Apple changes full-disk access permissions to curb abuse from AI agents
Source Entity
Dan Goodin

Apple is updating macOS 'Full Disk Access' permissions to mitigate privacy risks posed by increasingly intrusive AI agents. This move follows reports that Meta's Muse app allegedly accessed private messages without explicit user consent.
Apple Tightens macOS Security Amid AI Privacy Concerns
Apple has announced significant changes to the 'Full Disk Access' (FDA) permission settings within macOS, citing the escalating risks posed by modern AI agents. Historically, this permission was designed to assist system utilities—such as backup software—in accessing files across the operating system to ensure data integrity. However, as AI tools evolve to become more integrated into the desktop experience, Apple has identified that this broad level of access creates a potential vector for privacy intrusions that the original security framework was not built to manage.
The Catalyst: The Muse AI Controversy
The policy shift follows a high-profile incident involving the Meta-developed AI agent, Muse. Tech columnist Jason Aten reported that the tool referenced private message content in an unsolicited notification, despite Aten asserting that he had never granted the application permission to read his communications. While Meta has disputed these claims, the incident sparked a broader conversation regarding the 'black box' nature of AI agents and the extent to which they can operate behind the scenes of a user's operating system.
Redefining 'Full Disk Access'
Apple’s updated stance emphasizes that the current FDA framework is no longer sufficient to protect user data from sophisticated AI behaviors. The company intends to implement more stringent controls, ensuring that if a user decides to grant an application such extensive power, it must be through an incredibly explicit and unambiguous action. By creating these friction points, Apple aims to prevent third-party developers from misusing system permissions to scrape sensitive data like email, message histories, and browsing logs without the user's informed consent.
Broader Implications for AI Development
The incident highlights a growing tension between the utility of AI agents and the fundamental right to digital privacy. Many observers have compared AI assistants to high-powered tools, noting that while they offer immense productivity benefits, their ability to interface with personal data necessitates a higher standard of 'guardrails.' As these agents gain the ability to control system processes, the industry is forced to reconsider whether existing permission models—designed for static applications—are adequate for dynamic, autonomous software.
Future Trends in Operating System Security
Looking ahead, we can expect a shift toward more granular permission models. Instead of 'all or nothing' access, operating systems will likely move toward context-aware permissions that limit AI access to specific folders or time-bound sessions. Apple’s intervention serves as a bellwether for the tech industry, signaling that developers of AI agents will face increased scrutiny regarding how their software gathers information. This move likely marks the beginning of a new era where platform providers prioritize 'privacy-by-design' to combat the risks inherent in deep-learning integration.
Conclusion
Ultimately, Apple’s decision to limit Full Disk Access is a reactionary but necessary step in the ongoing battle for user privacy. By forcing developers to be more transparent and intentional about how their AI agents interact with personal files, Apple is setting a new precedent for the desktop ecosystem. As AI continues to integrate deeper into our digital lives, the responsibility for securing these systems will rest not only on the developers but on the platform architects who define the boundaries of digital access.