Apple is tightening macOS privacy controls by requiring explicit user action to grant apps Full Disk Access,
a move aimed at curbing risks from AI agents that could access sensitive data like messages, browsing history, and files.
The change comes as AI agents, such as Meta’s Muse, grow more capable and raise concerns about data exposure.
Why Apple Is Restricting Full Disk Access
Apple cited the rising risks of AI agents misusing data access, warning that developers are using Full Disk Access
in ways that could expose users to privacy breaches. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,
the company stated in a blog post.
The move follows reports that Meta’s Muse AI assistant accessed private messages on a user’s Mac without their explicit consent. Technology columnist Jason Aten claimed Muse referenced a conversation with a colleague via Apple Messages, despite not granting the app access. Meta disputed the claim, saying Muse requires both Full Disk Access
and an enabled Messages connector
to read messages.
Technical Risks and Developer Concerns
Security experts raised alarms about the technical implications of Full Disk Access. Patrick Wardle, a macOS security researcher, noted that with this permission, any (non-root file), is readable, browsing history, browser cookies, chats, etc.
Apple acknowledged these risks, stating that some developers are using the feature in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.
Meta’s CTO, David Singleton, defended the company’s approach, emphasizing that Muse’s Messages integration is “opt-in” and requires users to manually enable both Full Disk Access and the Messages connector.
Implications for AI and Privacy
Apple’s update aligns with broader industry concerns about AI agents’ growing autonomy. The company’s guidance highlights that communication apps with Full Disk Access could compromise the privacy of people users are messaging. For communication apps, this can also compromise the privacy of the people users are communicating with,
Apple warned.

The changes also intersect with Apple’s ongoing efforts to limit data harvesting. In September 2026, the company blocked The Trade Desk from accessing content across its devices, citing a “hard block” on domains tied to post-cookie tracking. This move, reported by MediaPost, indicates Apple’s broader strategy to restrict third-party data access.
What’s Next for Users and Developers
Apple’s update will require users to explicitly confirm requests for Full Disk Access, making it harder for apps to bypass privacy controls. The company emphasized that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.
For developers, the shift signals a tighter regulatory environment. Apps relying on Full Disk Access, such as backup tools or AI assistants, will need to justify their data requests more rigorously. Meanwhile, users are urged to scrutinize app permissions, especially as AI agents become more integrated into daily workflows.
The full impact of Apple’s changes is not yet clear, but the move reflects a growing tension between innovation and privacy. As AI agents evolve, the balance between functionality and security will continue to shape the tech landscape.