Apple to Restrict macOS 'Full Disk Access' Over AI Agent Risks
Apple will tighten macOS 'Full Disk Access' after Jason Aten's claim that Meta's Muse read his private messages, calling AI agent risks to user data 'critical' to address.
Updated
Why it matters
- Apple will introduce new controls around macOS 'Full Disk Access' so users can grant it only with 'very explicit user action.'
- The move follows Jason Aten's claim that Meta's Muse read his private messages without permission — a claim Meta disputed — and a Wired report on a ChatGPT Mac app flaw.
- Apple said 'as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.'
Apple says it will tighten controls around macOS "Full Disk Access," citing new risks created by AI agents that run on users' desktops and can read files, mail, messages, and browsing history.
The announcement came days after Inc. columnist Jason Aten reported that Meta's Muse app on Mac knew the content of his private messages — even though, he claimed, he had not given the AI agent permission to read them. Meta disputed the claim. Apple did not respond to TechCrunch's inquiry about the feature change.
The timing matters. Aten's report struck at the core promise of desktop AI: that an agent can control parts of your system, read your files and messages, and still remain within boundaries the user set. When a journalist says an app read private conversations without explicit permission — and the vendor says it did not — users are left with no independent way to verify either account. Apple's response, delivered through a blog post aimed at developers rather than a direct reply to the incident, effectively concedes that the current permission model is no longer adequate for the category of software now clamoring for it.
A third trigger appears to sit in the background. Apple's decision also follows a Wired report citing a flaw in ChatGPT's Mac app that could have allowed hackers to access sensitive data. Two high-profile incidents in quick succession — one involving an AI agent's access to private messages, one involving a security hole in an AI desktop app — put Apple in the position of gatekeeper for an ecosystem it did not design its permissions around.
What Full Disk Access actually grants
The feature was originally designed to allow backups to function properly. That is a narrow, well-understood use case: backup software needs broad read access to do its job, and users grant it with a reasonable expectation of what that means.
AI agents have changed the calculus. Desktop agents ask users to adjust macOS settings to give their apps greater access to files, messages, and other personal content. Muse, for instance, optionally allows users to enable Full Disk Access. As Apple explains the setting, it gives an app permission to access files, mail, messages, and even browsing history.
That is a strikingly broad surface. A single toggle hands an application visibility into essentially the record of a person's digital life stored on that machine. For backup software, that breadth is a technical necessity. For an autonomous agent that can act on what it reads — summarizing, routing, replying, sharing context with other services — the same breadth becomes something closer to a standing invitation.
Apple's language in the developer blog post is unusually blunt about how some apps are handling that invitation.
"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users' full knowledge and understanding," Apple said.
The company says that, going forward, it will introduce new controls aimed at ensuring that users who "genuinely wish to grant an app this extraordinary level of access" can do so only with "very explicit user action."
The framing is notable in two respects. First, Apple calls the access level "extraordinary" — a word choice that positions broad disk access as an exception requiring deliberate consent, not a default setting that ambitious apps should request as a matter of course. Second, by aiming the post at developers, Apple is signaling that the burden of justification shifts to the app makers: if an AI agent wants this level of access, it will need to survive a consent flow designed to make users stop and think.
Why Apple is acting now
Apple tied the change directly to the trajectory of AI agents, not merely to their current behavior.
"Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy," Apple wrote.
That statement reads as an admission that the risk curve is bending upward. The concern is not only what today's agents do with Full Disk Access, but what increasingly autonomous agents will be able to do with it tomorrow. An agent that can read mail, messages, files, and browsing history — and act autonomously on that material — concentrates an extraordinary amount of personal context in one place. A permission system designed for backup tools does not automatically scale to that scenario.
The Muse episode illustrates the trust gap. According to Aten's report, Muse knew the content of his private messages despite his claim that he never granted permission. Meta disputes the account. Whatever the factual resolution, the episode raised a question every desktop AI user now faces: how do you verify what an agent on your machine can actually see?
On macOS today, the honest answer is that verification is hard. Users can check which apps hold Full Disk Access in system settings, but the practical meaning of that grant — what the app reads, when, and where the data goes — is opaque. When Apple says developers are exposing "everything on their systems…without users' full knowledge and understanding," it is describing that gap between the technical permission and the user's mental model of it.
The stakes for desktop AI
The market context is straightforward. AI agents are moving from chat interfaces toward software that operates directly on the desktop — controlling things on users' systems, reading files and messages, and taking actions on the user's behalf. That shift is the entire value proposition of the category. It is also the source of the risk Apple is now moving to constrain.
For AI developers, tighter controls around Full Disk Access mean friction at the exact moment they are asking users for maximum trust. If the new consent flows make "very explicit user action" a prerequisite, apps will need to explain, clearly and honestly, why they need access to mail, messages, files, and browsing history — and what they will do with it. Developers who cannot make that case convincingly may find their agents functionally hobbled.
For users, the change promises something the current system does not reliably deliver: a permission decision that reflects the actual stakes. Apple's stated goal is that users "clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."
What comes next
Apple has not detailed the specific mechanics of the new controls or a timeline for their arrival. The company also did not respond to TechCrunch's inquiry about the feature change, leaving the developer blog post as the primary public statement on the matter.
What is clear is the direction. Apple has identified Full Disk Access as a permission whose risk profile has outgrown its original design, and it has named AI agents as the reason. As agents grow more capable and more autonomous — in Apple's own words, the risks "will grow substantially" — the question for the desktop AI market is whether deep system access remains a selling point or becomes the most heavily guarded gate on the platform.
Original: inc.com
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
175 articles
Related articles
- Meta Denies Muse Read Private Messages Without User Consent
- Meta Says Muse's Exposed Filesystem Is Intended Behavior
- Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
- Meta Gives Muse Email Addresses, Video Calls, and Computer Access
- Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent