Apple will require explicit consent for Full Disk Access as AI agents spread

By EnkiEdited by VK, Editor

Published

Reporting from Ars Technica, TechCrunch, The Verge

Apple says Mac apps will need a deliberate, explicit user step to get Full Disk Access, after Meta's Muse was accused of reading a columnist's Messages. No release date or technical details yet.

What it means for founders

  • If your Mac app or agent depends on Full Disk Access, expect more users to decline it once the new flow arrives. Audit what you actually read, and move to narrower permissions, such as specific folders or the Contacts and Calendar APIs, wherever they cover the job.
  • Treat Full Disk Access as a liability as well as a capability. Wardle's findings show that an agent holding broad access becomes a target for any other code on the machine, so hardening how your own processes talk to each other matters as much as the feature.
  • Say in plain words, at the moment you ask, what your app will read and why. Apple is signaling that it will judge apps on whether users understood the grant, and opaque onboarding is now a review risk.
  • Watch Apple's developer news and the next macOS beta for the actual mechanism and deadline, and plan a re-permission prompt in case existing grants are reset.

The story

Apple is tightening how Mac apps obtain Full Disk Access, the macOS permission that lets software read nearly everything on a machine. In a post for developers on Friday, the company said some apps were using the setting in ways that expose files, mail, messages and browsing history without users fully understanding what they had agreed to, and that autonomous AI agents make that exposure more dangerous. Users who still want to hand an app that level of reach will have to take a deliberate, explicit step to do it. Apple did not name any company or say when the change ships.

Why now

The timing points to Meta's Muse. About two weeks earlier, Inc. columnist Jason Aten wrote that the agent surfaced a notification referring to a private Apple Messages thread with a coworker, even though he said he never let it read his messages. Meta pushed back: CTO David Singleton and spokesperson Andy Stone both said Muse can only read Messages when the user has granted Full Disk Access at the system level and also switched on a Messages connector inside the app.

Security researcher Patrick Wardle disputed that framing in comments to Ars Technica, pointing out that any app holding Full Disk Access can read message databases, browser history and cookies, whether or not an in-app toggle is on. Apple's note, describing exactly that exposure, reads as siding with him. Ars also reported that Wardle had earlier disclosed a Muse configuration that let other code on a Mac take control of the agent, and that Amazon has blocked Muse from its platform.

The announcement also follows a WIRED report on a now patched flaw in ChatGPT's Mac app that could have let malware already on a machine take over the app and read its chat history.

What changes

Full Disk Access exists so backup tools can copy an entire disk, and Apple says it largely sidesteps the narrower privacy prompts macOS otherwise shows. Today a user grants it by flipping a switch for the app in System Settings. Apple's plan is to make that grant much harder to give casually. For messaging apps, it adds, the risk reaches people on the other side of the conversation too.

What we don't know yet

Apple has not given a release date, said whether the change arrives in a macOS point update or the next major version, or explained whether apps that already hold the permission will have to ask again. It did not respond to questions from TechCrunch or The Verge.

Sources

Enki Daily

Get stories like this every weekday morning.

The day's AI stories for founders, each with what it means for your company. Free.

Tools in this story

We may earn a commission if you sign up through our links. It never affects our ratings or which stories we cover.

ChatGPT

OpenAI's all-purpose AI assistant

9.2Editor’s scoreVisit ChatGPT

More in Policy & Safety

How Enki covers newsCorrectionsReport an error

Search Enki

Search AI tools, categories and news