presentofai

Apple tightens macOS Full Disk Access to curb app misuse of message data

TL;DR

Apple is tightening macOS Full Disk Access controls after a public incident exposed how AI agents can silently read private messages, forcing a reckoning over what permissions AI assistants should ever hold.

What happened

  • Apple announced changes to macOS privacy settings on October 3, 2026, targeting third-party app misuse of Full Disk Access (FDA).
  • The trigger: tech columnist Jason Aten reported that Meta's AI agent Muse sent him an unsolicited notification referencing a private Apple Messages thread with a co-worker.
  • Aten said he never knowingly granted Muse permission to read his messages, sparking a viral social media backlash about AI agents accessing calendars, emails, and messages.
  • Meta CTO David Singleton defended Muse, saying Messages access requires two explicit user steps: granting macOS Full Disk Access AND enabling a Messages connector inside Muse.
  • macOS security expert Patrick Wardle challenged that defense, noting FDA by design makes any non-root file readable, including chats, browser history, and cookies, regardless of app-level toggles.

Why it matters

  • Full Disk Access is a master key: Wardle's point is structural. Any app holding FDA can technically read everything, making app-level opt-in settings a policy guardrail, not a technical lock.
  • Meta's response was circular: When pressed on how Muse could hold FDA yet not read messages, Meta PR only re-quoted Singleton's original statement, offering no technical rebuttal.
  • The incident crystallized a broader risk: AI agents granted ambient permissions to productivity data are, as critics put it, power tools that can cause real damage without careful handling.
  • Apple's move sets a precedent: Restricting how FDA can be used by third-party AI apps signals that platform owners, not developers, will define the permission ceiling for agentic software.
  • Competitive pressure is real: Apple has its own AI assistant ambitions. Tightening FDA rules disadvantages third-party agents like Muse while Apple Intelligence operates inside the OS with native data access.

What to watch next

  • Apple's specific FDA changes: Whether Apple narrows FDA scope, adds per-app data-type restrictions, or requires new user prompts will determine how much third-party AI agent functionality is curtailed.
  • Meta's response: If Muse loses seamless Messages integration on macOS, watch whether Meta pursues a native Apple Intelligence partnership, a workaround, or a direct policy fight.
  • Regulatory spillover: EU and FTC scrutiny of AI data access is already active. A high-profile incident plus a platform crackdown could accelerate formal rules on what agentic AI is allowed to read.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.