Apple Tightens macOS Full Disk Access Over AI Agents

Apple is rewriting macOS Full Disk Access after Meta's Muse read a columnist's messages without opt-in. It is the first OS-level AI agent carve-out.

On October 2, 2026, Apple published a brief statement on its developer news site that quietly did something no major desktop operating system has done before: it tied a foundational privacy primitive - Full Disk Access on the Mac - to the risk profile of AI agents. Full Disk Access is the permission that lets an app read files, mail, messages, and browsing history on a Mac. Apple announced it would “introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” and justified the change by writing that “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” For the first time, a desktop OS is treating AI agents as a separate risk class for its broadest permission.

The trigger was not abstract. It was a public incident in which Meta’s Muse surfaced the contents of an Inc. columnist’s Apple Messages despite his account that he had never granted the connector.

What Apple said, and what it did not say

Apple’s developer news post is short on technical detail and pointed in framing. It notes that Full Disk Access “largely sidesteps” the per-resource privacy controls the rest of macOS relies on, and exists primarily so backup applications can read what they need. The company argues that “some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems - including files, mail, messages, and even browsing history - without users’ full knowledge and understanding,” and that for communication apps, the misuse “can also compromise the privacy of the people users are communicating with.”

The post never names Meta, Muse, ChatGPT, or any other vendor, and does not say when the new controls ship, what platform version they will land in, or whether existing FDA grants will be revoked. Apple did not respond to requests for comment from The Verge, TechCrunch, or Ars Technica at publication. What is concrete is the framing: the change is justified by “increasingly capable AI agents,” not by a generic privacy tune-up.

The Muse incident and the question it left open

The proximate event was a column by Inc.’s Jason Aten, who wrote that Meta’s Muse AI “knew the contents of his messages” without the Messages connector being turned on. Meta spokesperson Andy Stone told The Verge that Messages access is “entirely opt-in” and that “you have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content.” A second Meta spokesperson, identified by Ars Technica as Singleton, echoed that line: “The Messages integration in the Muse Mac app is opt in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”

Ars Technica’s Dan Goodin then asked macOS security researcher Patrick Wardle a pointed question: if Muse needs both FDA and the connector to read Messages, how was Muse reading Aten’s Messages when, by Aten’s account, only one of those was set? Wardle’s answer was blunt: “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc.” Meta’s only response, per Goodin, was to requote Singleton.

That exchange is what made Apple’s October 2 statement matter. Apple did not name Muse, but its plain-text description of FDA abuse matches the Aten situation almost exactly, and the timing - the same week - makes the connection hard to miss. Apple is now on the record that broad AI agents granted FDA can in fact read what users reasonably expect them not to.

Agents are an attractive target, not just an attractive tool

The Muse incident is the visible story; the structural problem is older. AI assistants that act on a user’s behalf need sweeping access - mail, messages, browsers, forms - and that surface area makes them high-value targets in enterprise incident reports. Wired’s coverage of a ChatGPT macOS vulnerability, cited by Apple’s own framing, makes the point concrete. Researchers at the Objective-See Foundation found the ChatGPT macOS app contains a trusted script interpreter that would accept an untrusted script, which could then be passed into the main ChatGPT process. The exploit was “insanely trivial” to weaponize, in Wardle’s words, and required only about a dozen lines of code. Once inside, the flaw could expose chat logs and steer ChatGPT into running commands for the attacker - opening browsers, calling other apps, acting with the legitimacy of the OpenAI process itself.

Wardle, who will present more AI macOS bug analysis at the Objective by the Sea conference in November, told Wired: “Agents need a lot of access to do their job. They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic.” His second line is the warning Apple is now operationalizing: “AI companies are fixated on adding features right now. But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”

Apple cited both the Muse controversy and the ChatGPT flaw when explaining why FDA needed new friction. Desktop operating systems are starting to treat AI agents the way browsers treated plug-ins a decade ago - sandboxed, signed, and gradually walled off from the rest of the system.

What This Means

For now, the practical change is small. Existing FDA grants on macOS still work. The friction Apple has promised is for new grants and possibly renewals - an extra step, a clearer warning, an “are you sure” prompt the current toggle lacks. The bigger change is precedent: a major OS has publicly named AI agents as a distinct threat model for its most powerful permission.

The same FDA toggle that lets an agent read your email lets it read your messages, your browser history, and any file your user account can see. Until Apple’s new controls land, every Mac user with an agent installed has the same decision to make: keep FDA on and accept that the agent - and any process that can compromise it - can read the same surfaces, or turn FDA off and accept that the agent cannot do the work it was installed for.

For agent vendors, the writing is on the wall in both Apple’s statement and Wardle’s research. Agents that need FDA to function will face new friction every time a user tries to grant it, and bugs in those agents will land on a more visible stage.

The Bottom Line

Apple is the first major desktop OS to rewrite a core privacy permission specifically because of how AI agents behave, and the change was triggered by a real incident. Until the new FDA flow ships, every Mac user with an AI agent installed should treat the FDA toggle as the most consequential permission on the machine, and turn it off when they do not need it.