Apple disclosed plans to embed additional user‑action requirements into macOS for applications that request Full Disk Access, a permission that grants an app sweeping visibility into a Mac’s stored data. The company said the change is intended to ensure that only users who deliberately choose to grant such extensive access can do so, and that they must do so through a clearly defined consent flow. The announcement appeared in a developer‑focused post on October 2, and Apple cited the rise of AI agents as a primary catalyst for the new safeguards.
What the new controls aim to achieve
Full Disk Access has traditionally been used to enable backup utilities to operate effectively, according to Apple. The permission allows an app to read files, mail, messages, browsing history and other data stored on the device. Apple warned that some developers have been exploiting this permission in ways that could expose a user’s entire system without the user’s full awareness. In the developer post, Apple wrote, “Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.” The statement added that communication‑focused apps could also compromise the privacy of the people users are communicating with.
Apple emphasized that the issue becomes more urgent as AI agents grow in capability and autonomy. “Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” the company said.
The Meta Muse dispute that sparked the response
The timing of Apple’s announcement follows a high‑profile dispute involving Meta’s AI agent, Muse. On September 19, Inc. columnist Jason Aten reported that Muse had synchronized his Mac Messages database to “row 187,462” even though Full Disk Access was turned off on his computer. Aten asserted, “I never gave it permission to do that.” Meta responded by denying the claim. Vice President of Communications Andy Stone clarified that Muse “can’t read your Messages unless you do this,” referring to two opt‑in settings: the macOS Full Disk Access permission and a Messages connector inside the Muse app. David Singleton, an executive at Meta Superintelligence Labs, further explained that reading Messages requires three separate permission steps across both the app and the operating system.
Muse is among several “always‑on” AI agents launched in recent weeks. OpenAI introduced its “dots” agents on September 29, which are designed to operate continuously toward user goals and can connect to more than 4,000 apps. In a separate report, Wired highlighted a vulnerability in the ChatGPT Mac app that could have allowed hackers to access sensitive data, underscoring broader concerns about AI‑driven software on personal computers.
Broader implications and regulatory context
Apple’s post did not disclose a rollout timeline, the specific macOS version that will carry the new controls, or which applications prompted the change. It also left unanswered whether apps that already possess Full Disk Access will retain it, how backup utilities—traditionally reliant on the permission—will be affected, and whether Apple’s own AI features will be subject to the same consent requirements.
The stakes are high because an AI agent with Full Disk Access could read every conversation stored on a Mac, including messages from contacts who never installed the agent or consented to its operation. This potential for inadvertent data exposure has regulatory relevance in jurisdictions such as India. The country’s Digital Personal Data Protection (DPDP) Act mandates consent from the individual whose data is processed, though the consent obligations will only become enforceable in phases beginning in 2027 under the DPDP Rules. Until those rules take effect, Apple’s consent mechanisms will dictate what AI agents on Indian users’ Macs are permitted to read.
Developers of AI agents for macOS—including Meta, OpenAI and other emerging players—will need to align their products with Apple’s forthcoming controls. At the same time, Apple has not clarified whether the same explicit consent steps will apply to its own AI capabilities that draw on user data within macOS. The lack of detail leaves open questions about parity between third‑party and first‑party AI services on the platform.
In summary, Apple is moving to introduce stricter, user‑driven consent flows for Full Disk Access in macOS, citing the expanding risk landscape created by sophisticated AI agents. The policy shift follows a public dispute with Meta over the Muse agent’s alleged access to Messages data, and it arrives amid broader industry scrutiny of AI‑related privacy vulnerabilities. While the exact implementation schedule remains unknown, the announcement signals Apple’s intent to place greater control of sensitive data in the hands of end users as AI agents become more pervasive on personal computers.






Be First to Comment