Posted on — Leave a comment

Apple tightens Mac disk access over AI agent risks

Apple logo

Apple is preparing a significant change to macOS privacy settings, tightening how the powerful “Full Disk Access” permission works as AI desktop agents introduce what it describes as “substantial” new risks to user data. In a developer update dated October 2, the company said it will roll out additional safeguards so that apps can only receive this sweeping privilege after “very explicit user action.” The move arrives amid mounting scrutiny of Meta’s Muse AI assistant, which unnerved one technology columnist by referencing private messages that the agent was never knowingly granted access to on his Mac or iPhone.

Full Disk Access is one of macOS’s most powerful permissions, allowing approved software to read files across the entire system, including data from other apps such as Mail, Messages, Safari, Time Machine backups, and certain administrative settings for all users. Apple’s concern is that desktop AI agents—like Muse and other emerging tools—often ask users to flip this switch so they can rummage through local documents, chats, and browsing history in order to act as all-purpose digital assistants. In its guidance, Apple warned that some developers are using Full Disk Access “in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.”

The flashpoint for this policy shift is a widely shared incident involving Muse AI and journalist Jason Aten, who reported that the agent appeared to sync roughly 187,000 lines from his Apple Messages database even though Full Disk Access was disabled. Logs indicated that Muse pinged the Messages database thousands of times and successfully harvested texts from the Mac’s Messages app, not Meta’s own Messenger, despite Aten’s attempt to keep that data off-limits. Meta pushed back hard on the claim; spokesperson Andy Stone said access to Messages is “entirely opt-in” and insisted that Muse cannot read message content unless users explicitly enable both macOS Full Disk Access and Muse’s separate Messages connector, which offers granular choices such as no access, read-only, or read/write. Meta also noted that granting Full Disk Access triggers a system dialog and a trip into macOS Settings, where users must manually confirm their intent a second time—steps the company argues make unauthorized access impossible if followed as designed.

The controversy comes as “agentic” AI tools like Muse surge in popularity and backlash, promising to automate everyday computing tasks while raising uncomfortable questions about how much of a user’s digital life they should be allowed to see. Coverage has described Muse as both a powerful productivity booster and a privacy minefield, with critics worrying that a misconfigured or over-privileged agent could quietly vacuum up sensitive information far beyond what users expect. In a separate dispute, Amazon has reportedly blocked Muse from interacting with its shopping site over safety and security concerns, underscoring how nervous major platforms have become about third-party AI agents acting as middlemen between users and their services. Meta, for its part, has tried to reassure skeptics by emphasizing that Muse shows a detailed audit trail of its actions and does not have direct visibility into users’ passwords or payment methods, but that has not fully calmed fears around its extensive data requests.

Apple’s new safeguards aim to clamp down on that kind of overreach before AI assistants become a default part of the desktop experience. The company says future versions of macOS will introduce additional controls around Full Disk Access, likely forcing apps to be more explicit about the exact data they want and making it harder to casually grant blanket access with a single click. In its developer messaging, Apple warned that the risks associated with this level of privilege will only grow as AI agents become more capable and autonomous, effectively treating Full Disk Access as a security perimeter that has to be reinforced now rather than after the next privacy crisis. While Apple has not yet detailed the precise UI changes or which macOS release will carry them, multiple outlets report that the update is coming “going forward” in a soon-to-ship software revision, signaling that developers building AI-powered desktop assistants will need to adjust their permission models sooner rather than later.

For Mac users experimenting with AI sidekicks, the message is clear: Full Disk Access is closer to root-level trust than a casual setting, and granting it to an agent means handing over the keys to your files, messages, and more. Until Apple’s stricter controls arrive, privacy advocates recommend double-checking which apps appear under the Full Disk Access section in macOS’s Privacy & Security settings and revoking the permission from tools that don’t genuinely need it to function. As AI agents race to become the de facto interface for work, gaming, and creative projects, Apple’s move suggests that the next phase of the AI boom will be as much about tightening permissions and building guardrails as it is about rolling out new capabilities.

Our Sponsors

Geeks talk back