Apple Tightens macOS Full Disk Access Amid Growing AI Agent Risks

Apple adds new controls to macOS Full Disk Access after AI agents like Meta’s Muse raised privacy concerns, requiring explicit user consent.

abstract prism with rings of light representing data protection
AI-generated illustration
On this page
  1. What happened
  2. Why it matters
  3. The bigger picture
  4. What happens next

Apple announced a major change to macOS that will make it harder for applications to obtain “Full Disk Access,” a permission that lets software read a user’s entire file system. The move comes after high‑profile reports that AI‑driven agents, such as Meta’s Muse chatbot, were able to read private messages without clear user consent. Apple says the new controls will require “very explicit user action” before an app can be granted this sweeping level of access.

What happened

In a blog post aimed at developers, Apple warned that some developers were using Full Disk Access in ways that could expose everything on a user’s Mac—including files, mail, messages, and browsing history—without the user fully understanding the implications. The company highlighted the accelerating capabilities of AI agents, noting that as these agents become more autonomous, the risks associated with unrestricted disk access will “grow substantially.”

The announcement follows two recent incidents that put the issue in the spotlight:

  • Inc. columnist Jason Aten reported that Meta’s Muse AI on his Mac appeared to know the contents of his private messages even though he had not explicitly granted the app permission to read them. Meta’s spokesperson, Andy Stone, countered that access to Messages is “entirely opt‑in” and requires both Full Disk Access and a specific Messages connector to be enabled.
  • A Wired report uncovered a flaw in the ChatGPT Mac app that could have let attackers retrieve sensitive data, underscoring the broader security challenges of desktop‑based AI.

Apple’s response is to roll out new controls that will only allow a user who genuinely wishes to grant Full Disk Access to do so after taking a clear, deliberate action. The company has not disclosed a specific launch date for the update.

Why it matters

Full Disk Access is a powerful permission originally designed to let backup utilities operate correctly on macOS. By bypassing many of the operating system’s standard privacy safeguards, the permission can give an app unfettered visibility into a user’s digital life. When AI agents are layered on top of that access, they can analyze, summarize, and potentially transmit personal data without the user’s explicit knowledge.

The incidents involving Muse and ChatGPT illustrate a new attack surface: AI agents that can read emails, messages, and files may inadvertently expose private information or be co‑opted by malicious actors. For users, the change means a higher bar to granting such access, reducing the chance of accidental data leakage. For developers, it signals that Apple will enforce stricter consent standards, potentially reshaping how AI‑enabled macOS apps are built and distributed.

The bigger picture

Apple’s tightening of Full Disk Access reflects a broader industry trend toward tighter privacy controls as AI becomes more embedded in everyday software. TechCrunch noted that the decision arrives just days after the Muse controversy, highlighting how quickly platform owners are reacting to emerging threats. The move also aligns with recent scrutiny of AI‑driven desktop applications, such as the Wired‑reported vulnerability in ChatGPT’s Mac client, which demonstrated that even well‑known AI services can contain exploitable flaws.

By requiring “very explicit user action,” Apple is attempting to make the consent process more transparent. This mirrors a shift seen across the tech sector, where companies are moving from implicit permissions to clearer, opt‑in models for data‑intensive features. The policy change could set a precedent for other operating systems that currently allow broader access to AI agents.

What happens next

Apple has said it will introduce the new controls in an upcoming macOS update, though a rollout schedule has not been provided. The company emphasized that the change is intended to help users “clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

Developers will need to adapt their applications to the new consent flow, ensuring that any request for Full Disk Access is accompanied by a clear explanation of why the permission is needed and how it will be used. Users, on the other hand, can expect a more deliberate prompt when an app seeks this level of access, reducing the likelihood of accidental permission grants.

The situation remains fluid. If additional AI‑related privacy concerns surface, Apple may further refine its policies or introduce complementary safeguards. For now, the focus is on giving Mac users a stronger say over which apps can see the entirety of their files, a step that could reshape the relationship between desktop AI agents and personal data security.