Apple Introduces Stricter Full Disk Access Controls Amid Rising Privacy Risks from AI Agents

Reviewed byNidhi Govil

11 Sources

Share

Apple announced it will tighten macOS privacy settings for Full Disk Access after concerns emerged about AI agents accessing sensitive user data without informed consent. The decision follows a high-profile incident involving Meta's Muse AI agent and growing security concerns around desktop-based AI tools.

Apple Tightens Full Disk Access Controls to Address AI Agent Privacy Risks

Apple announced Friday it will introduce stricter controls for Full Disk Access on macOS, citing growing privacy risks from AI agents that can access sensitive user data without users' full knowledge and understanding

1

2

. The company warned that third-party app developers are misusing macOS privacy settings to access message histories, browsing history, system files, and other personal information

3

. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems -- including files, mail, messages, and even browsing history -- without users' full knowledge and understanding," Apple stated

1

.

Source: TechCrunch

Source: TechCrunch

Meta's Muse Controversy Sparks Security Concerns

The announcement comes two weeks after Inc. columnist Jason Aten reported that Meta's Muse AI agent sent him an unsolicited notification referencing a private thread between him and a co-worker over Apple Messages

1

4

. Aten claimed he never granted Muse permissions to read his messages and assumed they were off-limits. Meta CTO David Singleton responded that "the Messages integration in the Muse Mac app is opt in" and that users must manually enable both Full Disk Access and the Messages connector setting for Muse to access Apple Messages content

1

. However, macOS security expert Patrick Wardle questioned this denial, noting that "from a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc"

1

.

Growing Risks as AI Agents Become More Autonomous

Apple emphasized that as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially

2

5

. Desktop clients for AI agents like OpenClaw, Dots, and Muse often encourage users to grant Full Disk Access so the agents can access their files, messages, and other data to accomplish more tasks

5

. The feature was originally designed to allow backup apps to function properly on Mac, but it "largely sidesteps" privacy controls offered to users

3

. For communication apps, this level of data access can also compromise the privacy of the people users are communicating with, Apple warned

1

.

Source: Ars Technica

Source: Ars Technica

Apple Commits to Explicit User Action and Informed Consent

Going forward, Apple will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action

2

3

. "We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy," the company stated

4

. The timing follows a Wired report citing a flaw in ChatGPT's Mac app that could have allowed hackers to access sensitive data

2

, and comes 11 days after security researcher Patrick Wardle disclosed a Muse configuration vulnerability that allowed any app or code running on a Mac to take full control of the AI assistant

1

.

What This Means for AI Agent Users and Developers

The enhanced controls signal Apple's recognition that AI requests for Mac data require more transparent user consent mechanisms. Unlike iPhones and iPads where no single app can access data inside another app by default through sandboxing, Macs are more flexible with the Full Disk Access option

4

. This flexibility has helped fuel Mac Mini shortages this year as some users opt to use AI agents on dedicated machines to mitigate security concerns

5

. Apple did not specify when the update would roll out or detail exact changes to the current setup, but the move suggests heightened scrutiny on how third-party app developers implement AI agents on macOS. The incident also follows Amazon blocking Muse from its platform, stating that such apps "should operate openly and respect service provider decisions about whether or not to participate"

1

. Users should carefully configure permissions when using AI agents, though as recent events suggest, informed consent remains challenging when the technical implications of Full Disk Access aren't fully transparent.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved