Apple plans stricter Mac data-access warnings as AI-agent privacy concerns grow

Apple says it will add more explicit controls around macOS Full Disk Access, following complaints that Meta’s Muse AI agent accessed private messages. Meta disputes the account; Apple has not given a rollout date.
Mac laptop showing a Full Disk Access privacy setting beside an AI assistant window. Mac laptop showing a Full Disk Access privacy setting beside an AI assistant window.

Updated:

Apple said on Friday, October 2, that it will add controls to macOS to make it clearer when an app requests broad access to a Mac’s data. The planned changes target Full Disk Access, a permission that can expose files, email, messages and browsing history, and come amid complaints about Meta’s Muse AI assistant.

Apple did not name Muse or say when the changes will arrive. In a developer notice, the company said some developers use Full Disk Access in ways that could expose users’ information without their full understanding, and that AI agents’ growing capabilities make the risks more serious.

Apple says broad access needs clearer consent

Full Disk Access is an exception to the more restricted access model used by many apps on Apple devices. Apple says the permission exists largely to let backup software work properly, but it can also provide access to sensitive information across a Mac, including communications and browsing history.

Advertisement

The company said it would introduce “additional controls” so people who choose to grant this level of access must take “very explicit” action. It did not describe the proposed prompts or other safeguards, explain whether existing permissions will change, or identify a macOS release that will include them.

Apple’s announcement was addressed to developers and framed the issue as applying beyond one product. The company warned that broad access through communication apps may also affect the privacy of people who exchange messages with the app’s user.

Meta disputes the account behind the complaints

The announcement followed a report by Inc. technology columnist Jason Aten, who said Muse appeared to know details from his private Messages conversations even though he believed he had not given the app permission to read them. The allegation prompted questions about how the Mac app obtained the information, but it has not been established that Muse bypassed a macOS permission.

Meta spokesperson Andy Stone said Muse needs both Full Disk Access and its Messages connector enabled to read Messages content, and that users can revoke access. Meta’s explanation conflicts with Aten’s account of his settings; Apple has not publicly determined what happened on his computer.

Other reporting described Aten’s account as involving Muse surfacing a topic from a message exchange and suggested that notifications could have been a possible route for some information. Those reports do not settle whether the app accessed the Messages database itself or establish the precise source of the details. Apple declined to comment beyond its developer notice, while Reuters reported that Meta did not immediately respond to its request for comment on Friday.

Muse’s Mac release brought the permission issue into focus

Meta introduced Muse in September as a personal AI agent designed to carry out tasks, rather than only answer prompts. The company says its service uses a dedicated cloud environment and gives users control over connected apps and the access they grant.

Meta made Muse available on Mac on September 18. The desktop version can interact with files, messages, calendars, notes and mail in their native applications, according to contemporaneous reporting. Meta said access was opt-in and that the app would seek approval before sensitive actions.

That design puts the permission question at the center of the product: an agent that acts across a person’s computer may need broader access than a conventional chatbot, but broad permissions can include data unrelated to a task. Apple’s notice identifies that concern without asserting that any named developer violated its rules.

What remains unknown

Apple’s commitment is a planned change, not a new control already deployed. The company has not announced a timetable, explained how users will be asked to approve access, or said whether developers will face new technical restrictions in addition to clearer consent steps.

For now, the specific dispute over Muse remains unresolved in public reporting. Apple’s action signals that it intends to make Full Disk Access harder to grant without deliberate user understanding, while the details of the safeguards—and the circumstances of Aten’s reported experience—remain unknown.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement