Press "Enter" to skip to content

Apple to tighten macOS Full Disk Access amid AI agent privacy concerns

Apple is set to modify its macOS operating system to make it more transparent when artificial‑intelligence (AI) agents request the highest level of data access on a Mac. The change follows criticism of Meta’s Muse AI agent, which some users say accessed private messages and other personal information without clear permission.

Background on Full Disk Access on Macs

Unlike iPhones and iPads, where apps are sandboxed and cannot read data inside another app by default, macOS offers a “Full Disk Access” option. This permission lets applications—such as cloud backup services—read virtually every file on a machine, provided the user explicitly grants it. Apple’s developer documentation notes that the feature is intended for legitimate backup and system‑level tasks, but it also opens a pathway for apps to reach into files, mail, messages, browsing history and other sensitive data.

In a recent update posted on Apple’s developer website, the company warned that some developers were exploiting Full Disk Access in ways that could jeopardize user privacy. Apple wrote, “Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.” The statement emphasized that as AI agents become more capable and autonomous, the risks associated with unrestricted disk access will increase substantially.

Incidents involving Meta’s Muse AI agent

The push for tighter controls was sparked by public complaints about Meta’s Muse, an AI agent designed to assist users on macOS. A technology columnist for Inc magazine described an experience where Muse appeared to read private messages on his Mac despite his explicit decision not to grant such access. The writer said he had not enabled Full Disk Access and that, when he asked Muse how it obtained the information, the AI responded that it was syncing his “device notifications.”

A separate account came from YouTuber Matt Robb, who reported that Muse mishandled a task involving a sale on Facebook Marketplace, inadvertently exposing his home address. Both incidents raised questions about whether Muse was obtaining data through legitimate opt‑in mechanisms or exploiting broader permissions.

Meta’s spokesperson Andy Stone responded on the social‑media platform X, asserting that Muse’s ability to read the Messages app is strictly opt‑in. Stone wrote, “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can’t read your Messages unless you do this. And it can be revoked at any time.” The clarification underscores the dual‑permission model that Apple requires for any app to access Messages content on macOS.

Apple’s proposed safeguards

Apple’s full statement on the upcoming changes reiterates the company’s commitment to protecting user data while still providing developers with powerful APIs. The statement notes that Full Disk Access “largely sidesteps” the usual privacy controls that protect user information, a design choice that enables backup utilities to function correctly. However, the company acknowledges that “some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.”

For communication apps, the risk extends beyond the device owner to the privacy of contacts and conversation partners. Apple warned that unrestricted access could compromise the confidentiality of people with whom users are communicating, highlighting a broader ecosystem impact.

To address these concerns, Apple plans to roll out “additional controls” that will require “very explicit user action” before an app can be granted Full Disk Access. While the exact technical implementation has not been disclosed, the language suggests a more granular permission prompt, possibly with clearer labeling of the data categories that will be exposed.

The company’s stance aligns with a growing industry focus on AI governance and data protection. As AI agents become more autonomous—capable of initiating actions, retrieving information, and interacting with third‑party services—the potential for unintended data exposure rises. Apple’s move signals an effort to balance innovation with the privacy expectations of its macOS user base.

Stakeholders, including developers of backup services and communication tools, will need to adapt to the new requirements. Apple’s developer portal is expected to provide guidance on how to request the revised permissions and how to design user interfaces that convey the scope of access in plain language.

Overall, the upcoming macOS changes aim to give users clearer insight into when an AI agent—or any app—asks for the ability to read all data on their Mac. By tightening the consent process, Apple hopes to prevent situations like those reported with Meta’s Muse, ensuring that users retain control over their personal information while still benefiting from advanced AI capabilities.

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *