Apple prepares stricter macOS Full Disk Access controls for AI agents

Apple says it will tighten macOS controls for Full Disk Access (FDA), warning that artificial intelligence agents and other applications can expose extensive personal data when developers use the permission without users fully understanding its consequences. The company has not provided a release date for the planned changes.
Full Disk Access is managed in Privacy & Security settings and was introduced with macOS Mojave 10.14. Once enabled, it lets an application bypass some normal security restrictions to read and write system files that would otherwise be unavailable. The permission can encompass data associated with Mail, Messages, Safari and Time Machine backups.
Apple targets explicit consent for privileged access
FDA remains important for software that needs deep system visibility, including security products and backup tools. Apple nevertheless said the setting largely bypasses protections intended to keep private data private. Its planned updates are intended to ensure this level of access is granted only through an explicit action by the user.
Apple highlighted a broader concern about increasingly capable and autonomous AI agents. An agent with broad operating-system permissions may handle files, communications and browsing information, while its integrations can also affect the privacy of people with whom the user communicates. The company said users should clearly understand those risks before making a decision about access.
Muse scrutiny illustrates the permission model
The announcement follows reporting about Meta's Muse agentic tool accessing a journalist's private iMessages after Full Disk Access was granted. Meta describes Muse as a personal AI agent that runs in a dedicated Linux virtual machine in Meta's cloud. Meta CTO David Singleton said Messages access requires two conditions: macOS system-level Full Disk Access and the Messages connector enabled in Muse.
Muse has also drawn security research attention. Patrick Wardle demonstrated a proof of concept called not-a-mused for a now-patched zero-day in the Muse Mac app. The issue could allow an app or terminal command to obtain a token used to authenticate a user to a Muse account. Wardle said an undocumented setting, endo_voyager_dictation_endpoint, could be exploited by an unprivileged local attacker to capture dictated audio and prompts, inject malicious prompts, and abuse access granted to Muse.
The pattern resembles risks documented in macOS living-off-the-land activity and AI-agent incidents involving macOS living-off-the-land activity and AI-agent incidents, where trusted local access can widen the paths available to attackers. Wardle was also credited with reporting CVE-2026-100754, a flaw in OpenAI's ChatGPT app for Mac that could have enabled takeover of the assistant and unauthorized access to chat logs and other application data.
What organisations should review now
Apple's change does not remove the need for legitimate high-privilege tools, but it underlines the sensitivity of granting them to agentic software. Organisations should inventory which macOS applications have Full Disk Access, identify the data and connectors each agent can reach, and remove permissions that are not essential. Before enabling an agent integration, teams should confirm that its requested system access and individual connectors match a defined business need.

