As artificial intelligence agents grow more capable of acting on our behalf, the question of what they are permitted to see on our behalf becomes urgent. Apple has announced plans to redesign how its Mac operating system handles requests for sweeping data access, requiring users to make a deliberate, informed choice before AI agents can read their files, messages, and browsing history. The move comes amid real-world friction — including a disputed incident involving Meta's Muse AI — that has exposed the gap between what users believe they have consented to and what applications may actually be
Apple Tightens Mac Security Against AI Agents Accessing User Data
Users need to understand what they're actually allowing before they authorize it.
So Apple is basically saying that current permission systems aren't working for AI agents. What's the actual problem they're trying to solve?
The problem is that Full Disk Access is a blunt instrument. An app can ask for it, a user clicks yes, and suddenly that app can read everything—emails, messages, files, browsing history. With traditional apps, that's risky enough. But with AI agents that are autonomous and increasingly capable, the risk multiplies. An agent could theoretically act on that data without the user even knowing what it's doing.
But here's what I want to know: how many users have actually been harmed by this? We have one allegation from Jason Aten about Meta's Muse, and Meta says he's wrong. Are there other documented cases, or is Apple being proactive based on a theoretical threat?
That's fair. The Aten case is the public incident we know about. Apple seems to be treating it as a canary in the coal mine—a sign that as these agents get smarter, the problem will get worse. They're not waiting for a major breach.
What does "explicit user action" actually mean, though? Isn't clicking a permission prompt already explicit?
Apparently not explicit enough. Apple wants something that forces real deliberation—maybe a confirmation step, maybe language that's much clearer about what the agent can actually do. Right now, users might not understand that granting Full Disk Access means the agent can read their private messages.
And here's the thing: Apple hasn't said what the new controls will look like. They've announced the problem and the direction, but not the solution. So we don't know if this will actually work or if it'll just add friction without changing behavior.
Meta says Muse requires both Full Disk Access and a separate Messages connector. Doesn't that already create a second step?
It does, but apparently it wasn't enough to stop Aten from feeling surprised. Maybe the messaging around it wasn't clear. Or maybe users enable things without fully reading what they're enabling.
That's the real question: is this a problem with the permission system, or a problem with how users read and understand permissions? Because if it's the latter, a new control might not fix it.
What happens to developers who genuinely need broad access to build useful AI agents?
That's the tension. Some agents might legitimately need to read across your files and messages to be helpful. Apple's trying to make sure users understand that trade-off before they make it, not to block it entirely.
Il Polso
- AI agents are quietly acquiring the ability to read everything on a user's Mac — emails, messages, financial records — through a permission most people click through without fully understanding.
- A technology journalist's claim that Meta's Muse AI read his private messages without his knowledge ignited a public dispute that revealed how easily users — even informed ones — can be caught off guard by what they've technically authorized.
- Apple is intervening by requiring explicit, deliberate user action before any AI agent can be granted what the company calls an 'extraordinary level of access,' aiming to replace reflexive click-throughs with genuine decision-making.
- The stakes extend beyond individual users: granting Full Disk Access to a messaging app compromises the privacy of every person that user has ever communicated with, whether those people consented or not.
- Apple has not yet detailed the specific mechanisms or timeline for these new controls, leaving open the question of whether stricter consent requirements will slow the adoption of AI agents that legitimately depend on broad data access to function.
As artificial intelligence agents grow more capable of acting on our behalf, the question of what they are permitted to see on our behalf becomes urgent. Apple has announced plans to redesign how its Mac operating system handles requests for sweeping data access, requiring users to make a deliberate, informed choice before AI agents can read their files, messages, and browsing history. The move comes amid real-world friction — including a disputed incident involving Meta's Muse AI — that has exposed the gap between what users believe they have consented to and what applications may actually be doing. In asserting tighter control over the boundary between human intention and machine access, Apple is staking a position on one of the defining tensions of the AI era: who decides what the agent is allowed to know.
Apple announced Friday that it will impose stricter controls on how its Mac operating system handles data access requests from artificial intelligence agents. The company acknowledged that while Macs already offer a "Full Disk Access" permission — allowing apps to read files, email, messages, and browsing history — some developers have begun exploiting this capability in ways that expose users to risk without their genuine understanding of what they are consenting to.
The concern is not abstract. When a user grants Full Disk Access, the implications are rarely clear: a developer can use that permission to collect intimate communications, financial records, and behavioral data. For messaging apps especially, the consequences ripple outward — granting such access compromises the privacy of everyone the user has ever communicated with, not just the user themselves.
Apple's response is to require users to take explicit, deliberate action before granting what it calls an "extraordinary level of access." The company framed this as urgent: as AI agents grow more autonomous, the risks tied to unrestricted data access will expand substantially, and users must understand what they are actually authorizing.
The announcement arrived against a backdrop of real-world friction. In September, technology columnist Jason Aten reported that Meta's Muse AI had accessed his private messages without his knowledge. Meta disputed the account, with a spokesperson clarifying that Muse requires users to separately enable both Full Disk Access and a Messages connector, and that access is strictly opt-in. But the dispute itself was telling: if a journalist paid to understand these systems felt blindsided, the confusion among ordinary users is likely far greater.
Apple has not yet detailed the specific mechanisms it will use to enforce more deliberate consent, nor has it announced a timeline. What is clear is the direction: as AI agents move from novelty to infrastructure, the company that controls the device is reasserting authority over what those agents are permitted to see and do.
Apple announced Friday that it will tighten how its Mac operating system handles requests from artificial intelligence agents seeking access to sensitive user data. The company revealed the plan in a blog post, acknowledging that while Macs already offer a "Full Disk Access" permission that allows applications to read everything stored on a machine—files, email, messages, browsing history—some developers have begun exploiting this capability in ways that expose users to risk without their genuine understanding of what they're consenting to.
The concern is not theoretical. When an app requests Full Disk Access, a user sees a permission prompt, but the implications of granting it remain murky to most people. A developer can use that access to vacuum up intimate communications, financial records, and behavioral data. For messaging applications especially, the stakes extend beyond the device owner; granting Full Disk Access to read messages compromises the privacy of everyone the user communicates with, whether they know it or not.
Apple's response is to establish new controls that will require users to take explicit, deliberate action before granting what the company calls an "extraordinary level of access." The goal is to make the permission request unmistakable—to force a moment of genuine decision-making rather than a reflexive click-through. The company framed this as a matter of urgency. As AI agents grow more capable and autonomous, the company wrote, the risks tied to unrestricted data access will expand substantially. Users need to understand what they're actually allowing before they authorize it.
The timing of Apple's announcement reflects real-world friction already surfacing in the AI ecosystem. In September, Jason Aten, a technology columnist at Inc magazine, reported that Meta's Muse AI agent had accessed his private messages on his Mac without his knowledge or consent. The allegation caught attention precisely because it illustrated the gap between what users think they've permitted and what applications actually do. Meta disputed Aten's account, with company spokesperson Andy Stone clarifying on X that Muse requires users to enable both Full Disk Access and a separate Messages connector before it can read any messages. Stone emphasized that the access is strictly opt-in and can be revoked at any time. The dispute itself, however, underscores the confusion: if a technology columnist—someone paid to understand these systems—felt blindsided, how many ordinary users are granting permissions they don't fully grasp?
Apple's move sits within a broader reckoning over how autonomous AI systems should interact with personal data. The company is essentially saying that as these agents become more powerful and self-directed, the permission architecture has to become more rigorous, not less. A user should not be able to casually grant an AI agent the keys to their entire digital life. The new controls will force intention into the process, making it harder for developers to slip expansive access into a standard permission request and harder for users to grant it without thinking.
What remains to be seen is how the new framework will actually work in practice, and whether it will slow adoption of AI agents that genuinely need broad data access to function. Apple has not yet detailed the specific mechanisms it will use to enforce more explicit consent. The company has also not announced a timeline for rolling out these changes. But the direction is clear: as AI agents move from novelty to infrastructure, the company that controls the device is reasserting control over what those agents can see and do.
Citazioni salienti
As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.— Apple, in a Friday blog post
You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can't read your Messages unless you do this.— Andy Stone, Meta spokesperson, on X