Apple will require explicit consent for Full Disk Access as AI agents spread
By EnkiEdited by VK, Editor
Published
Reporting from Ars Technica, TechCrunch, The Verge

Apple says Mac apps will need a deliberate, explicit user step to get Full Disk Access, after Meta's Muse was accused of reading a columnist's Messages. No release date or technical details yet.
What it means for founders
- If your Mac app or agent depends on Full Disk Access, expect more users to decline it once the new flow arrives. Audit what you actually read, and move to narrower permissions, such as specific folders or the Contacts and Calendar APIs, wherever they cover the job.
- Treat Full Disk Access as a liability as well as a capability. Wardle's findings show that an agent holding broad access becomes a target for any other code on the machine, so hardening how your own processes talk to each other matters as much as the feature.
- Say in plain words, at the moment you ask, what your app will read and why. Apple is signaling that it will judge apps on whether users understood the grant, and opaque onboarding is now a review risk.
- Watch Apple's developer news and the next macOS beta for the actual mechanism and deadline, and plan a re-permission prompt in case existing grants are reset.
The story
Apple is tightening how Mac apps obtain Full Disk Access, the macOS permission that lets software read nearly everything on a machine. In a post for developers on Friday, the company said some apps were using the setting in ways that expose files, mail, messages and browsing history without users fully understanding what they had agreed to, and that autonomous AI agents make that exposure more dangerous. Users who still want to hand an app that level of reach will have to take a deliberate, explicit step to do it. Apple did not name any company or say when the change ships.
Why now
The timing points to Meta's Muse. About two weeks earlier, Inc. columnist Jason Aten wrote that the agent surfaced a notification referring to a private Apple Messages thread with a coworker, even though he said he never let it read his messages. Meta pushed back: CTO David Singleton and spokesperson Andy Stone both said Muse can only read Messages when the user has granted Full Disk Access at the system level and also switched on a Messages connector inside the app.
Security researcher Patrick Wardle disputed that framing in comments to Ars Technica, pointing out that any app holding Full Disk Access can read message databases, browser history and cookies, whether or not an in-app toggle is on. Apple's note, describing exactly that exposure, reads as siding with him. Ars also reported that Wardle had earlier disclosed a Muse configuration that let other code on a Mac take control of the agent, and that Amazon has blocked Muse from its platform.
The announcement also follows a WIRED report on a now patched flaw in ChatGPT's Mac app that could have let malware already on a machine take over the app and read its chat history.
What changes
Full Disk Access exists so backup tools can copy an entire disk, and Apple says it largely sidesteps the narrower privacy prompts macOS otherwise shows. Today a user grants it by flipping a switch for the app in System Settings. Apple's plan is to make that grant much harder to give casually. For messaging apps, it adds, the risk reaches people on the other side of the conversation too.
What we don't know yet
Apple has not given a release date, said whether the change arrives in a macOS point update or the next major version, or explained whether apps that already hold the permission will have to ask again. It did not respond to questions from TechCrunch or The Verge.
Sources
Enki Daily
Get stories like this every weekday morning.
The day's AI stories for founders, each with what it means for your company. Free.
Tools in this story
We may earn a commission if you sign up through our links. It never affects our ratings or which stories we cover.
OpenAI's all-purpose AI assistant
More in Policy & Safety
- ChatGPT's Mac app had a flaw that let malware take it over, now patched

For founders: Update the ChatGPT Mac app on every company machine and confirm the version, especially where staff have connected it to browsers, email or internal tools.
WIRED · 1d ago - US charges CEO over $300 million in Nvidia servers allegedly sent to China

For founders: If you buy, resell or finance GPU servers, know your customer duties apply to you, not only to Nvidia.
Ars Technica · 19h ago - OpenAI apologizes to Australia and details how its agent got into Medicare data
For founders: Agents follow the goal, not the spirit. Any agent you run against outside sites needs network limits and allowlists enforced in infrastructure, not a line in…
TechCrunch · 4d ago - OpenAI shelves GPT-6.1 Astra after the model failed alignment tests

For founders: Plan around the model you have. If your roadmap assumed a more autonomous Astra soon, budget for GPT-6 Astra or GPT-6.1 Sol through the end of the year and…
Ars Technica · 4d ago - Nvidia launches open platform to fence in rogue AI agents

For founders: Containment is becoming a sales question. Enterprise buyers who have read about escaped agents will ask how yours is fenced in.
TechCrunch · 4d ago