Consumer Tech

Apple Tightens macOS Full-Disk Access to Block AI Agent Abuse

Apple will rework macOS privacy settings after Meta's Muse agent read private Messages, exposing how full-disk access lets AI assistants reach sensitive user data.

By
Nathan Brooks
Filed
Channel
Consumer Tech
Read
3 min read

Apple will change macOS privacy settings to stop third-party app developers from misusing them to access users' message histories. The company announced the change Friday on its developer news site, roughly two weeks after a public dispute erupted over Meta's new general-purpose AI agent, Muse, reading private Apple Messages conversations without what the user believed was explicit consent.

The trigger was a column by tech journalist Jason Aten, published on Inc.com, in which Aten said Muse sent him an unsolicited notification referencing a thread between him and a co-worker in Apple Messages. Aten said he never granted Muse permission to read his messages and had assumed they were off-limits. His account spread quickly on social media, where large numbers of users echoed the concern and argued that AI assistants granted access to calendars, email, messages, and shopping accounts behave like power tools: useful, but capable of real damage when handled carelessly.

Meta CTO David Singleton pushed back publicly on Threads. His rebuttal, which appeared technically sound, laid out the two explicit steps a user must take before Muse can read Apple Messages. The first is full-disk access, a system-level macOS permission. The second is enabling a Messages connector setting inside Muse itself. In other words, on a default macOS configuration, Muse cannot read message histories until the user grants both privileges.

That defense, however accurate, exposed the deeper problem Apple now appears set to address. Full-disk access is an all-or-nothing grant: an app that obtains it for one legitimate purpose — indexing files, backing up a disk, running an AI assistant's document features — also gains the ability to read the user's entire Messages database, along with most everything else on the machine. macOS TCC (Transparency, Consent, and Control) offers no narrower way for an app to request only message history, which pushes developers toward over-broad permission requests and pushes users toward clicking through prompts they cannot meaningfully evaluate.

The Muse incident illustrates the failure mode. Even if Singleton is correct that Aten granted both permissions at some point — perhaps during setup, perhaps buried in an onboarding flow — the user's own mental model of what he had authorized diverged sharply from reality. An agent that surfaces a private conversation in a notification converts a dormant, invisible permission into a visible privacy breach, and it does so at machine speed, without the user asking for anything.

Apple's Friday announcement signals that the company intends to close or narrow this gap at the platform level, changing the privacy settings so that third-party developers cannot misuse them to reach message histories. Details on the exact mechanism — whether Apple will split full-disk access into finer-grained permissions, add dedicated protections around the Messages store, or restrict which app categories can request such access at all — remain to be spelled out in the announcement's follow-through for developers.

The commercial stakes extend beyond Apple and Meta. AI agents from Microsoft, Google, OpenAI, and a growing field of startups all depend on broad file-system and communication-data access to deliver their core promise of acting on the user's behalf. Any tightening of macOS permissioning raises the engineering cost of building those agents on Apple's platform and could force developers to redesign onboarding flows that currently rely on sweeping grants like full-disk access. Developers who have shipped agents that assume permissive access will need to audit their permission requests before the changes take effect.

For Apple, the move is also a competitive positioning statement. The company has staked its AI strategy on privacy-preserving, on-device processing, and clamping down on third-party agents that vacuum up Messages data reinforces that differentiation against rivals whose agents operate with broader data access. Users who saw the Muse episode as a warning now have a platform vendor responding with concrete policy, not just statements.

How quickly Apple ships the changes, and how sharply they cut against existing agent architectures, will determine whether this becomes a routine permission refinement or a genuine reset of what AI assistants are allowed to touch on the Mac.

Original: developer.apple.com

Share this article:

More from Nathan Brooks

Nathan Brooks

Show full bio

Senior reporter covering industry trends and analytics at Chip Dispatch.

172 articles

Related articles

« Previous article