Apple says it will add stricter consent controls to macOS Full Disk Access, a permission that can expose files, email, messages and browsing history to an app. The company’s 2 October announcement links the planned change to risks from increasingly capable AI agents, but does not say when the added controls will arrive or how they will work.

macOS Full Disk Access can expose more than an agent needs
Apple says Full Disk Access was created largely to let backup apps work around macOS privacy controls. The permission gives an app unusually broad access to data stored on a Mac; Apple specifically lists files, mail, messages and browsing history. For a communications app, that can expose information about people who never installed it. The label is concise; the permission is not.
The company has not described a new technical limit or said that agents will be blocked from local data. Its announcement says it will add controls so users must take a deliberate action before granting this level of access and understand the risks. Apple has not published a design, release date, or list of macOS versions that will receive the change. TechCrunch reported that Apple did not answer questions about the planned change, while Ars Technica noted that the company gave no implementation timeline.
The existing control is listed under System Settings > Privacy & Security > Full Disk Access. Apple’s Mac user guide says users can review and change which apps have permission there. Users can remove access from tools that no longer need it, especially utilities installed for a one-off task.
The Meta Muse dispute remains unresolved
Apple’s announcement came after a journalist reported that Meta’s Muse assistant for Mac referenced a private Messages conversation. Meta disputed the account. Its response said the Messages integration requires both Full Disk Access and a separate Messages connector. The journalist said Muse referred to messages despite their belief they hadn’t granted that access, according to TechCrunch’s report on Meta’s response.
Ars Technica described the disagreement as a dispute over what the system-level permission allows and what Muse’s own connector does. According to Meta, Full Disk Access is a broad macOS permission, while the connector is a separate product setting. Apple’s 2 October note does not name Muse or any other developer.
The two controls answer different questions. macOS Full Disk Access decides whether an app can access protected data on the device; an app’s own setting can decide whether a feature uses or presents a particular category of that data. Meta says both are required for Muse to read Messages. Apple’s announcement focuses on the breadth of the system permission.
Tbreak has covered a separate security flaw in Meta Muse, which involved a local attack on the assistant rather than this Messages-access dispute. Mac apps that connect to personal data are not limited to Muse: ChatGPT for Mac can also work with Apple Messages, with access set up through the app and macOS permissions.
What Mac users can do now
The promised change isn’t a new toggle users can enable today. Until Apple ships it, the practical option is to review the existing Full Disk Access list and remove apps that do not need it. Before granting the permission, check why the app requests it, whether the feature depends on it and whether you trust the developer with access to data beyond the task at hand.
Does Full Disk Access itself upload or share my files?
No. Full Disk Access lets an app access local data; the permission alone doesn’t mean the app uploads or shares it. That depends on how the app handles data, so check its settings and privacy policy.
Does Apple’s announcement prove that Meta Muse read Messages without permission?
No. Apple did not name Muse or confirm the reported incident. Meta disputed the claim, saying Muse needs both Full Disk Access and its separate Messages connector; Apple’s announcement was a general warning about broad app access.
Will Apple’s planned controls apply only to AI apps?
Apple cited AI agents as a growing risk but framed the change around apps granted Full Disk Access. It has not said whether the controls will cover every app requesting the permission or only particular categories.
Does turning off an app’s Messages connector revoke macOS Full Disk Access?
Not by itself. An app’s connector and the macOS system permission are separate controls. Review the app under System Settings > Privacy & Security > Full Disk Access and remove the system-level grant there if you no longer want it.


















