Apple announced on October 2, 2026, that it will introduce additional controls on macOS's Full Disk Access permission, the system-level setting that lets apps reach files, mail, messages and browsing history on a Mac. In a post on its Developer website, the company said some developers are using the permission in ways that put users at risk, exposing data "without users' full knowledge and understanding."
The announcement follows a claim by Inc. columnist Jason Aten, who said Meta's Muse AI agent on Mac sent him an unsolicited notification referring to a private conversation he had over Apple Messages, a permission he says he never granted. Meta disputes that reading messages is possible without two opt-in settings, and Apple has not named any app or developer.
Why Apple is changing Full Disk Access
Apple says Full Disk Access was built so backup apps could work properly, and that it largely bypasses the usual privacy controls. According to the company, granting it to a communication app can also compromise the privacy of the people the user talks to.
The stated trigger is AI agents. Apple warned that as these tools become "increasingly capable and autonomous," the risks of broad disk access will grow substantially. Going forward, it says users who truly want to grant an app this "extraordinary" level of access will only be able to do so through "very explicit user action."
Apple has not shared specifics on what those new controls will look like or when they will arrive, and did not respond to TechCrunch's request for comment on the change.
AI agent privacy worries: Muse and ChatGPT for Mac
Meta CTO David Singleton pushed back, saying the Messages integration in the Muse Mac app is opt-in and requires both macOS Full Disk Access and the Messages connector to be enabled. macOS security researcher Patrick Wardle questioned that defense, noting that any app with Full Disk Access can read non-root files, browsing history, cookies and chats.



