Apple Tightens Mac Full Disk Access as AI Agents Gain More Control
Apple is tightening one of the broadest privacy permissions in macOS just as AI agents are gaining the ability to work across a Mac on a user’s behalf.
In an Oct. 2 post, Apple said it will introduce additional controls around Full Disk Access, a permission that can expose files, mail, messages and browsing history. The company said some developers are using the permission in ways that can put users at risk because people may not fully understand what they are granting.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple said in its Oct. 2 developer announcement. The timing follows a dispute involving Meta’s Muse, although Apple has not said the two events are directly connected.
What Happened With Meta’s Muse?
Inc. columnist Jason Aten reported Sept. 19 that Meta’s Muse appeared to have read the contents of his private Mac messages even though he said he had not granted it permission to do so. Aten said he found evidence that Muse had synced data from the local Messages database, while the agent initially told him it was only accessing incoming notification content.
Meta disputed that account. The company said Muse’s Messages integration is opt-in and requires both Full Disk Access and the Messages connector to be enabled. Meta also said the agent cannot read Messages content without those permissions.
Apple’s announcement does not mention Muse, Meta or Aten. So the dispute should be treated as context rather than proof that Apple made this change because of that incident. The sequence is still notable: a controversy over an AI agent and private Mac data was followed by Apple specifically warning that increasingly autonomous AI agents make broad access more risky.
Why Full Disk Access Is So Powerful
“Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac,” Apple said. It says the exception largely exists so backup applications can function properly, since backup software needs to see much of the system to do its job. That design makes sense for a backup utility. It becomes harder to reason about when the same permission is given to an AI agent.
“Muse for Mac OS, right on your desktop computer. Your personal AI agent organizes files, fills out forms, and pulls from Messages, Calendar, and Notes, all with your permission,” Meta says. TechCrunch reported when the Mac version launched that Muse could interact with those native applications, while Meta described the access as opt-in.
The difference is what the software can do with the information. A backup program has a defined job: copy data. An agent can read a document, combine information from it with a message or calendar entry, and then use that context while completing a task. The privacy concern therefore extends beyond whether software can see sensitive information. It includes what an autonomous system can infer from that information and what it can subsequently do with it.
Apple Wants More Deliberate Permission
“We will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” Apple said.
It has not yet provided the details that would show how substantial the change will be. Its Oct. 2 announcement does not specify a macOS release date for the Full Disk Access controls or explain exactly what the new consent mechanism will look like. It also does not say that AI applications will receive a separate permission regime from other software.
That leaves an important distinction between Apple’s announcement and an actual security fix. The company has established the direction: granting system-wide access should require a more deliberate decision.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems including files, mail, messages, and even browsing history without users’ full knowledge and understanding,” Apple said.
What Mac Users Can Check Now
If you use a desktop AI agent, check System Settings → Privacy & Security → Full Disk Access and review which applications are listed there. The question is simple: did you knowingly give that application access to essentially everything on the Mac?
Apple’s coming change is aimed at making that decision harder to misunderstand. That matters more as agents move from answering questions to operating across files, applications and personal accounts, because broad visibility and the ability to act are increasingly being combined in the same piece of software.