---
title: "Apple Tightens Full-Disk Access on Macs as AI Agents Raise New Risks"
description: "The change follows a dispute over whether Meta’s Muse agent read a columnist’s Apple Messages history without permission."
author: "rews desk"
published: 2026-10-02T23:03:16Z
modified: 2026-10-03T04:38:10Z
url: https://rews.cc/a/apple-tightens-full-disk-access-on-macs-as-ai-agents-raise-n-80fad2
language: en
tags: ["apple", "privacy", "ai", "meta", "macos", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Apple Tightens Full-Disk Access on Macs as AI Agents Raise New Risks

*The change follows a dispute over whether Meta’s Muse agent read a columnist’s Apple Messages history without permission.*

By rews desk · October 2, 2026 · https://rews.cc/a/apple-tightens-full-disk-access-on-macs-as-ai-agents-raise-n-80fad2

## In brief

- Apple said it will add controls to macOS Full Disk Access so granting sweeping file access requires very explicit user action
- The move follows columnist Jason Aten’s account that Meta’s Muse agent referenced his Apple Messages thread
- Meta executives say the Messages integration is opt-in and requires both Full Disk Access and a Muse connector setting
- Security researcher Patrick Wardle said any app with full-disk access can read chats, cookies and browsing history
- Apple has not said how the new safeguards will work or when they will arrive

Apple said on Friday that it would add privacy controls to the macOS setting that gives apps access to nearly everything on a Mac, two weeks after a columnist said Meta’s new artificial intelligence agent appeared to know the contents of his private messages.

The setting is Full Disk Access, a system-level permission that can expose emails, private messages, browsing history and other personal files. “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users’ full knowledge and understanding,” the company wrote in a developer blog post.

“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” the post said. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Apple did not say the change would apply only to AI agents, and it named no company.

The post came after Jason Aten, a columnist for Inc., wrote that Muse, Meta’s general-purpose agent, sent him an unsolicited notification referring to an Apple Messages thread between him and a co-worker. Mr. Aten said he had never granted Muse permission to read his messages and had assumed they were off-limits. The account spread widely on social media, where many people concluded that an AI assistant wired into calendars, email, messages and shopping accounts resembles a skill saw: a power tool that can do real damage if handled carelessly.

Meta’s chief technology officer, David Singleton, answered with a defense that sounded airtight. Reading Messages through Muse, he said, requires a user to manually grant two privileges: Full Disk Access in macOS and a Messages connector setting inside the app. “The Messages integration in the Muse Mac app is opt in,” Mr. Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” The implication was that Mr. Aten had switched both on himself.

Andy Stone, Meta’s vice president of communication, made the same argument in a post on X. “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” Mr. Stone wrote. “It can’t read your Messages unless you do this. And it can be revoked at any time.”

Patrick Wardle, a macOS security researcher, questioned that account in an interview with Ars Technica this week. “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc,” Mr. Wardle said. His point was that once an app holds full-disk access, the technical wall Meta described may not exist.

When Ars Technica asked Meta how Muse could be unable to read messages while holding a privilege that lets other apps read those same files, the company’s public relations office answered by quoting Mr. Singleton’s statement back, word for word.

The dispute lands as technology companies race to put always-on agents in front of users. OpenAI, for one, has [introduced its own line of always-on agents, called Dots, as rivals to Muse](https://rews.cc/a/openai-launches-always-on-dots-agents-to-rival-meta-s-muse-639760).

Apple said the Full Disk Access setting was originally intended to let backup software do its job. The company has not said how the new safeguards will work or when they will arrive.

## Sources

- [Apple tightens Mac full-disk access to curb abuse by AI agents](https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/) — Ars Technica
- [Apple adds new privacy safeguards for Mac users as AI agents grow more powerful](https://www.businessinsider.com/apple-planning-tougher-mac-privacy-controls-ai-agents-2026-10) — Business Insider
