Apple has confirmed it is overhauling the way macOS handles Full Disk Access, the system-level permission that allows applications to read almost anything stored on a Mac. The change, announced on Friday, targets third-party developers that Apple says are leveraging the privilege in ways that expose data users never meant to share, message histories included.

The timing is not incidental. The announcement arrives roughly two weeks after a tech columnist described an unsettling encounter with Meta's general-purpose AI agent, Muse, and it lands in the middle of an intensifying argument over how much of a person's digital life an autonomous assistant should be able to see.

How the Muse Incident Unfolded

Tech columnist Jason Aten reported that Meta's Muse agent sent him an unsolicited notification that referenced a conversation between him and a coworker conducted over Apple Messages. According to his account, he had never granted Muse permission to read his messages and had assumed that content was off-limits to the assistant entirely.

The claim resonated quickly. Over the following week, social media filled with users who said the episode confirmed a broader fear: that AI assistants handed access to calendars, email, messaging, shopping accounts and other resources have quietly become some of the most sensitive software on a personal computer.

The Power-Tool Comparison

A recurring analogy in that discussion compared agentic AI to a skill saw or another power tool. Such tools are genuinely capable and often useful, but they can cause serious damage when handled carelessly or given more reach than the task requires. Applied to an assistant with Full Disk Access, the comparison implies that the danger is not malice so much as an enormous capability surface with very few guardrails around it.

Meta's Rebuttal

Meta's chief technology officer, David Singleton, entered the debate with a rebuttal that on its face sounded persuasive. He argued that for Muse to reach Apple Messages, a user must deliberately grant two separate privileges. The first is Full Disk Access, the macOS system-level permission. The second is switching on a Messages connector inside the Muse application itself.

In Singleton's framing, the Messages integration in the Muse Mac app is opt-in, and Muse can only read message content when Full Disk Access has been granted at the system level and the connector has been enabled inside the app. The clear implication was that the columnist could only have been exposed if he had turned on both switches himself, and that responsibility therefore rested with him rather than with Meta.

A Security Expert Pushes Back

Not everyone found that explanation complete. Ars Technica spoke with macOS security specialist Patrick Wardle, who questioned the logic behind Singleton's denial. From a technical standpoint, Wardle argued, once an application holds Full Disk Access, essentially any non-root-owned file on the machine becomes readable to it, whether that means browsing history, browser cookies, chat logs or other personal data.

That raised a pointed question, which Ars put directly to Meta: if an app with Full Disk Access can read messages just like any other app holding the same privilege, how exactly could Muse be prevented from doing so? Meta's public relations team did not offer a new technical explanation. Instead, according to Ars, it re-supplied Singleton's original statement about the integration being opt-in and contingent on both the system-level permission and the connector setting.

Why Full Disk Access Is So Consequential

The dispute matters because of what the permission actually grants. Full Disk Access is not a narrow, app-specific key. It is a broad master credential that macOS reserves for software with a legitimate need to roam across a user's storage. Once granted, it can open the door to:

  • Message databases and conversation threads stored locally on the Mac
  • Email archives and account data held by desktop mail clients
  • Web browsing history and the cookie stores that underpin logged-in sessions
  • Documents, downloads, backups and other files scattered across the disk
  • Configuration and cache data belonging to entirely unrelated applications

Because the permission is granted at the operating-system level rather than per-file, a user who approves it once is effectively trusting an app to behave responsibly across all of that material indefinitely.

Apple's Response and What Changes

Apple is now positioning itself as the party clearing up the ambiguity. In explaining why it would change the Full Disk Access permission setting, the company said that some developers are using the permission in ways that could put users at risk, exposing everything on a system, including files, mail, messages and even browsing history.

The practical effect is likely to be a narrower, more deliberate consent model for the most sensitive permission on macOS. Rather than treating Full Disk Access as a single toggle that unlocks the whole disk, Apple's stated intent is to reduce how easily that access can be repurposed by apps that were never meant to reach personal communications.

The Bigger Fight Over Agentic AI

Beyond macOS, the episode illustrates a tension that every platform is now confronting. AI agents are only as useful as the data they can reach; an assistant that cannot read your calendar, mail or messages cannot schedule, summarize or remind. But the same connective tissue that makes an agent helpful also turns it into a potential surveillance layer if its permissions are broader than users understand.

Two things remain unresolved. The first is technical: how much of Meta's explanation survives scrutiny once independent researchers examine how Muse interacts with macOS permissions in practice. The second is procedural: whether an operating-system-level toggle like Full Disk Access is an appropriate gate for an entire class of autonomous software, or whether agents need a more granular permission model that reflects the specific resources they touch.

For now, Apple's move signals that the company no longer considers the status quo acceptable. Users who have granted broad access to an assistant, whether Muse or any other, may soon find that the operating system asks them more specific questions about what that agent can see, and why.

This article is based on reporting by Ars Technica. Read the original article.

Originally published on arstechnica.com