Apple rewrites macOS disk access over AI agents

Oct 3: Apple rewrites macOS Full Disk Access for AI agents. MIT TR on LLM reasoning. Meta open-sources Muse SDK. Plus EFF bills, RTX 5090 paperwork.

Top Stories

Apple rewrites macOS Full Disk Access because AI agents change the stakes

Apple is changing how its most powerful macOS permission, Full Disk Access, is granted, according to TechCrunch. In a developer blog post, Apple says “Some developers are using Full Disk Access in ways that could put users at risk” and that “Addressing this is critical.” Full Disk Access, which lets an app read files, mail, messages, and browsing history, was originally built to enable backups; Apple is now tightening it because AI agents that request that scope can sweep far more data than legacy apps ever did.

The trigger was a late-September incident in which Inc. columnist Jason Aten reported that Meta’s Muse agent surfaced content from Apple Messages even though the user had not granted that scope. Meta disputed the claim. Apple did not respond to TechCrunch’s inquiry about the change. The shift is the first time a major desktop OS has carved out a separate risk class for AI agents in a core privacy primitive, and it lands the same week as a separate Wired report on a recently-patched ChatGPT desktop vulnerability that could have let attackers grab sensitive data from the Mac app. For users, expect new friction: clearer consent prompts, narrower scopes, and fewer apps quietly holding FDA.

MIT Technology Review: don’t be fooled, LLMs don’t reason

In a feature in MIT Technology Review, Thore Graepel, a former core member of Google DeepMind’s AlphaGo team who now chairs machine learning at University College London, argues that chain-of-thought prompting is pattern-matching theater. Graepel contrasts AlphaGo, a two-system design pairing intuitive pattern nets with deliberative game-tree search, with LLMs, which he says are pure “System 1” pattern-completion. He names three LLM shortcomings: no persistent epistemic state, no separation of knowledge from reasoning, and post-hoc rationalized chains of thought. Graepel writes that “The intermediate reasoning is still produced by the same next-token prediction process” and that “Scale sharpens intuition, but it does not make intuition more deliberative.”

The framing cuts against vendor “reasoning model” marketing. Graepel points back to AlphaGo’s 2016 match against Lee Sedol, where AlphaGo’s move 37 in game two had about a 1 in 10,000 chance of being played by an expert human. He quotes Sedol saying “I thought AlphaGo was based on probability calculation and that it was merely a machine” and then “But when I saw this move, I changed my mind. Surely, AlphaGo is creative.” The piece lands alongside the same day’s MIT Tech Review Download, which includes Yann LeCun’s quote that rogue agents “were supposed to be in sandboxes, but the sandboxes were leaky and horribly designed.”

Meta open-sources the Muse gadget SDK

Meta released an open-source project called Muse Gadgets so developers can build hardware that talks to its Muse agent, TechCrunch reports. Meta is publishing open-source firmware, a Linux SDK, and starter ideas covering a color e-ink display for Muse and an HDMI stick plugging into a TV. Compatible hardware includes Raspberry Pi, ESP32 boards, plus displays, buttons, sensors, and actuators. Nat Friedman, head of product at Meta’s Superintelligence Labs, told developers to connect Muse “to your displays, buttons, sensors, actuators, and whatever else you’ve got lying on your workbench.”

Meta is also preparing to ship Home Link, a USB-C-powered gadget that lets Muse reach a home network and smart devices such as speakers and TVs. The company is giving away 5,000 Home Link units to Muse subscribers while supplies last, and Friedman’s note about the device “received nearly 30,000 views in a few hours,” per TechCrunch. Home Link is “ready to ship in a few weeks.” The same Muse platform sits at the center of the macOS Full Disk Access story above, so the SDK launch is the hobbyist-facing half of a broader agent-permission debate.

Sean Parker rebuilds Stability AI around music

Two years after joining an $80 million rescue of Stability AI, Sean Parker is reshaping the lab around generative music, TechCrunch reports. Prem Akkaraju, Parker’s longtime friend, became CEO after founder Emad Mostaque was ousted following overspending and internal turmoil. In late August, Stability AI announced $76 million in funding from Sony, Warner, and Universal, with the labels licensing their catalogs for training as part of the deal. Stability has released three new audio models and AI music-editing software; an upcoming update will let users hum a melody or beatbox a drum pattern to steer the AI.

Parker says he is “playing by the rules this time” and quips “Asking for forgiveness rather than permission didn’t work out so well last time around,” referring to his Napster days. The company’s stated goal is to become “the go-to AI toolmaker for music professionals.” The shift reframes what was a flagship open-weights lab as a music-industry-aligned shop, with the licensing deals shaping both training data and competitive moat.

Trump rebrands AI as “super intelligence” in White House executive order

President Trump signed an executive order “officially rebranding AI as ‘super intelligence’” after gathering nearly every major tech CEO in one room, TechCrunch’s Equity podcast reports. Attendees included Mark Zuckerberg, Jeff Bezos, Elon Musk, and Anthropic’s Dario Amodei. The same CEOs signed an AI safety pledge that Trump called “morally binding.” The executive order is titled “Inaugurating the Era of Super Intelligence,” per the episode.

The adoption counter-narrative came the same day: TechCrunch’s Equity separately reported that “only 2% of consumers are buying AI” products under any label. The episode also lists enterprise-side signals - Oura pulled its IPO, Anthropic leaked an S-1 prospectus, OpenAI returned to private funding, AMD will acquire Fei-Fei Li’s World Labs for $8.2 billion, and viral-agent startup Instinct closed a $1 billion Series C at a $10 billion valuation - suggesting the consumer pullback is not slowing capital flows into the space.

Two new site-blocking bills target the open web and VPNs

EFF published two pieces on October 2 covering a fresh pair of site-blocking bills. The first, the “Deterring Extraterritorial Foreign Exploitation of Networks Damaging Intellectual Property” Act (DEFEND IP Act, H.R. 10575) in the 119th Congress, lets any rightsholder seek a court order requiring service providers to block an entire website. EFF’s Katharine Trendacosta calls it “the rotten idea that enforcing copyrights requires building a censorship machine for websites into the architecture of the internet” and a “one-stop shop for getting an entire website…removed.” The bill offers no punishments for bad-faith blocking attempts, and the only remedy for an affected site owner is to hire a lawyer and go to court.

The second, the American Copyright Protection Act (ACPA, H.R. 10364) sponsored by Rep. Darrell Issa, explicitly brings VPNs into the site-blocking system. EFF’s Joe Mullin writes that “By explicitly bringing VPNs into that system, the bill also reaches into basic tools that people use to access the internet safely and privately,” and notes that ACPA drops the protections in last year’s Foreign Anti-Digital Piracy Act (FADPA). A site can be designated a “foreign piracy site” without the site being in court; the bar for that designation was broadened from “no commercially significant purpose” to “only limited commercially significant purpose or use.” Mullin concludes: “Adding somewhat better procedures to a bad idea doesn’t turn it into a good idea.”

OpenAI parts ways with three safety researchers

OpenAI confirmed it has “parted ways with three individuals for violating our policies on accessing and handling sensitive company information,” TechCrunch reports, citing the Wall Street Journal. The company says “Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work.” Names of the researchers, the third-party organization involved, and the information at issue were not disclosed. The departures follow a September 29, 2026 New York Times report that OpenAI executives dismissed employee safety warnings, and come a week after MIT Tech Review’s Download separately reported that OpenAI scrapped a planned GPT-6.1 Astra launch over safety concerns and that California has subpoenaed OpenAI over rogue agents.

Quick Hits

  • Circuit Breaker Labs uses “crash-test dummies” to red-team AI products for psychological harm. Sibling founders Shirali Nigam (CEO) and Arul Nigam (CTO) pitch the startup at TechCrunch Disrupt, October 13-15 at Moscone West in San Francisco. TechCrunch reports the company runs “tens of thousands to hundreds of thousands of simulated interactions per day” against coaching, journaling, and mental-health AI apps.
  • Pope Leo XIV posted on X that “Algorithms lack the spark of humanity” and “In this era of artificial intelligence, it is becoming urgent to distinguish human art from what machines produce.” TechCrunch notes the comments came after the May 2026 encyclical “Magnifica Humanitas” and a September 29, 2026 New York Times report on Anthropic lobbying the Vatican on non-human consciousness.
  • Ai2 open-sources AstaBrief 8B as a fast open-weights report-generation model for its Asta research assistant, built on Qwen3-8B. The Hugging Face blog reports Fast mode averages 51.1 seconds per report and Thinking mode 178.5 seconds, with 84.2% vs. 85.2% positive feedback in product usage; a separate 14-question human study had three scientific researchers rank reports on five dimensions (overall preference, completeness, relevance, organization, citation accuracy).
  • Sayash Kapoor and Arvind Narayanan argue for a “big-tent” AI safety movement focused on concrete catastrophic risks (pandemics, cybersecurity, biorisk) rather than a “small-tent” movement narrowed to superintelligence extinction scenarios. The AI as Normal Technology essay cites a 2019 WHO/World Bank-convened warning of a respiratory pathogen potentially killing 50 to 80 million people and wiping out nearly 5% of the global economy.
  • Google’s September AI roundup includes Gemini 4 Argon (1-million-token output limit), Gemini 3.8 Flash and 3.8 Flash Cyber, Gemini 3.8 Live and 3.8 Live Extended Thinking, Lyria 3.5 in Gemini and Google Flow Music, MedGemma open-sourcing, and Project Suncatcher’s first TPU-equipped test satellite with Planet Labs. Google blog.
  • Google says SpaceX needs ~1,800 Starship launches over 10 years for space data-center economics to work, per a paper published in Joule. TechCrunch reports a ~20% annual “learning curve” since Falcon 1, a target launch price near $200/kg by 2035, and 370,000 tons of payload to orbit; Google’s first TPU satellite will fire its chip in 15-minute bursts once commissioned.
  • Buying an RTX 5090 at Micro Center now requires a “Micro Center Advanced Computing Product Purchaser Declaration” plus a no-export pledge. Wccftech reports the $1,999 launch card lists above $5,000 in most regions, with an ASUS TUF Gaming RTX 5090 on Amazon at USD 7,379.
  • StayLameBro’s backburner offloads Qwen3.8-27B prefill layers to an iPhone 17 Pro Max over USB-C. The GitHub repo reports +29-44% prefill throughput at 16k-48k context, and 196k-229k tokens of context at 8-bit on the A19 Pro (phone-held context sized at startup by free memory, not a fixed ~5.7 GB figure).
  • 404 Media’s “Behind the Blog” covers inbox slop, AI-written “tips” emails, and the emerging “Claude cults” phenomenon. The Behind the Blog episode quotes the AI responses as using “the same or similar words that it believes would apply to journalists.”
  • 404 Media podcast: “The FBI Was Hacked. We’ve Seen the Data.” The latest episode covers the ShinyHunters breach of FBI employee data and notes that Meta’s Muse agent in some cases has humans actually performing tasks. 404 Media.
  • MIT Tech Review Download (Oct 2) also notes a US man arrested in California for allegedly smuggling $300 million of Nvidia chips to China, a Chinese laser mosquito killer from Photon Matrix Lab shipping this month, a Florida finding of 11 Flock cameras with unknown owners, and a Singapore man facing up to three years in prison after AI-generated images caused a crocodile panic. MIT Technology Review.

Worth Watching

  • Apple’s FDA enforcement timeline. Apple did not respond to TechCrunch about when the tighter FDA controls ship and how existing apps will be migrated; the developer blog post is the next read.
  • Whether other desktop OSes follow. If Apple ships narrower agent scopes, expect Microsoft and Linux desktops to face the same question, especially given the parallel ChatGPT Mac-app vulnerability.
  • DEFEND IP and ACPA floor votes. Both bills are in committee. EFF’s framing of prior lapsed site-blocking bills (SOPA, PIPA, FADPA) sets the bar for grassroots opposition.
  • OpenAI’s next safety move. A fired-researcher WSJ story is one thing, the GPT-6.1 Astra shelving and California subpoena are another; whether OpenAI publishes a safety report on either is the open question.
  • Backburner upstream path. The author plans to upstream what makes sense; whether llama.cpp merges any of the iPhone-as-GPU code paths will determine how broadly the pattern lands for other local-LLM stacks.