**Apple** has announced that it will introduce new restrictions on the ‘Full Disk Access’ permission for Mac apps. A measure aimed at addressing concerns about the risks of AI agent apps excessively collecting and using user data, it came just 24 days after **Meta** unveiled its AI agent app ‘Muse’.
Key points
Apple plans to introduce additional controls before Mac apps receive full disk access permissions, but did not disclose a specific implementation timeline.
The announcement came after a claim that Meta’s Muse agent read a columnist’s personal messages. Meta denied the allegation.
Apple warned that as AI agents become increasingly sophisticated and autonomous, the associated risks will grow significantly.
Apple tightens full Mac disk access permissions further
Through a notice to developers, Apple explained that when an entitlement designed originally for backup software is applied to other apps, it effectively bypasses most privacy protection measures.
According to Apple, some developers design apps in a way that allows access to nearly all data in the system—files, mail, messages, browser history, and more—while the user is in a state of “not fully being aware.” The company pointed out that in the case of messenger and communication apps, this could even expose who the user is talking to.
Apple said it plans to introduce additional controls so that only if users truly intend to grant such high-risk permissions in the future will it require “highly explicit user action.” Although it did not disclose specific technical specifications or a rollout timeline, it said the goal is to ensure users are clearly aware of the risks before granting full disk access.
Also worth seeing: Chainalysis tracks North Korea involvement in the theft of $387 million Bitget… from XRP to Bitcoin
Meta’s ‘Muse’ privacy infringement controversy
Apple’s notice was released shortly after an article written by tech columnist **Jason Aten**. Aten reported that even though Meta’s Muse agent refused message access during the app’s setup process, it accessed his personal text messages.
According to his claims, Muse suggested column ideas based on text conversations she shared with the podcast co-host. In response, a Meta spokesperson, **Andy Stone**, argued that Muse’s message integration feature is strictly an opt-in (user-choice) system, and that it only works when users turn on both full disk access and a separate message connector.
In an official notice, Apple did not directly mention the names of specific companies or products.
However, Apple stressed that the risks related to full disk access will “increase substantially as AI agents evolve into more powerful and autonomous entities,” and that it is important to address them proactively. Apple specialist columnist **John Voorhees** warned that the announcement is vague and could end up restricting ordinary Mac utilities that rely on the same type of permission too heavily.
He also said that the launcher, file manager, and image editor he developed already use this permission as well.
Security risk track record of AI agents
Desktop AI agents from OpenAI, such as Dots and OpenClaw, including Muse, often require full disk access to fetch files, messages, and various other data on the user’s behalf.
Recently, OpenAI patched vulnerabilities in the ChatGPT Mac app that could allow an attacker to access chat history, execute commands, and even steal data from other apps.
This issue was raised by researchers at the Objective-See Foundation and is evaluated as a case that symbolically demonstrates potential security flaws in an AI desktop client.
Meta’s Muse was developed at its ‘Superintelligence Labs,’ and the first model from that unit was released this April. The Muse app launched in the United States and Canada on September 8, and within ten days it took the No. 1 spot for popularity in the U.S. App Store. Third-party trackers estimate cumulative downloads of around 2.3 million to 4.3 million as of the end of September.
Read next: iPhone 18 Pro Max, AT&T outage controversy… Apple: “cannot be resolved with a software update”
