Skip to content

Apple tightens Full Disk Access on the Mac because of AI agents: Meta Muse reportedly read private messages without permission

1 min read
Share
Apple tightens Full Disk Access on the Mac because of AI agents: Meta Muse reportedly read private messages without permission

For years one macOS setting sat quietly in the background. It's called Full Disk Access, and it was created so that backup programs could do their job. Today it's how AI agents get access to files, mail, messages and even browsing history. Apple has now announced it is introducing additional controls, because agents, according to the company, have increased "the risks associated with this level of access".

The trigger isn't abstract. Inc. columnist Jason Aten reported that Muse, Meta's AI agent for the Mac, knew the content of his private messages, even though he says he never gave it permission. Meta disputed that. A few days later Apple came out with its announcement. On top of that came a Wired report about a flaw in the ChatGPT app for Mac through which hackers could have reached sensitive data.

Muse doesn't steal access - it asks for it. The agent offers the user the option to turn on Full Disk Access, and habit does the rest: you click "allow" to get the program working and move on. Apple admits exactly that. "Some developers use Full Disk Access in ways that can expose users to risk, revealing everything on their systems... without users' full knowledge and understanding," the company wrote in a new post aimed at developers.

The fix it is announcing is that users who "truly want to grant an app this exceptional level of access" will only be able to do so through a "very explicit action". What exactly the new controls will look like, Apple hasn't yet explained.

"This is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow significantly," the company added. True - but the setting existed before the agents did. For how many years did users click "allow" without knowing they were opening up their entire computer to someone else? And why was the lockdown only announced after a journalist complained publicly?

There's another side to the story too. Apple is the gatekeeper of its own platform, and Meta, OpenAI and the rest want their agents to live on precisely that platform. Every new access rule is also a rule about who gets to go how deep into someone else's house. The next time an agent asks for the keys to the whole computer, how many people will read what they're actually approving?