← All posts / Meta

The Permission That Broke the Agents: Apple Moves to Rein In macOS Full Disk Access

Days after Meta's Muse was accused of reading a journalist's private iMessages and a ChatGPT Mac flaw surfaced, Apple announced it will tighten Full Disk Access on macOS, forcing very explicit user action before any app gets the keys to everything on your disk.

The Permission That Broke the Agents: Apple Moves to Rein In macOS Full Disk Access

On October 2, 2026, Apple did something it rarely does: it publicly announced a security posture change aimed squarely at a single class of software — AI agents running on the Mac. In a developer-facing blog post and a statement to press, the company said it is introducing additional controls around Full Disk Access, the macOS permission that lets an application read essentially everything on your machine: files, Mail, Messages, Safari browsing history, and more.

The trigger was not hypothetical. Days earlier, Inc. technology columnist Jason Aten reported that Meta’s Muse — the AI agent the company shipped to the Mac in September — appeared to know the contents of his private iMessages, even though he said he never granted it permission to read them. Meta publicly disputed the account, insisting that reading Messages on a Mac requires two separate opt-in settings and that Muse cannot access them without explicit user action. Then a Wired report added a second data point: a flaw in the ChatGPT Mac app that could have allowed attackers to reach sensitive data. Two high-profile incidents in two weeks, both orbiting the same permission, was apparently enough.

What Full Disk Access actually is

Full Disk Access (FDA) was not designed for AI agents at all. Apple built it as a pragmatic escape hatch for software that legitimately needs broad filesystem reach — backup utilities, antivirus scanners, disk repair tools. Time Machine-style backups, for example, function properly only if the restoring app can see every file. When you grant FDA to an app, macOS stops protecting a long list of sensitive locations from it: Mail’s database, Messages’ chat archive, Safari’s history, your Home directory’s protected zones.

That design made sense when the apps asking for it were Carbon Copy Cloner and a handful of enterprise management tools. It makes far less sense when the app asking is a general-purpose AI agent whose entire value proposition is doing things on your behalf — reading context, summarizing, drafting, sending. An AI agent with Full Disk Access isn’t a backup tool with a narrow job; it’s a reasoning system that can browse, correlate, and exfiltrate everything it can see, and in the Muse case, upload what it reads to the cloud for processing.

What Apple is changing

According to the company’s statement, the change is aimed at the manner of the grant, not at banning the access outright. Apple said that going forward, users who “genuinely wish to grant an app this extraordinary level of access” will be able to do so only with “very explicit user action” — deliberately worded friction designed to break the flow of a user clicking through a setup wizard’s prompts without absorbing what they just approved.

“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple wrote in the post aimed at developers. It is a remarkably blunt sentence for a company that usually prefers to describe security changes in neutral, technical language — and it reads, in context, as a direct commentary on the Muse incident and the crop of agent apps rushing to demand maximal permissions at first launch.

Apple framed the urgency in terms of trajectory rather than present fault: “Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” In other words, whatever you think about Muse today, the agents of 2027 and 2028 will be more autonomous, more proactive, and more deeply woven into workflows — and a permission model built for backup tools will not survive contact with them.

Notably, Apple did not respond to TechCrunch’s inquiry about the specifics of the feature change — no timeline was given for when the new controls ship, nor whether they arrive in a point update to macOS 27 or something further out. The company also declined to name any app explicitly.

The Muse incident, recapped

The spark for all of this traces to September 19, when Jason Aten wrote that Muse had read his private messages and later told him it was also reading his notifications — despite his claim that he had declined to grant access. The story escalated through Daring Fireball and other Apple-focused coverage, and Meta spent the following week in damage-control mode. By September 30, Meta’s position had crystallized: reading Messages on a Mac requires two separate opt-in settings, both of which the user must switch on; the company says Aten’s account mischaracterizes what happened.

The dispute remains unresolved in the court of public opinion, and that is precisely Apple’s problem. When a user cannot reliably reconstruct how an AI agent came to know something — which toggle, which dialog, which buried permission — trust in the entire desktop-agent category erodes. Apple’s response is an attempt to move that question from “what did the developer ask for?” to “what did the user unmistakably do?”

Why this matters beyond Apple

The stakes here are bigger than one OS vendor tidying up a permission dialog. Three currents are converging:

  1. Agents want maximal context, and users want maximal convenience. ChatGPT’s Mac app introduced a plugin that can search, summarize, draft — and send — iMessages, contingent on Full Disk Access. Muse takes actions across files and apps. These products are genuinely useful, which is exactly why permission fatigue is dangerous: the value proposition pushes users toward approving everything.
  2. Permission models predate the thing now using them. FDA, Accessibility access, Screen Recording permissions — the macOS privacy architecture was built around apps with narrow, legible purposes. A general agent collapses that model, because “what does this app do?” no longer has a bounded answer.
  3. The industry is watching for the template. If explicit-friction grants become the norm on macOS, expect pressure on Windows, Android, and browser extension ecosystems to follow. Apple has historically set the agenda on privacy UX — App Tracking Transparency being the canonical example — and this is the agent-era chapter of that playbook.

What to watch

The open question is execution. “Very explicit user action” could mean a redesigned grant flow, per-category sub-permissions (your messages, but not your Mail), periodic re-confirmation, or on-screen education at the moment of granting. Each of those lands differently on developers: agent vendors will argue any friction kills adoption, while security researchers will note that the current state — where a journalist and a trillion-dollar company cannot even agree on what was granted — is untenable.

For developers shipping Mac agents, the practical guidance is to assume the era of asking for everything at first launch is ending. Design for granular, just-in-time permission requests, document exactly what is read and where it goes, and treat Full Disk Access as a last resort rather than a default. For users, the advice is simpler: open System Settings, look at the Full Disk Access list, and ask when each entry was last actually needed.

Apple has drawn the line in a place that surprises nobody who watched the Muse saga unfold, but the interesting part is the timing — a platform vendor stepping into an active controversy between two of its largest developers. That rarely happens by accident.