Apple Tightens Full-Disk Access Rules to Block AI Agent Overreach

Apple is adjusting full-disk access permissions after Meta argued the existing controls fall short for its Muse AI to read messages.

The news

Apple has changed how macOS handles full-disk access requests from applications. The update limits the default reach of that permission in response to concerns that autonomous AI agents could exploit it. The move follows an open disagreement between Apple and Meta over whether the prior permission model gave tools like Meta’s Muse AI enough visibility to read messages and files without extra workarounds.

Context

Full-disk access has existed on macOS for years as a single, high-privilege entitlement. Apps that receive it can read and write anywhere on the drive once the user grants approval in System Settings. Security researchers and Apple have long warned that the permission is difficult to audit once granted, because the app can act on any file without further prompts. Traditional uses included backup utilities and antivirus scanners that needed broad visibility. AI agents change the risk profile because they can decide on their own what to read, summarize, or transmit after the initial approval. Meta publicly stated that the existing full-disk access mechanism does not reliably allow Muse to inspect messages, while Apple maintained that loosening the control further would increase exposure without clear benefit.

Details

The revised rules require developers of AI agents to ask for narrower entitlements that target specific directories or message stores rather than the entire disk. Apple described the adjustment as a direct response to the new class of software that can operate without continuous user oversight. The company has not released the full list of restricted paths or new entitlement keys, but the change is already visible in recent macOS builds. Apps that previously relied on the broad permission for general file inspection must now request more precise access or accept reduced capability. Meta continues to argue that the updated permissions still fall short for Muse’s message-reading tasks and that additional workarounds will be necessary. No other major vendors have issued statements on the change.

Reactions / counterpoints

The public exchange between the two companies highlights differing priorities. Meta frames the permission limits as an obstacle to useful AI features that users might want. Apple frames the same limits as a necessary safeguard against overreach. The sources do not record statements from other developers or security firms, so the extent of industry agreement remains unknown.

Why it matters

The change forces developers to treat full-disk access as an exception rather than a convenient default when building agents that inspect user data. Teams that designed around the older model now face a choice between refactoring for narrower entitlements or shipping agents that request repeated, targeted prompts. Users receive a smaller attack surface if an agent is later compromised, yet they may encounter more frequent permission dialogs for tasks that once worked silently. Apple is effectively raising the bar for any AI product that wants blanket visibility into messages or files. The disagreement with Meta shows that at least one large company believes the tighter rules will slow down certain agent capabilities. Over time the policy favors agents that work within clearly bounded scopes and makes blanket-access designs more expensive to maintain on macOS.

---

Sources:

No comments yet