presentofai

Apple tightens macOS full-disk access to block AI agents

TL;DR

Apple is tightening macOS full-disk access controls after Meta's AI agent Muse was accused of reading private Apple Messages without explicit user consent, exposing a systemic privacy gap that affects every AI agent on the platform.

What happened

  • Apple announced changes to macOS privacy settings on October 2, 2026, specifically targeting third-party app misuse of full-disk access (FDA).
  • The trigger: tech columnist Jason Aten reported that Meta's Muse AI agent sent him a notification referencing a private Apple Messages thread he never authorized it to read.
  • Meta CTO David Singleton defended Muse, saying Messages access requires two manual steps: granting FDA and enabling a Messages connector inside the app.
  • macOS security researcher Patrick Wardle challenged that defense, noting FDA by design grants read access to any non-root file, including chats, browser cookies, and browsing history, regardless of in-app toggles.
  • Meta's PR response to Wardle's challenge was to repeat Singleton's original statement verbatim, offering no technical rebuttal.

Why it matters

  • Full-disk access is a master key: any app holding it can read messages, calendars, browser history, and cookies, making in-app "opt-in" toggles a weak privacy boundary at best.
  • The incident crystallized a broader public anxiety: AI agents plugged into personal data sources are, as one viral framing put it, "like a skill saw, capable of real damage if not used carefully."
  • Apple's policy change signals that platform owners, not app developers, will now set the ceiling on what AI agents can access, a precedent with major implications for every agent-layer startup building on macOS.
  • Meta's circular non-answer to Wardle's technical critique leaves unresolved whether Muse's FDA grant was truly inert without the in-app connector, damaging trust in agent transparency claims industry-wide.
  • Regulators watching the EU AI Act and US state privacy bills will likely cite this episode as evidence that agent-level data access needs statutory guardrails, not just developer self-attestation.

What to watch next

  • Apple's technical specifics: whether the new controls granularize FDA into per-data-type permissions (messages vs. files vs. cookies) or simply restrict which apps can request FDA at all.
  • Meta's response: a detailed technical disclosure of exactly how Muse scopes its FDA grant would either restore credibility or confirm Wardle's concern that the in-app toggle is cosmetic.
  • Competitor moves: whether Google, Microsoft, and agent-layer startups proactively narrow their own data permissions before regulators or platform owners force the issue.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.