“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding,” Apple said. “For communication apps, this can also compromise the privacy of the people users are communicating with.”
Full Disk Access gives macOS software permission to reach protected parts of a user’s system. Desktop AI agents such as OpenClaw, Dots and Muse may ask for that access so they can work across files, messages and other personal information.
Those permissions can make agents more useful, but they also increase the amount of sensitive data an AI system can reach. Some users have responded by running agents on separate computers rather than granting them broad access to their primary machines.
Concerns around those permissions resurfaced recently with Meta’s Muse. Inc. columnist Jason Aten wrote that the Muse Mac app was able to access his messages even though he believed he had denied that permission. Meta said that if his messages were synchronized, he must have opted in.
Apple did not name Muse or Meta in its announcement. Instead, the company focused on the broader issue of making sure users understand the consequences of granting an app unrestricted access to protected data.
“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” Apple said.
The company also tied the change directly to the increasing autonomy of AI software.
“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple said. “We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”
For now, Apple has outlined the direction of the change without detailing the final controls. The update signals that macOS permission design is being revisited specifically around the risks created when autonomous software can see and act on large amounts of personal data.
This analysis is based on reporting from Engadget.
Image courtesy of Unsplash.
This article was generated with AI assistance and reviewed for accuracy and quality.