Apple Mandates Explicit Consent for macOS Full Disk Access to Curb AI Agent Data Breaches

Apple is tightening macOS Full Disk Access permissions to prevent AI agents from accessing sensitive data without clear user consent. The move follows a controversy where Meta’s Muse agent allegedly read private messages, prompting Apple to require 'very explicit user action' for granting such broad access. While developers warn this may hinder power users, Apple cites growing risks from autonomous AI tools.
Key points
- Apple announced new controls for macOS Full Disk Access (FDA) to ensure users understand the risks before granting apps access to files, mail, messages, and browsing history.
- The changes follow a public incident where tech columnist Jason Aten reported that Meta’s AI agent, Muse, accessed his private iMessage conversations despite his belief that permissions were not granted.
- Apple stated that some developers are misusing FDA to expose user data without full knowledge, posing significant privacy risks as AI agents become more autonomous.
- The new policy requires 'very explicit user action' to grant FDA, moving beyond simple system settings toggles or Touch ID approvals.
- The update affects various AI agents, including Meta Muse, ChatGPT dots, Claude, and others, though Apple did not name specific apps in its official statement.
Background
This development follows a broader trend in late 2026 where personal AI agents from OpenAI, Meta, and Apple have become mainstream, raising concerns about data ownership and privacy. Earlier reports in October 2026 highlighted Apple’s initial response to these risks, noting that while the company introduced stricter controls, specific technical details and rollout timelines were not immediately disclosed. The current announcement clarifies the direction of these controls, emphasizing explicit user consent over passive permission grants.
How outlets are covering it
Daring Fireball emphasizes the tension between power users who rely on FDA for complex tasks and unsophisticated users who may inadvertently grant dangerous access due to a lack of technical understanding. The outlet worries that stricter controls could hamper advanced users but notes the necessity of protecting the majority of Mac users who may not comprehend the implications of FDA. Ars Technica highlights the conflict between Apple’s stance and Meta’s defense, noting that Meta CTO David Singleton claimed Muse’s message access was opt-in, while security expert Patrick Wardle argued that FDA inherently allows access to all non-root files. Ars Technica points out that Apple’s statement contradicts Singleton’s denial, suggesting that FDA alone could enable message access. Newsshooter focuses on the practical impact, noting that the new explicit consent requirement will affect multiple AI agents, including ChatGPT dots and Claude, and emphasizes the need for users to be fully aware of the risks involved.
Why it matters
The change addresses a critical privacy gap in macOS, where Full Disk Access previously allowed apps to bypass standard privacy controls. As AI agents become more autonomous, the risk of unauthorized data access grows, potentially compromising not only the user’s data but also the privacy of their contacts. Apple’s move aims to ensure informed consent, reducing the likelihood of accidental data exposure and enhancing user trust in the platform. For developers, it necessitates a reevaluation of how they request and use FDA, potentially impacting the functionality of backup and AI applications.
What to watch
Apple has not specified a rollout timeline or exact technical implementation for the new FDA controls. Developers are expected to adapt their apps to comply with the new explicit consent requirements. Users may see updated permission prompts that clearly outline the risks of granting FDA. The outcome will depend on how effectively Apple balances security with usability for both power users and general consumers.
- Apple Is Going to Further Tighten the Screws on Full Disk Access on MacOS, in Response to Agentic AI Apps Running Amok Daring Fireball
- Apple changes full-disk access permissions to curb abuse from AI agents Ars Technica
- Apple to Tighten Mac Data Controls in Guard Against AI Agents Bloomberg.com
- Apple has notified developers that, as AI agents become more advanced & autonomous, full-disk access to all data on a Mac poses an increasing risk Newsshooter
- Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents TechCrunch
Want the full story? Read the original reporting
Read on Daring Fireball