Apple is planning changes to macOS that will make it more explicit when applications, particularly increasingly autonomous artificial intelligence agents, seek broad access to data stored on a Mac. The move comes amid growing concerns over how AI agents can interact with sensitive files, messages, emails and browsing information when granted powerful system-level permissions.
Apple said it would introduce additional controls around the Full Disk Access permission, a macOS feature that allows applications to access data across a computer with the user’s approval. The company said the permission was originally designed in part to support applications such as backup services that require extensive access to files, but warned that some developers are now using it in ways that could expose users to privacy risks.
According to Apple, applications with Full Disk Access can potentially access a wide range of information stored on a Mac, including files, mail, messages and browsing history. The company said that such access can also affect the privacy of other people communicating with the user, particularly when applications are capable of processing or acting on personal information.
Apple to Require More Explicit User Consent
Apple said future versions of macOS will introduce additional safeguards to ensure that users who intentionally want to give an application this level of access take a more explicit action before doing so.
The company did not provide detailed information about how the new controls will work or when they will be introduced. However, Apple said the changes are increasingly important as AI agents become more capable of operating autonomously and performing tasks on behalf of users.
Unlike conventional applications that generally perform specific functions, AI agents can interpret instructions, access information across different services and take multiple actions with limited direct user involvement. This broader functionality has increased concerns about what could happen when such systems receive access to large amounts of personal information.
Apple said users need to clearly understand the consequences of granting such permissions so they can make informed decisions about their data and privacy.
Meta’s Muse Faces Privacy Questions
Apple’s announcement follows criticism surrounding Meta’s Muse, an AI agent designed to perform complex tasks on behalf of users. Muse can assist with activities such as managing unused subscriptions and attempting to negotiate better prices.
The controversy intensified after technology columnist Jason Aten alleged that Muse had accessed private messages on his Mac. Aten said he had not enabled Full Disk Access and questioned how the AI agent could have obtained information from his Messages application.
The allegations generated broader discussion about the privacy implications of AI agents that operate directly on personal computers and potentially interact with files, communications and other sensitive information.
Meta has disputed the characterization of the incident and said access to Apple’s Messages application through Muse is strictly optional. Meta spokesperson Andy Stone said users must enable both Full Disk Access at the macOS level and the Messages connector within Muse before the AI agent can access Messages content.
Meta has maintained that the Messages integration cannot access users’ messages without those permissions being enabled and that the access can subsequently be revoked.
Macs Offer Broader System Access Than iPhones and iPads
The issue also highlights an important difference between Apple’s desktop and mobile operating systems.
On iPhones and iPads, applications generally operate within isolated environments known as sandboxing. This prevents one application from freely accessing information belonging to another application unless Apple provides an approved mechanism for sharing that information.
macOS provides developers with greater flexibility, particularly for applications that need extensive access to a computer’s storage. Full Disk Access is one of the mechanisms that allows certain applications to operate beyond the normal privacy restrictions.
That flexibility can be useful for legitimate purposes, such as backup software and other utilities that need to examine large portions of a user’s storage. However, the same capability can create significantly greater privacy consequences when granted to software capable of independently interpreting and acting on personal information.
AI Agents Create a New Privacy Challenge
Apple’s decision reflects a wider challenge emerging as AI systems move beyond traditional chat interfaces and become capable of acting directly on users’ devices.
An AI agent with extensive system permissions could potentially process information from multiple applications and use that information while carrying out tasks. While such capabilities can make AI tools more useful, they also increase the consequences of granting excessive permissions or misunderstanding what an application can access.
Apple’s planned changes therefore appear focused on making the user’s consent more deliberate and transparent rather than eliminating Full Disk Access altogether. The company has not indicated that the permission itself will be removed, as certain applications continue to require broad access to function properly.
The company also did not specifically name Meta or Muse in its announcement. However, the timing of the announcement comes shortly after the controversy surrounding Muse and broader scrutiny of AI agents that request extensive access to personal computers.
For Mac users, the forthcoming changes are expected to place greater emphasis on ensuring that users understand exactly what they are allowing before giving applications broad access to their data.
Disclaimer: This report has been editorially prepared using publicly available information and official company statements. Readers are advised to refer to official announcements for further details.
