Apple’s Disk Access Pivot: The First Real Admission of the Agentic Security Nightmare

AI-generated image · Bay Street Wire
By tightening macOS permissions in response to AI agent autonomy, Apple is signaling that the 'power tool' era of AI is a privacy disaster waiting to happen.
OPINION: For months, the industry has pitched 'agentic' AI as the ultimate productivity unlock—AI that doesn't just chat, but actually *does* things across your OS. But Apple’s latest move to tighten Full Disk Access (FDA) on macOS is the first real admission that this future is a security nightmare. As social media users recently noted, giving an autonomous agent the keys to your system is akin to installing a digital skill saw in your living room.
***
**The Catalyst: Meta’s Muse and the Permission Gap**
According to reporting from Ars Technica, the current friction began when Jason Aten, a columnist for Inc., reported that Meta’s general-purpose AI agent, Muse, sent him a notification referencing a private Apple Messages thread. Aten claimed he never granted Muse permission to read those messages.
Meta has fought back against these claims. Meta CTO David Singleton told Ars Technica that Muse can only read messages if a user manually enables two specific settings: the macOS system-level Full Disk Access and a specific Messages connector within the Muse app. Meta spokesperson Andy Stone echoed this to The Verge, stating the integration is "entirely opt-in."
However, macOS security expert Patrick Wardle told Ars Technica that from a technical standpoint, FDA allows any non-root file—including chat logs, browser cookies, and browsing history—to be readable, regardless of separate app connectors. This technical reality is underscored by a recent disclosure from Wardle regarding a Muse configuration that could allow any app or code running on a Mac to take full control of the AI assistant, potentially granting attackers access to the same resources Muse possesses.
**Apple’s Response**
Apple is now introducing broader changes to its system permissions. As reported by TechCrunch and The Verge, Apple announced it is introducing new controls for Full Disk Access to ensure that users who wish to grant this "extraordinary level of access" can only do so through "very explicit user action."
In a blog post for developers, Apple stated that some developers have used FDA to expose system files, mail, messages, and browsing history without the user's full understanding. Crucially, Apple explicitly linked this to the rise of AI, noting that as agents become more autonomous and capable, the risks associated with this level of access will "grow substantially."
**A Broader Pattern of Risk**
While Apple did not name Meta or Muse specifically in its announcement, the timing is telling. Ars Technica notes that Amazon has already blocked Muse from its platform, stating that such apps should respect service provider decisions.
This isn't an isolated incident of AI instability. TechCrunch reports that a Wired story recently highlighted a flaw in the ChatGPT Mac app that could have allowed hackers to access sensitive data.
Apple's FDA feature was originally designed to allow backup apps to function, which The Verge reports "largely sidesteps" standard privacy controls. By forcing "explicit user action," Apple is finally acknowledging that the autonomous agent model is fundamentally incompatible with the legacy permission structures of the modern desktop.

