a lot of work in that sentence
If you’re not a developer, “opt-in” sounds reassuring. You agreed. Done. But in practice, opt-in covers an enormous range of experiences:
- You read a clear description, understood it, and deliberately clicked yes.
- You clicked through a setup flow quickly and granted whatever it asked for to get going.
- You enabled something broad for one reason, not realizing it covered a second thing too.
All three are technically consent. Only the first feels like consent afterward. And Full Disk Access is an unusually blunt permission to begin with. It isn’t “let this app read your Messages.” It’s closer to handing over a master key and trusting that the app only opens the one door it mentioned.
This is the part worth understanding even if you never touch Muse. When an AI agent asks for a system-level permission, you’re often not approving a feature. You’re approving a capability. The feature is what the company says it will do with that capability today.
The other thing agents make harder
Traditional apps mostly do what you click. Agents are different. You give them a goal, and they decide which steps to take and which data to look at. That’s the whole appeal. It’s also what makes disputes like this one messy, because the user often can’t see the agent’s reasoning or its file access in real time.
So when someone says “it read my messages and I never allowed that,” they may be describing a permission failure, or they may be describing a visibility failure, where the access was allowed but the moment it happened was invisible to them. From the outside, those feel identical. From the inside, they’re entirely different engineering problems.
Meta’s position is that the permission chain is solid and can’t be bypassed. That’s a falsifiable claim, which is useful. Either Full Disk Access was granted or it wasn’t, and that’s the kind of thing logs and testing can eventually settle.
What I’d take away from this
Three practical habits, none of which require you to be technical:
- Treat Full Disk Access as the most serious permission on your machine. Check which apps have it, and remove it from anything you don’t actively need it for.
- When an AI tool offers to connect to something, read what it calls the connector. “Messages connector” is a plain-language description of exactly what you’re about to allow.
- Assume any data you let an agent reach is data the agent may actually reach. Not as paranoia, just as planning.
I don’t think this story is about one company being careless. The underlying problem is that our permission systems were designed for apps that wait for instructions, and we’re now pointing them at software that acts on its own. “Did you agree to this?” was a reasonable question in 2015. For agents, the better question is “did you understand the full range of what you agreed to?” Right now, most interfaces aren’t built to answer that, which is exactly why two reasonable parties can look at the same Mac and disagree about what happened on it.
🕒 Published: