
What happened
Apple is rolling out new controls so apps can only get 'full disk access' on Mac through 'very explicit user action,' citing risks as AI agents become more capable and autonomous. The update follows a report by Inc's Jason Aten that Meta's Muse AI somehow knew his message contents.
Why it matters
The change tightens a macOS permission that gives an app access to a user's entire system — files, mail, messages and browsing history — and Apple says it has been used in ways that could expose that data without users' full knowledge and understanding, so this narrowing of access is likely to reshape how Mac apps obtain it.
What to watch
Apple hasn't said when the update will roll out, and its timing is likely to be measured against developers who rely on broad access for features like backup. Watch that rollout date, and whether the limits are enough to keep pace with more autonomous AI agents.
WHO IT HITSThis lands on Mac app developers who build AI agents and assistants that read local files, messages or browsing history, and on the Mac users whose data those apps can currently reach.
Summaries like this, in your inbox every morning.
The change arrives just weeks after Inc's Jason Aten reported that Meta's Muse AI somehow knew the contents of his messages, despite his not giving the chatbot explicit permission to access them on his iPhone or Mac. Meta spokesperson Andy Stone pushed back on that report, saying access to Messages is 'entirely opt-in' and that users must 'enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content.' That dispute is part of the backdrop Apple is now responding to.
At the center of the matter is a macOS permission Apple describes as 'largely sidestep' of the privacy controls users are normally offered — one the company says exists so backup apps can function properly on Mac. Apple's stated concern is that some developers use Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages and even browsing history, without full knowledge and understanding. The company also frames its move as a response to AI agents becoming increasingly capable and autonomous, warning that the risks associated with this level of access will grow substantially.
What remains unresolved is timing and degree. Apple hasn't said when it plans to roll out the update, and the test is likely to be whether these controls meaningfully change how apps obtain such sweeping access without breaking the backup-style functions the permission was designed to serve — a balance that developers relying on broad access will be watching closely.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Google said free Gemini app users will be restricted to the "Flash-Lite" model starting October 9; "Flash" nee…

Indie developer Robert Varadan argues that AI models like Opus 5.5 and GPT-6 Astra can clone game demos from a…

David Robinson, who led safety reporting on OpenAI's main products, resigned, saying the company's culture is…

A developer published Rai, a small Rust engine that runs language models on an ordinary PC's CPU, using only t…

The developer published fk2000/minecraft-ai-bot, which uses Jev to assemble instructions, Gemini to pick from…

On September 22, 2026, Anthropic announced Claude Opus 5.5 at $4 input / $20 output per million tokens, then O…
