Apple to tighten macOS Full Disk Access controls for AI agents
Apple announced new privacy safeguards requiring explicit user action before apps gain full disk access, citing risks from increasingly autonomous AI agents.

KEY POINTS
- Apple will require explicit user action to grant Full Disk Access on macOS.
- The change addresses risks from increasingly autonomous AI agents seeking broad data access.
- Meta's Muse agent sparked the dispute after a columnist said it read his Messages without consent.
- Meta denies unauthorized access, stating Messages access requires two separate opt-in steps.
- Apple has not specified which apps will be affected or when the new controls will ship.
Apple confirmed on October 2 it will change macOS so that granting Full Disk Access requires a far more explicit user action. The setting currently allows apps to read nearly all non-root files, including messages, emails, and browsing history.
The company said some developers have begun exploiting this flexibility in ways that put users at risk, and that risks will grow substantially as AI agents become more capable and autonomous. Apple did not name specific applications or set an implementation timeline.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
The move follows a public dispute involving Meta's new Muse agent. Inc. columnist Jason Aten reported that Muse accessed his private Messages history despite his belief he had declined Messages access during setup. Meta spokesperson Andy Stone countered that Muse's Messages access is strictly opt-in, requiring both Full Disk Access and a separate Messages connector to be enabled.
Security researcher Patrick Wardle explained that Full Disk Access technically permits reading any non-root file, such as browser history, cookies, and chats. The permission was originally designed for backup utilities, but recent AI agents have sought it to operate across the file system.
Apple stated it is committed to ensuring users clearly understand the risks before granting such broad access. The company has not yet detailed the exact technical controls or their release date.
3 more sources below
COMMENTS (0)
No comments yet. Be the first.
RELATED STORIES

Pentagon Ends Use of Anthropic AI Tools After Blacklisting
The Defense Department has ceased using Anthropic products months after labeling the company a national security supply-chain risk.

Ukraine advances near Lyman with drones and robots in Operation Vivaldi
Kyiv says it captured over 250 Russian soldiers while pushing back Moscow's forces in Donetsk region.

NYC Council Hears Warnings of AI Extinction Risk as Whistleblowers Testify
Former OpenAI and Anthropic researchers tell lawmakers humanity may lose control of advanced AI, while companies decline to quantify catastrophic risk.
- US Stocks Hit Records on Weak Jobs Data, Then Retreat as Yields and Oil Surge
- Nigeria Voter Register Tops 103 Million Ahead of 2027 Elections
- Microsoft and Nvidia Launch Surface Laptop Ultra with RTX Spark Chip
- Three OpenAI Safety Researchers Fired, Allege Retaliation for Raising Concerns
- OpenAI Publishes 372 AI-Generated Math Solutions, Sparking Verification Debate
This page was compiled with AI assistance from the outlets named above and passed an automated language check before publication. Montegre has no reporters of its own; the byline names the outlets the story was compiled from. Method and editorial standards