Apple announced Friday it is tightening controls around the "Full Disk Access" (FDA) permission in macOS, citing new risks posed by increasingly capable artificial intelligence (AI) agents, according to TechCrunch and Ars Technica.
The company stated that broad access to users' files, messages, mail, and browsing history has become riskier due to these AI agents. Apple plans to introduce new controls to ensure that users who wish to grant an application this "extraordinary level of access" can do so only with "very explicit user action," TechCrunch reported.
Details of the Changes
Full Disk Access is a macOS setting designed to allow functions like backups to operate correctly. However, AI agents running on the desktop can leverage this setting to gain extensive access to personal content on a user's computer, including files, messages, mail, and browsing history, according to TechCrunch.
In a blog post aimed at developers, Apple stated:
Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
The company emphasized the growing risks associated with such access as AI agents become more capable and autonomous. Apple said it is "committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy," TechCrunch and Ars Technica reported.
Background and Recent Incidents
Friday's announcement follows recent concerns regarding AI agents' access to private user data.
Meta's Muse App and Private Messages
The decision comes weeks after Inc. columnist Jason Aten reported that Meta's Muse app, a general-purpose AI agent, appeared to have accessed the content of his private messages on Mac. Aten stated he had not granted the AI agent permission to do so and had assumed his messages were off-limits, according to TechCrunch and Ars Technica. This report led to a significant social media discussion about the security of desktop-based AI and their access to sensitive information, Ars Technica noted.
Meta's CTO, David Singleton, responded to the claims, stating that for Muse to access Apple Messages, a user must manually enable two privileges:
- macOS system-level Full Disk Access.
- A Messages connector setting within Muse.
Singleton was quoted by Ars Technica as saying: "The Messages integration in the Muse Mac app is opt in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled."
However, macOS security expert Patrick Wardle questioned Singleton's denial, telling Ars Technica that "From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc." Apple's recent statements appear to contradict Meta's position that Muse cannot read Messages content without the connector enabled, Ars Technica reported. Apple did not specifically name Meta, Muse, or any other app in its announcement, according to Ars Technica.
Other Related Concerns
The decision to limit the Mac feature also follows a Wired report that cited a flaw in ChatGPT's Mac app, which could have allowed hackers to access sensitive data, TechCrunch reported.
Additionally, 11 days prior to Apple's announcement, Wardle disclosed a Muse configuration that could allow any app or code running on a Mac to take full control of the AI assistant, potentially accessing the same resources Muse could, Ars Technica reported. Amazon also blocked Muse from its platform, stating that such apps "should operate openly and respect service provider decisions about whether or not to participate," according to Ars Technica.
Implications for Users and Developers
The events leading to Apple's announcement highlight the increasing scrutiny on desktop AI agents and their ability to access sensitive user data. While such tools can be useful, they can also pose risks if not managed carefully, Ars Technica noted.
The upcoming changes are expected to require users to take more deliberate steps when granting applications broad system access. Ars Technica suggested that users of AI assistants should configure permissions carefully, though Aten's experience indicates such precautions may have limitations.






