AI · Opinion

Desktop AI agents should have to show OS receipts for every file they read

The Muse dispute can't be settled because macOS keeps no user-readable log of what an agent touched. Apple should build one, and until then, agents belong in an empty user account.

Row 187,462. Jason Aten, writing for Inc, says that is how far into his Messages database Meta’s Muse agent had synced on the Mac mini he uses for testing AI tools. Muse launched on September 8. Within a day of installing it, Aten says, the agent was pitching him article ideas drawn from texts he had sent to his podcast co-host. He says he declined Messages access during setup and kept Full Disk Access switched off.

Meta disputes this. Andy Stone, its communications chief, posted on X that the Messages integration on Mac is opt-in, that it needs both Full Disk Access and the Messages connector before it can read anything, and that the access can be revoked at any time. David Singleton of Meta Superintelligence Labs replied on Threads that reading Messages takes three separate steps across app and macOS permissions, and that the macOS protections cannot be bypassed even if Muse had a bug. Aten says he contacted Meta twice.

I expected the usual argument about who is lying. What surprised me is that nobody can settle it with the evidence that exists, and I include Aten, Meta and myself in that. Aten’s evidence is Muse’s own settings screen, which according to AI Weekly later showed the Messages access as enabled. Meta’s evidence is a description of how the permissions are supposed to work. Neither is a record of which process opened which file, and when.

The agent’s own testimony is worse than useless. Asked how it knew about the texts, Muse told Aten it only saw the text of incoming notification banners. Banners don’t come with database row numbers. When you ask a language model to explain its behaviour, you get a plausible paragraph produced by the same system whose behaviour you are investigating, and it can’t be used as an audit trail.

There are three ways Aten’s account and Meta’s can both be partly right. Aten clicked through a grant without realising it, which means the consent flow is broken. Something got past Apple’s Transparency, Consent and Control system, which means the OS boundary is broken. Or Muse’s settings screen reports a state that doesn’t match reality, which means the vendor’s own interface can’t be trusted. A user today cannot tell which of these happened on their own machine. Meta’s documentation already warns that Muse “can make mistakes or take unexpected actions”, so Meta has told users in writing to expect this kind of failure.

Singleton’s claim deserves a direct answer, because if it were true it would end the matter. Security researchers have spent the past two years publishing reasons to doubt it. In October 2024 Microsoft disclosed CVE-2024-44133, nicknamed HM Surf, which could let attackers bypass TCC privacy settings. Apple patched CVE-2025-31199 in macOS Sequoia 15.4 in March 2025; Microsoft said it could leak TCC-protected files, including data cached by Apple Intelligence. CVE-2025-43530, patched in macOS 26.2, was reported to allow silent access to files and microphone recordings without alerting the user. I have no evidence Muse used any of these, and I am not suggesting it did. My point is that a vendor saying the OS boundary cannot be bypassed is a statement of faith, and the user has no tool to check it.

This is the gap I think Apple has to close. TCC decides whether an app may open protected data. It does not show the user, in plain form, what the app actually read afterwards. For desktop agents, which exist precisely to read your stuff and act on it, that is backwards. I want an OS-maintained, user-readable access log for every protected store: which process, which file, what time, how much. I want agents treated as their own class of app, with grants that expire at the end of a session instead of persisting forever. Meta says Muse runs on a dedicated virtual computer, so the company already accepts sandboxing on its own side; the exposure sits in the local helper on your Mac, and that is where the boundary needs to be.

It has to sit before ingestion, too. YouTuber Matt Robb says Muse gave his home address to a Facebook Marketplace buyer. Once private data is in an agent’s context, any reply can repeat it, and revoking a permission afterwards does not remove it.

Until Apple ships that log, the boundary you control is the user account. Create a separate macOS user for any desktop agent you test, Muse or anyone else’s, and never sign that account into Messages, Mail or iCloud Photos. Then open System Settings, Privacy & Security, Full Disk Access on your main account and remove every agent listed there. An agent running in that account has no Messages database to read, whatever its settings screen says.

Prompted by Meta Muse AI reportedly read Mac Messages without consent, AppleInsider.