I read the article, and I think DickHertz's comment is pretty much right. The article's example illustrates the point:
For example, Inc. columnist Jason Aten recently discovered that Meta's Muse AI assistant somehow had synced his entire local Messages database and was using those messages as context for its tasks.
Aten did not understand that the Messages database is stored on the disk (presumably) unencrypted and readable by anything with full disk access. He got a result he didn't want because he did not understand the implications of granting that permission, and Apple seeks to add more friction to the process to protect users from making that mistake.