Apple tightens Mac privacy controls as AI agents raise data access concerns

As AI agents become more autonomous, the risks grow substantially
Apple's statement explaining why it is tightening controls on data access for artificial intelligence applications on Macs.
Mark

So Apple is basically saying the current system isn't clear enough about what these AI apps can actually see?

Mimi

Right. On Macs, there's this Full Disk Access permission that lets apps read everything on your computer. It was designed for things like backup services, but now AI agents want it too.

Luke

But here's the thing—Meta says you have to opt in twice. So how much of this is a real problem versus a perception problem?

Mimi

That's fair. The Aten incident is the only concrete example we have, and Meta's explanation seems plausible. But Apple's point is that as these agents get smarter and more autonomous, the risk grows even if the permission structure is technically sound.

Mark

So Apple isn't saying Muse did anything wrong necessarily?

Mimi

Not explicitly. They're saying some developers are using Full Disk Access in risky ways, and they want to make the stakes clearer before users click yes.

Luke

The question is whether "clearer warnings" actually changes behavior. People ignore warnings all the time.

Mimi

True. But at least it shifts the burden—users can't claim they didn't understand what they were allowing.

Mark

When will these new controls actually show up?

Mimi

Apple didn't say. They just announced the intention.

Luke

So we're watching a policy response to a complaint that may or may not reflect a real vulnerability. That's worth noting.

Mark

And Meta's position is that their system already requires explicit consent?

Mimi

Yes, twice over. But they also didn't deny that Full Disk Access, if granted, would let Muse read your messages.

  • A technology columnist's claim that Meta's Muse AI agent read his private messages without permission ignited a sharp public debate about what AI assistants can silently access on personal computers.
  • Meta pushed back firmly, insisting Muse requires two deliberate user steps — enabling Full Disk Access and activating a Messages connector — before any private conversation can be reached.
  • The dispute exposed a structural gap: iPhones sandbox apps tightly, but Macs offer a sweeping Full Disk Access permission that was designed for backup tools, not autonomous AI agents capable of acting on what they find.
  • Apple declared on October 2 that some developers are already exploiting this permission in ways that endanger users, and warned the risks will grow substantially as AI systems become more independent.
  • The company committed to introducing clearer warnings and stronger controls before users grant broad access — though it has not yet said exactly what those controls will look like or when they will arrive.

As artificial intelligence agents grow capable enough to cancel subscriptions, negotiate bills, and read the full contents of a hard drive, the question of who truly controls a personal computer has become urgent. Apple's announcement on October 2 that it will redesign how Macs handle broad data-access requests reflects a quiet reckoning: the permissions architecture built for backup utilities was never meant for autonomous minds. The episode involving Meta's Muse assistant and a journalist's private messages has made visible a tension that will define the next era of personal computing — between the power we grant our tools and the privacy we assume we still hold.

Apple announced on October 2 that it will overhaul how its Mac operating system handles requests from AI applications seeking broad access to user data, introducing more explicit warnings when apps ask for what the company calls Full Disk Access — permission to read everything stored on a machine.

The announcement was a direct response to controversy surrounding Meta's Muse, an AI assistant built to handle complex tasks like canceling subscriptions or negotiating better service prices. Technology columnist Jason Aten accused Muse of reading his private messages without his knowledge, saying he had never granted the app Full Disk Access. Meta disputed this, with spokesperson Andy Stone explaining that Muse requires two separate user actions — enabling Full Disk Access and then activating a Messages connector inside the app — before it can reach any messages at all.

The disagreement laid bare a meaningful difference in how Apple's own platforms work. iPhones and iPads use sandboxing to prevent apps from reaching each other's data without explicit permission. Macs, by contrast, offer Full Disk Access as a broad, sweeping option that cloud backup services and utilities have long relied upon — but which carries different implications when placed in the hands of an autonomous AI agent.

Apple's statement acknowledged that some developers were already using Full Disk Access in ways that could put users at risk, and warned that as AI agents grow more capable and independent, those risks will expand. The company pledged to ensure users genuinely understand what they are permitting before granting such access. The precise shape of the new controls, and when they will arrive, remains unspecified — but the direction is clear: the design of operating systems is now being shaped, in real time, by the arrival of AI that can act on what it reads.

Apple announced on October 2 that it will overhaul how its Mac operating system handles requests from artificial intelligence applications seeking broad access to user data. The company plans to introduce more explicit warnings and controls when apps ask for what Apple calls "Full Disk Access"—permission to read everything stored on a machine.

The move responds directly to a growing tension between the capabilities AI agents need to function and the privacy risks those capabilities create. Meta's Muse, an AI assistant designed to handle complex tasks like canceling subscriptions or negotiating better prices on services, became the flashpoint for this debate. Technology columnist Jason Aten, writing for Inc magazine, accused Muse of reading his private messages without his knowledge. He stated he had not granted the app Full Disk Access permission.

Meta disputed the characterization. Andy Stone, a Meta spokesperson, clarified on social media that Muse cannot access the Messages app without two separate steps: a user must enable Full Disk Access, and then separately activate a Messages connector within Muse itself. "It can't read your Messages unless you do this," Stone wrote, noting the permission can be revoked at any time.

The distinction matters because it reveals how differently Apple's platforms handle app permissions. On iPhones and iPads, Apple uses a technique called sandboxing, which prevents any single app from accessing data stored inside another app unless the user explicitly allows it. Macs work differently. They offer a Full Disk Access option that grants apps sweeping permission to read all files on the machine—a flexibility that cloud backup services and other utilities have long relied on, but which poses risks when granted to autonomous AI agents.

Apple's response signals concern about how this feature might be misused as AI systems become more capable and independent. In its October 2 statement, the company wrote that some developers were already using Full Disk Access in ways that could endanger users. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple stated. The company committed to ensuring users understand what they are permitting before granting such broad access, allowing them to make informed choices about their own information.

The practical effect of Apple's planned changes remains to be seen. The company did not specify exactly how the new controls would work or when they would arrive. Meta did not respond to requests for comment beyond Stone's earlier statement. What is clear is that the tension between AI capability and user privacy is no longer theoretical—it is shaping how operating systems will be designed going forward.

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.
— Apple, in statement on October 2
You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can't read your Messages unless you do this.
— Andy Stone, Meta spokesperson, on social media
Envie de l'histoire complète ? Lire l'original sur The Straits Times ↗
Nous contacter FAQ