AI agents are no longer confined to standalone apps or clunky web interfaces. They’re slipping into your text messages, becoming as ordinary as chatting with a friend. This week, a surge of SMS‑first agents—from personal assistants like Caddy and Fambot to travel‑focused Miso—highlighted how deeply AI is weaving into our daily communication channels. But as these agents gain more autonomy and access to our devices, Apple is responding with a precautionary move: tightening “full disk access” permissions on Mac to curb potential risks.

The Text‑Message AI Agent Boom

A recent TechCrunch survey of the AI agent landscape revealed a clear trend: developers are prioritizing text‑based interfaces because they’re universal, low‑friction, and already embedded in our habits. Agents like Caddy turn your iMessage or RCS chat into a personal assistant that can schedule appointments, organize calendars, and even shop online—all without downloading another app. Fambot acts as a family “chief of staff,” syncing school communications, meal planning, and calendars across iOS, Android, and the web, with SMS as a primary channel. Folk takes a different approach, running on its own private cloud to execute multi‑step tasks and run code, all reachable via WhatsApp, Telegram, and iMessage.

What’s striking is how quickly these agents are moving from novelty to utility. Caddy has been in public beta since April 2026. Fambot, launched in beta in early September, already raised $3.5 million in pre‑seed funding and plans to charge a Netflix‑style subscription once beta ends. Folk, available since May, offers a free tier and a $8.33/month Pro plan for unlimited background tasks. These aren’t sci‑fi experiments; they’re tools people are already using to offload mundane cognitive labor.

Meta’s Open‑Source Musketeer Agents

Adding momentum to the agent ecosystem, Meta recently open‑sourced the code behind its Muse AI agent, enabling hobbyists and developers to build their own AI‑powered gadgets. The Verge reported that Meta released SDKs for ESP32 boards and Raspberry Pis, letting users connect Muse to displays, buttons, sensors, and actuators. Projects range from practical—like a color E‑Ink display showing reminders—to playful, such as a DIY “Muse Charm” touchscreen device. Meta even manufactured 5,000 Muse Home Link gadgets, which it’s giving away to users who join a waitlist. This open‑source push lowers the barrier to experimenting with agentic hardware, complementing the software‑only agents flooding our text messages.

Apple’s Preemptive Strike on Disk Access

But with greater agent power comes greater responsibility—and greater risk. Apple announced it will soon require “very explicit user action” for apps to gain full disk access on Mac, a permission that grants an application virtually unfettered access to a user’s system. The change, reported by The Verge, comes just weeks after security researcher Jason Aten demonstrated that Meta’s Muse AI could read his iMessage and Mac contents without explicit permission, sparking a debate about opt‑in safeguards. Apple’s statement was clear: some developers are using full disk access in ways that expose files, mail, messages, and even browsing history without users’ full understanding. As AI agents grow more capable and autonomous, the risks associated with this level of access will grow substantially.

Apple’s new controls aim to ensure that only users who genuinely intend to grant such deep access can do so, and only through deliberate steps. While the company hasn’t set a rollout date for the update, the signal is clear: the era of frictionless, all‑powerful agent permissions is ending. For developers, this means rethinking how agents interact with the underlying OS. For users, it’s a reminder that convenience often trades off against security—and that the OS vendors will step in when the balance tilts too far.

What This Means for the Agent Landscape

The convergence of these three developments—text‑first agents, open‑source agent hardware, and tighter OS permissions—paints a picture of an ecosystem maturing rapidly. Agents are becoming more accessible, more versatile, and more embedded in our existing communication habits. At the same time, platform holders like Apple are asserting their responsibility to protect users from potential misuse, even if it means adding friction.

For the everyday user, the takeaway is simple: expect to see more AI agents pop up in your iMessage, WhatsApp, or SMS threads, offering to help with everything from grocery shopping to trip planning. But also expect those agents to operate within clearer boundaries set by your device’s operating system. The agent revolution isn’t just about smarter AI; it’s about negotiating the terms of that intelligence in our digital lives.

Want this in your inbox every morning? Subscribe to the SpaghettiStories newsletter. Some links may be affiliate links. If you’re buying hardware to run local models, this affiliate link helps keep the lights on.