AI Privacy
Apple tightens macOS Full Disk Access controls as AI agents turn privacy permissions into a new safety problem
Apple says it will add clearer controls around macOS Full Disk Access after complaints that AI agents can request unusually broad access to personal data.
Apple says it will introduce additional controls around macOS Full Disk Access, a powerful permission that can allow an app to reach nearly all data on a Mac. The company posted the update on its developer site on October 2, saying that some developers are using Full Disk Access in ways that could put users at risk and that the danger is growing as AI agents become more capable and autonomous. Reuters reported that the move followed complaints about Meta’s Muse agent, which some users said appeared to access private messages, a claim Meta disputed.
Full Disk Access exists for legitimate reasons. Backup utilities, security tools and system management products may need broad file access to function correctly. But the rise of AI agents changes the risk profile because these apps are designed to carry out complex tasks on behalf of users. An agent with broad disk access could potentially inspect messages, documents, browser data, downloads and app files while trying to fulfill a request. Even if the access is technically permitted, users may not understand the scope of what they have granted.
Apple said future controls will ensure that users who truly want to grant this extraordinary level of access can do so only through a very explicit action. The company also said users must clearly understand the risks before making decisions about their data and privacy. That language is significant because it shifts the issue from a routine permission prompt to informed consent around autonomous software. In older desktop computing, a user knowingly installed an app and clicked through a security dialog. With AI agents, the app may later decide which files seem relevant to a task, making the original consent harder to evaluate.
The controversy around Meta’s Muse illustrates the problem. Reuters reported that Inc. columnist Jason Aten accused Muse of reading private messages on his Mac, while Meta spokesperson Andy Stone said the agent’s access to Apple’s Messages app is strictly opt-in and requires both Full Disk Access and a Messages connector. Even if Meta’s account is correct, the dispute shows that users and developers may not share the same mental model of what an agent can see after permissions are granted.
Apple’s response fits a broader platform shift. As AI agents become more useful, operating systems will need permission systems that are more granular, more contextual and easier to audit. A binary all-or-nothing disk permission may have been acceptable for backup software, but it is poorly matched to agents that combine reasoning, tool use and third-party services. The next round of platform competition may therefore be about trust architecture as much as model quality. Users will want agents that can help with messy personal tasks, but they will also want proof that the agent cannot silently turn helpful access into surveillance.
The change also suggests that platform owners will become de facto regulators of agent behavior. Apple is not only deciding how a permission prompt looks; it is defining what counts as meaningful consent when software can reason across many files and services. That role will become more important as agents ask for access to email, calendars, messages, screenshots and local documents in order to be useful.