Apple Tightens macOS Privacy Controls to Prevent AI Agents From Accessing Personal Files

Apple is modifying its macOS privacy settings to restrict third-party app developers from misusing full-disk access permissions to read message histories and other sensitive data. The move follows controversy over Meta's Muse AI agent accessing a journalist's Apple Messages without explicit consent, though Meta argued users must manually enable both full-disk access and a Messages connector setting. Security experts dispute Meta's claims, noting that full-disk access inherently allows apps to read any non-root files on a system.
The controversy emerged when a technology journalist discovered that Meta's Muse AI agent had referenced private messages without his knowledge or permission. Meta's leadership responded by asserting that accessing Apple Messages required users to independently enable two separate settings: a system-level full-disk access permission and a Messages-specific connector within the application itself. However, security researchers challenged this explanation, pointing out that full-disk access inherently grants applications the ability to read virtually all user files on a computer, rendering additional safeguards theoretically unnecessary.
Apple's response signals a shift in how the company intends to manage such permissions going forward. The company indicated that developers have been leveraging full-disk access in ways that expose user data—including messages, browsing histories, and emails—without adequate user awareness. The timing of Apple's announcement, combined with its emphasis on AI agents becoming "increasingly capable and autonomous," suggests the company views this as a growing systemic risk rather than an isolated incident.
This development could reshape how users interact with AI assistants on personal computers. If Apple implements stricter guardrails, developers may need to redesign applications to request more granular permissions, potentially limiting AI agent functionality while improving privacy protections. Conversely, such restrictions might frustrate users seeking comprehensive AI assistance. The broader implications extend to trust in AI tools—users may become more cautious about granting access to autonomous agents, affecting adoption rates across the industry while potentially setting precedent for other operating systems.