SAN FRANCISCO, UNITED STATES — Apple plans stronger Mac controls after AI agents raised concerns over broad access to messages, files, mail...
SAN FRANCISCO, UNITED STATES — Apple plans stronger Mac controls after AI agents raised concerns over broad access to messages, files, mail and browsing data via existing Full Disk Access permissions.
Apple is preparing additional safeguards around one of macOS's most powerful privacy permissions, responding to a new problem created by artificial intelligence agents that can do far more with a computer's data than conventional applications.
The company said on October 2 that it intends to introduce additional controls around Full Disk Access, a Mac permission capable of giving software unusually broad visibility into information stored on a computer. Apple's announcement specifically warned that the consequences of granting such access are becoming more significant as AI agents grow more capable and autonomous.
The change does not amount to a general ban on AI agents accessing Mac data. Instead, Apple says users who genuinely want to grant an application this level of access will have to take more explicit action, with the aim of making the consequences clearer before permission is given.
The announcement comes amid scrutiny of Meta's Muse personal AI agent and a dispute over whether users sufficiently understood the data the software could reach. Meta has rejected claims that Muse secretly bypassed user permissions, leaving the controversy centred not only on whether permission technically existed but also on whether users understood what that permission enabled.
Full Disk Access can expose far more than ordinary app data
The significance of Apple's announcement lies in what Full Disk Access was designed to do.
Modern operating systems normally prevent applications from freely examining information belonging to other applications. Apple's security architecture applies multiple restrictions to files and sensitive resources, requiring users to authorise access in circumstances where software needs information that would otherwise be protected.
Full Disk Access is an unusually powerful exception.
Apple says the capability largely bypasses normal privacy controls so that applications such as backup utilities can perform tasks that require comprehensive access to a Mac. Once such permission is available, however, an application may potentially reach files, email, messages and browsing history that would ordinarily sit behind separate protections.
That distinction becomes especially important with an AI agent. Traditional backup software may need extensive read access because its function is to copy or preserve data. An autonomous agent may instead analyse information, connect it with other data, make decisions and perform actions on a user's behalf.
The permission therefore remains technically similar while the capability of the software receiving it has changed substantially.
Apple acknowledged that difference directly in its developer announcement, saying risks associated with this degree of access will grow as AI agents become increasingly capable and autonomous.
Why Mac permissions differ from the tighter mobile model
Apple's response also highlights an important architectural difference between Macs and the company's mobile devices.
On iPhones and iPads, applications operate under extensive sandboxing restrictions. An app generally cannot simply inspect another application's private data store. Access to sensitive categories of information is mediated through system controls and specialised permissions.
macOS also uses sandboxing and privacy controls, but the Mac has historically offered greater flexibility because desktop applications perform a wider variety of professional, administrative and system-level tasks.
Apple's security documentation says that applications requiring access to the entire storage device have needed explicit authorisation since macOS 10.13. Later versions of macOS expanded consent requirements for protected locations including Desktop, Documents, Downloads, iCloud Drive and network volumes.
Full Disk Access nevertheless creates a deliberate route around many of those restrictions.
This arrangement made practical sense for software that genuinely required comprehensive disk access. AI agents complicate that model because a single broad permission can potentially expose information from several parts of a person's digital life to software capable of interpreting that information rather than merely storing or copying it.
The emerging security question is consequently about both access and capability: what information can an application reach, and what can it infer or do once it reaches it?
Muse dispute puts informed consent under scrutiny
The immediate controversy involves Muse, the personal AI agent Meta introduced in September.
Meta describes Muse as a personal agent capable of proactively assisting users with goals and carrying out tasks. The company says the service can handle activities ranging from sending emails and booking travel to more complicated agentic work, with its processing built around a dedicated secure virtual-machine architecture.
Those capabilities require connections to services and personal information if the agent is to act on a user's behalf.
A technology journalist subsequently alleged that Muse referred to information from private messages that he did not believe he had authorised the agent to read. The episode triggered questions about how the application obtained that information and what users should reasonably understand when enabling broad system permissions.
Meta disputes the suggestion that Muse simply accessed messages without authorisation. The company has said access requires permissions enabled by the user, including relevant Mac and Muse controls.
The disagreement illustrates a distinction that will become increasingly important as personal AI develops: technical permission and informed consent are not necessarily identical concepts.
A user may click a system control that legally and technically authorises access while still failing to appreciate the range of information exposed by that decision. Conversely, an application's ability to reach information after a user enables an explicitly described permission does not by itself establish that the software circumvented the operating system.
Apple has not publicly resolved the factual disagreement between Meta and its critic. Its announcement instead addresses the operating-system layer, where it can change how extraordinary access is granted in the first place.
Apple's answer is an extra consent barrier, not an AI prohibition
Apple's wording indicates that Full Disk Access will remain available.
That matters for developers whose applications have legitimate reasons to use it. Backup utilities, security tools and other specialised software can depend on broad storage access to perform their intended functions.
Rather than eliminating the permission, Apple says it will add controls requiring "very explicit user action" before an application receives it.
The company has not yet detailed the complete interface, implementation or release timetable for the new controls. It is therefore premature to assume exactly what the additional warning will look like, whether AI applications will receive a distinct treatment, or whether developers will face new technical requirements beyond the user-consent process.
What Apple has established is the principle: access powerful enough to reveal much of a person's digital activity should require a decision proportionate to that power.
For Mac users, that makes the Full Disk Access list increasingly important. The relevant question is no longer simply whether an application is trusted in a conventional malware sense. Users also need to consider whether its normal function genuinely requires visibility into such a broad range of personal information.
AI agents change the consequences of a familiar permission
The wider issue extends beyond Apple and Meta.
AI assistants are evolving from systems that respond to prompts into agents designed to complete tasks. To book travel, organise communications, negotiate purchases, manage subscriptions or coordinate schedules, an agent may need access to multiple applications and accounts.
That access can make the software substantially more useful. It can also combine information that previously remained separated across email, messaging, browsers, files and online services.
The privacy implications are therefore cumulative.
An individual email, document or browser entry may reveal relatively little in isolation. An agent able to examine many categories simultaneously can potentially establish relationships among them, identify patterns and use those conclusions when performing future actions.
This is why permission design is becoming part of the AI infrastructure itself. Security controls built for conventional desktop applications may technically continue to work while becoming harder for ordinary users to evaluate when the application requesting access is capable of reasoning across everything it sees.
Apple's planned change represents an attempt to narrow that comprehension gap before the software receives access rather than relying entirely on restrictions after the permission has already been granted.
What Mac users can check before the new safeguards arrive
Users do not have to wait for Apple's forthcoming changes to review existing permissions.
Current versions of macOS provide privacy controls in System Settings where users can see applications authorised for Full Disk Access. Because this permission is unusually broad, users can review whether each listed application still requires it and whether they recognise and trust the software involved.
Removing access can affect an application's functionality, particularly for software designed to back up, scan or manage files. Permission changes should therefore be considered in relation to what the application is expected to do rather than treated as an instruction to disable every entry.
AI agents deserve the same scrutiny, but with an additional question: whether the value of allowing the agent to reason over extensive personal information justifies the breadth of access being requested.
Users should also distinguish operating-system permissions from connectors or authorisations configured inside an AI service. An application may require more than one layer of permission to reach a particular source of information, and disabling one connection does not necessarily describe the status of every other permission.
The Muse dispute demonstrates why those layers need to be understandable rather than merely technically available.
The next privacy battle is about understanding what an agent can do
Apple's decision is an early example of operating-system security adapting to agentic AI rather than treating AI applications exactly like the software that came before them.
Full Disk Access existed long before today's generation of autonomous agents. The permission was built to solve legitimate desktop-computing problems, particularly for applications that cannot function inside narrower boundaries.
What has changed is the power of the software that can sit behind that permission.
An AI agent may be capable of interpreting messages, identifying relationships, combining files with browsing information and taking actions using the resulting context. That makes a single consent decision potentially more consequential than users accustomed to ordinary application permissions may expect.
Apple has yet to disclose the precise design or timing of its additional controls, so their effectiveness cannot yet be assessed. But the direction is clear: as agents gain more authority to act on behalf of people, operating systems are beginning to demand clearer decisions about the information those agents are allowed to see.
For Mac users, the practical principle remains straightforward. Broad access should be granted deliberately, understood before it is enabled and limited to software whose need for that access matches the task it is being trusted to perform.

COMMENTS