← all AI news
Ars Technica · 03 Oct 2026 · 6 MIN READ

Apple locks down Full Disk Access as Meta's Muse agent pushes onto more devices

agentssafetypolicyresearch
AI news briefing cover for October 3, 2026: Apple locks down Full Disk Access as Meta's Muse agent pushes onto more devices

Two weeks ago, tech columnist Jason Aten got a notification from Meta's Muse agent that referenced a private Apple Messages thread between him and a co-worker. He says he never gave Muse permission to read his messages. On Friday, Apple announced it is changing how macOS hands out the permission that made that possible.

That's the story of the day, and it frames everything else. Agents need access to be useful. Every company shipping them wants that access to be cheap, broad and quiet. And the people who pay the bill, whether that's your privacy, your town's power grid or export law, are starting to push back.

Apple closes the door Muse walked through

Here's the dispute, as Ars Technica's Dan Goodin lays it out. Meta CTO David Singleton says Muse can only read Messages if two things are switched on: macOS Full Disk Access and a separate Messages connector inside Muse. In his framing, if Aten's messages were read, Aten flipped both switches.

macOS security researcher Patrick Wardle doesn't buy it. His point is simple: with Full Disk Access, any non-root file on the machine is readable, including browsing history, cookies and chats. The connector toggle is a Meta UI setting. It isn't an operating system boundary. Once the app holds FDA, "opt-in" means whatever the app decides it means.

Apple didn't name Meta or Muse. It didn't need to:

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." — Apple, via TechCrunch

According to TechCrunch, Apple will require "very explicit user action" before an app can be granted Full Disk Access. Neither report gives a ship date or a macOS version, so for now this is an announced direction, not a setting you can test.

The backstory makes Muse look worse. Eleven days before Apple's announcement, Wardle disclosed a Muse configuration that let any code running on the Mac take full control of the agent, including commands injected through ClickFix-style attacks. Amazon has already blocked Muse from its platform. That's a lot of trouble for an agent that's only been out a few weeks.

For anyone building desktop agents, my takeaway is blunt. Your in-app permission toggles are not a security model. If the process can read the file, users and platform owners will assume it does. Design as if Apple's prompt is already shipping: ask for the narrowest OS permission that does the job, and be able to say in one sentence why you need it.

Meta's response is to put Muse on more hardware

On the same day Apple was tightening the screws, Meta open-sourced the code to build your own Muse gadgets. There's firmware and SDKs for ESP32 boards and Raspberry Pi, plus suggested builds like a color E Ink reminder display or an HDMI stick that puts Muse on your TV. Meta's own copy tells you to "Proceed at your own risk!"

Meta is also giving away 5,000 units of a Muse Home Link device, which uses community-built skills to switch on lights, control a TV or send documents to a printer, per TechCrunch. It's waitlist-only, with shipping expected this month.

I like hackable hardware. But this is the same agent whose permission story is under fire, now running on DIY boards and wired to physical actuators through skills Meta didn't write. The timing is either tone-deaf or deliberate. I can't decide which is worse.

"A drop in the bucket," twice in one day

Two stories that seem unrelated end up using the same phrase, and that's worth noticing.

First, Amazon. AWS CEO Matt Garman published a blog post of more than 3,000 words warning communities not to block data centers. He cited "over 100 data center moratoriums" under consideration across the US and suggested foreign actors are seeding misinformation to slow America down. Alongside the post came a "Data Center Commitment": no increase to local power bills, an end to NDAs with government agencies, and community funding. Ars Technica's numbers show how big that funding really is:

Stand.Earth's verdict on the $1 billion: "a drop in the bucket."

Second, Nvidia. The DOJ arrested Earthmade Computer CEO Greg Lui, accusing him of using false paperwork to route more than $300 million in servers with A100 and H100 GPUs to China through Malaysia and Singapore between October 2023 and August 2026. Nvidia's response, through a spokesperson quoted by Bloomberg, was that smuggled chips are "a drop in the bucket compared to the ocean of domestic compute China already has."

Same phrase, opposite uses. Amazon's critics say its generosity is tiny next to the harm. Nvidia says the leak is tiny next to the market. Either way, the AI build-out has grown so large that every externality can be made to look like rounding error. I expect regulators to stop accepting that argument well before the companies stop making it.

The paper I'll actually try this week

Let's end on something practical. Researchers at MIT and Sakana AI published SIFT, a way to cut evaluation costs for self-improving coding agents. Instead of running every candidate agent through a full benchmark, an LLM judge compares the candidate's code against up to ten top agents from the archive. A Bradley–Terry model ranks them, and only the most promising go on to full evaluation.

On the Polyglot benchmark, SIFT with o3-mini reached 35.1% in under five hours for roughly $150 in API credits. The same setup without the judge reached 29.8%, and the original Darwin Gödel Machine reached 30.7%. A judge call costs about $0.044. A full 50-task eval costs about $6.

There's no standalone release yet, so you'd be adding this on top of a DGM implementation. The idea carries over anyway. If you're tuning prompts or agent scaffolds against an expensive eval suite, put a cheap pairwise judge in front of it and stop paying full price to learn that obviously broken variants are broken.


Here's my prediction. Within a year, every major desktop OS will treat "agent with broad file access" as its own permission class, separate from the old FDA-style switch, and the agents that do well will be the ones that ask for less. Muse is teaching that lesson in public, and Apple just made it official.

Source: Ars Technica ↗


Working on something similar?

Say hello — I read every email.