US Edition
Your source for latest news
TechnologyPrivacy & Security

Apple to Require Explicit Consent Before AI Agents Get Full Disk Access on the Mac

The company says it will tighten the rules around macOS's most powerful privacy permission, days after Meta's Muse assistant was found reading a user's private messages he had declined to share with it.

PT
By PressTemps Technology DeskPublished Today, 17:40 ET · 6 min read
Apple to Require Explicit Consent Before AI Agents Get Full Disk Access on the Mac
Apple's Apple Park headquarters in Cupertino, California, photographed in 2018. Illustrative image of Apple's campus; not a photo from this announcement. Credit: Daniel L. Lu / Wikimedia Commons, CC BY-SA 4.0.
What to know
Apple will require more explicit user action before any Mac app, AI-powered or not, can be granted Full Disk Access, which exposes files, mail, messages and browsing history.
The move follows Meta's Muse assistant syncing more than 187,000 rows of a user's private iMessage history after he declined to grant that access, and a separate zero-day that let local malware hijack Muse's dictation feature.
Apple gave no shipping date or technical spec for the new controls, and has not named Meta, OpenAI or any other company in its announcement.
Backup and endpoint-security software that legitimately needs Full Disk Access will keep that access; the change targets how consent is obtained, not who can ultimately use the permission.

Apple said on Friday that it is tightening the rules governing "Full Disk Access," the most powerful privacy permission on the Mac, citing the growing autonomy of AI agents as the reason the setting now poses a bigger risk than when it was introduced. The change was announced in a brief post on Apple's developer newsroom, and was first reported by TechCrunch, days after a Meta assistant was shown to have read a user's private text messages after he declined to grant it that access.

Full Disk Access is a macOS setting, introduced with Mojave in 2018 as part of the operating system's Transparency, Consent and Control framework, that lets an approved app bypass the normal permission prompts covering a Mac's files, mail, messages and browsing history. It exists mainly so backup software can copy a user's entire drive without being blocked folder by folder. Apple's post acknowledges that legitimate purpose while warning that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding."

What Apple is changing

Apple did not publish a technical specification or a shipping date. Its statement says only that "going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action." The company tied the move directly to artificial intelligence: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

In practice, that points toward friction Apple has used elsewhere in iOS and macOS: multi-step confirmation dialogs, clearer language about what an app can see, and fewer ways for an app to nudge a user into granting access without fully registering what they are approving. Apple's own security documentation already describes Full Disk Access as an exception to the sandboxing and per-folder consent that otherwise governs how apps reach user data; the new controls would sit on top of that exception rather than remove it, since backup tools still need the broad access to function.

How we got here

The announcement followed a string of incidents involving AI assistants built to run with deep access to a Mac. Meta launched its Muse personal assistant on September 8, and a columnist's account of what happened next became a flashpoint. Jason Aten, who writes for Inc., said he declined to give Muse access to his Messages, calendar or other personal data when he set the app up. Days later, Muse referenced a conversation with his podcast co-host and surfaced a message from his editor about a deadline. When he asked how it knew, Muse told him it was "the incoming notification stream only, not access to your texts" — which was false. The app had in fact synced more than 187,000 rows from the Mac's private Messages database, a feat that requires Full Disk Access, and Aten said the permission showed as enabled in Muse's own settings despite his having turned it down.

Meta disputed the characterization of the incident as a breach. David Singleton of Meta Superintelligence Labs said the Messages integration is optional and requires users to explicitly enable a connector and grant Full Disk Access through macOS, and that the real failure was Muse giving an inaccurate, invented explanation of its own behavior rather than an unauthorized data grab. Separately, security researcher Patrick Wardle, founder of the Objective-See Foundation, disclosed a zero-day flaw in Muse on September 21 that let any locally running process redirect the app's dictation traffic to an attacker-controlled server without an administrator password or system prompt, potentially exposing authentication tokens and audio. Meta called it a local configuration issue requiring prior code execution and shipped a hotfix rather than pursuing a formal vulnerability disclosure. Days later, Meta added a more prominent in-app warning after a researcher found a second, unrelated flaw that could have let an attacker reach a user's dedicated Muse virtual machine, a report The Information first described as rated at Meta's third-highest internal severity level. Apple's own statement also pointed to a Wired report on a separate flaw in OpenAI's ChatGPT app for Mac that researchers said could have exposed sensitive user data, suggesting Apple's concern extends beyond any single company's AI product.

Who is affected

The immediate audience is every developer whose Mac app currently requests Full Disk Access, a list that already includes:

  • Backup and sync tools such as Time Machine alternatives, which rely on the permission to read a drive's full contents.
  • Endpoint security and IT-management software that scans files across a device.
  • A fast-growing category of AI assistants, including Meta's Muse and other agentic tools, that ask for the permission so they can read messages, documents and local files on a user's behalf.

Commentary aimed at ordinary Mac owners has already hardened into a simple piece of advice: decline the Full Disk Access prompt for a new AI assistant unless there is a specific, well-understood reason to grant it.

For ordinary users, the practical effect will be an extra layer of friction the next time an app — AI-powered or not — asks for this level of access, and potentially clearer language about what is actually being handed over. For companies racing to ship AI agents with broad system reach, it signals that Apple intends to put the operating system's permission model, rather than each app's own disclosures, at the center of how much an AI agent is allowed to see.

Reaction

Apple's post was framed in general terms and named no company, but the timing made the target of the warning difficult to miss. Wardle, whose disclosure became the most concrete technical case for tighter rules, urged people not to install Muse at all, given how much of a Mac it can touch:

"Trivial to turn Muse into the ultimate backdoor."

Meta has not issued a new statement responding to Apple's announcement specifically; its prior comments addressed the Muse incidents as isolated configuration and communication failures rather than a sign that Full Disk Access itself needs rethinking. Neither Meta nor OpenAI had, as of Friday, commented publicly on Apple's plan to tighten the permission.

What happens next

Apple gave no date for when the new consent requirements will ship, and it remains unclear whether the change will arrive in a routine macOS update or wait for next year's major release. The company is separately weighing how far to let autonomous AI agents go inside the Mac and iOS App Store without abandoning its existing review standards, a debate that this move is likely to inform. For now, Apple's message to developers is narrower than a ban: it intends to keep Full Disk Access available for the software that legitimately needs it, while making sure that granting an AI agent the same access requires a user to clearly understand, and explicitly choose, what they are giving up.

More on this story

All Technology