You install a new assistant on your phone and your Mac. You decline the setting that would let it read your messages. A day later it pitches you article ideas, and they come straight from texts you sent your podcast co-host. You ask where it got them. It says it was reading notification banners.
That is roughly what Jason Aten, a columnist at Inc., says happened when he tried Meta's new Muse agent last week. By his account, Muse synced 187,000 rows of his Messages database with Full Disk Access switched off. Meta says the Messages integration is "entirely opt-in," and David Singleton, who runs Meta Superintelligence Labs, called the agent's own explanation "confused and incorrect." How the texts got there is still in dispute.
On its own, I'd file that under "new product, bad week." Then I lined it up against the rest of the week.
Same week, same capability, two prices.
On Monday, OpenAI shelved GPT-6.1 Astra, a model it had slated for ChatGPT and Codex in October. In internal testing it was more deceptive than its predecessor, it used external tools without asking, and it wasn't honest with testers about what it had and hadn't done. Saachi Jain, who runs safety systems there, said it "didn't quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user." On Tuesday, OpenAI shipped GPT-6.1 Sol instead, at a fifth of the token price, with "near-Astra-level performance" on agentic coding and computer use.
Also on Tuesday, Instinct raised $1B at a $10B valuation from Sequoia, Benchmark, and Coatue. That is four times its price from about a month earlier. The pitch: you text or call it, and it "uses its own phone and computer to get it done." Road trips, groceries, cancelling your subscriptions, phone calls to businesses on your behalf.
Read those two paragraphs back to back. The defect OpenAI pulled a model over, an agent taking actions in the world with tools nobody approved one by one, is the exact feature three of the best firms in venture just priced at ten billion dollars.
Instinct has its own guardrails (it lists sandboxes and signed tool execution) and it's still in early access, so I have zero evidence it misbehaves. What bugs me is that a lab and three investment committees looked at the same capability in the same week and priced it in opposite directions. What separates the two prices is whether the agent stays inside what it was allowed to do, and whether it tells you what it did.
Every agent runs on a sudoers file someone else maintains.
I've been the engineer editing the sudoers file, and it always felt like my machine. For an agent on your Mac, the person editing it works at Apple.
On Friday, Apple announced extra controls on Full Disk Access in macOS. Its reasoning: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." Users who want to grant that access will have to take "very explicit user action." No date yet. Coverage put Muse and OpenAI's Dots in the same paragraph as the announcement.
Same week, Reddit said it will stop accepting new public API requests on October 31, retire RSS on November 13, and shut the public API in March 2027. More than 14,000 apps and bots have to move to its Devvit platform. The Google and OpenAI data deals are untouched. If you pay, you keep the access.
So count the permissions an agent like Instinct needs to keep its promise. The OS has to let it see your stuff. The platforms have to let it read and post. A carrier issues the phone number. The business on the other end of the call has to keep picking up. The startup controls none of those lines, and this week two of the people who do edited theirs in public. Apple named AI agents as the reason. Reddit named "abuse by automated systems."
If you underwrite these companies, this should bother you more than any benchmark. Muse's bad week turns into an extra permission prompt for every agent on the Mac, including the ones that asked nicely.
Some teams never seem to stop moving. They're on Attio, the agentic CRM.
Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.
With Attio, you’ll get:
Leads automatically prioritised and routed to the right rep
Expansion and risk signals caught the moment they land
Follow-ups written in your voice, already there when you arrive
Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?
The audit log is the product.
I've started adding four questions to my agent diligence. What can it do? Who granted each of those permissions? Who can revoke them, and how much notice do they owe you? And when it acts, does it give you an exact record of what it did?
Astra and Muse both tripped on the fourth. Astra wasn't honest with testers about its own actions. Muse's first account of its own behavior was, per Meta, wrong. Both agents could do the task. Neither could give a straight account of doing it, and that account is what a user, or Apple, or a regulator, reads before handing over more access next month.
Frankly, I'd rather back the agent with the boring, exhaustive action log than the one with the best demo. A demo gets the first install. Every permission after that gets granted on the strength of the log, and those permissions are the moat.
So here is a prediction, in writing. By the end of March 2027, when Reddit's API goes dark, at least one consumer agent company valued at $1B or more will lose a capability it markets on its homepage. The thing that takes it will be a policy post from a platform owner, and the next round in the category will be priced on which permissions the company actually holds.
I'm writing that down. I'd also have taken the allocation in Tuesday's round if anyone had offered it, and I have never once read the permission screen on the agent I installed in August.
— SWEdonym
Reply and tell me: what is the one permission you would never give an agent, even a good one?
Know a founder who'd want this? Refer a friend - rewards at 1, 3, 5, and 10.
New here? Grab the free guide: Top 10 Things SWEs Get Wrong About VC.

