Apple to tighten Mac Full Disk Access rules amid AI agent privacy fears
Synopsis
Key Takeaways
Apple has announced plans to significantly tighten controls around Full Disk Access on Mac computers, following growing concerns that a new wave of AI agent apps — including Meta's Muse — are accessing users' private data far beyond what most people knowingly permit. The move marks one of the most consequential Mac privacy policy shifts in recent years, arriving as agentic AI tools become mainstream consumer products.
What Is Changing and Why
Full Disk Access is a Mac permission tier that, when granted, allows an application to read virtually every file on a user's system — from personal messages to local documents. It was originally designed to enable backup utilities and system tools to function properly, effectively bypassing Apple's usual data-protection controls.
Apple acknowledged the structural tension in a public statement: 'Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac.' The company said some developers are now exploiting that loophole in ways that could put users at risk, 'exposing everything on their systems without users' full knowledge and understanding.'
Under the revised approach, Apple will introduce more explicit prompts requiring users to take a clear, deliberate action before any third-party application can obtain that level of system access. These prompts will specifically identify which part of the system the app is requesting access to, rather than presenting a generic approval dialogue.
The AI Agent Trigger
Meta's Muse, one of the AI agent apps at the centre of the controversy, has reportedly surpassed 5 million downloads. Users have raised complaints that the app — while capable of performing complex autonomous tasks such as cancelling unused subscriptions — can also read what users assumed were private messages, using Full Disk Access as its mechanism.
This comes amid a broader industry shift toward AI agents that operate autonomously across a device, executing multi-step tasks with minimal human input. Notably, such capabilities inherently require deeper system access than conventional apps, making the permission gap acutely visible for the first time at consumer scale.
Apple warned that 'the risks associated with Full Disk Access will grow substantially as AI agents become increasingly capable and autonomous,' and added that for communication apps, broad data access 'can also compromise the privacy of the people users are communicating with' — not just the device owner.
Apple's Position on Developer Responsibility
Apple stressed that it provides developers with 'powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users' private data.' The company framed the tightened prompts as a mechanism to enforce that those controls are not circumvented, rather than a restriction on legitimate development.
The company said it is 'committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.'
Broader Context: Apple, AI, and India
The announcement arrives as Apple continues its expansion across global markets, including a strengthened push in India, where Unified Payments Interface (UPI) accounts for over 80 per cent of digital payments volume. With India emerging as a fast-growing market for premium devices and AI-enabled services, the privacy assurances underpinning Apple's ecosystem carry increasing commercial weight in the region.
The timing also reflects a wider regulatory moment: data protection authorities in multiple jurisdictions are scrutinising AI agent apps that access local device data, and Apple's move could set a precedent for how platform owners respond. Exact implementation timelines for the updated Full Disk Access prompts have not yet been disclosed by the company.