Key Highlights

  • Apple's move: Apple will require clearer, more deliberate user approval before apps can get Full Disk Access on Mac.
  • The trigger: AI agent apps, including Meta's Muse, raised concerns after accessing users' private data.
  • The core problem: Full Disk Access was meant for backup tools but largely bypasses Apple's usual privacy controls.
  • Wider risk: Apple warned that risks will grow as AI agents become more capable and autonomous.

Apple has said it will tighten controls around Full Disk Access on Mac computers, after a wave of AI agent apps raised concerns by reaching into users' private data.

Full Disk Access is a powerful permission that lets an app read almost everything on a Mac, from files to messages. It was originally designed for backup and system utilities. Apple said it will now introduce more explicit prompts, so users must take a clear, deliberate action before granting it, and will be asked specifically which parts of their system an app can access.

What Apple Said

"We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users' private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac," Apple said.

The company said some developers are using the permission in ways that expose everything on users' systems without their full understanding. "For communication apps, this can also compromise the privacy of the people users are communicating with," it added.

The Muse Controversy

The concerns centre on agentic apps such as Meta's Muse. Meta launched Muse on September 8 as a personal AI agent that takes actions rather than only answering questions. Its Mac app, released later, can work with files, Mail, Messages, Calendar and Notes.

Shortly after launch, tech journalist Jason Aten reported that Muse synced roughly 187,000 lines from his Mac's Apple Messages database even though Full Disk Access was disabled. When asked, the assistant said it was only relaying notification previews, and Meta has not answered his questions about the discrepancy. Meta has attributed some reported privacy issues to a bug.

According to IANS, Muse has crossed 5 million downloads.

Why It Matters: Agents Change the Privacy Equation

A traditional app usually does one job with the data it is given. An AI agent is built to look across everything it can reach and act on it. That makes broad permissions like Full Disk Access far riskier, because a single "yes" can hand an agent access to years of messages, documents and personal records.

Apple's point about communication apps is especially important. When an agent reads your chats, it also reads the words of everyone you talk to, people who never agreed to share their data with that app.

What Mac Users Can Do Now

  • Open System Settings > Privacy & Security > Full Disk Access to see which apps already have this permission.
  • Turn it off for any app that does not clearly need it, especially AI agents and chat tools.
  • Grant access only to trusted backup or security tools that require it.

The Bottom Line

As AI agents move from chatting to acting, the permissions we grant them matter more than ever. Apple's tighter prompts are a step towards making sure users understand exactly what they are handing over before an agent starts digging through their data.

With inputs from IANS.