Apple Tightens Full-Disk Access to Block AI Misuse
Apple updates macOS privacy controls after a reporter discovered Meta's Muse AI reading his Messages without explicit permission.
Apple announced new macOS privacy settings designed to stop AI assistants from reading personal data without clear consent. The change follows a report that Meta’s Muse AI accessed a journalist’s Messages even though he said he never granted that permission. Apple’s response tightens the approval process for full‑disk access and for any connector that lets an app read Messages.
What Apple Changed
Apple’s update modifies the way third‑party developers request full‑disk access (FDA) on macOS. Previously, an app with FDA could read any non‑system file, including chat logs, browser history, and cookies. The new flow adds a second gate for apps that want to interact with the Messages database: a dedicated “Messages connector” toggle inside the app’s settings. Both the system‑level FDA permission and the app‑level connector must be turned on before any Message content can be read.
Apple’s engineering team explained that the change is meant to give users a clearer picture of what data an AI agent can see. When an app asks for FDA, macOS now shows a warning that the permission allows access to all user files. The additional connector prompt appears only for apps that request Messages data, so users can deny that specific integration while still allowing other legitimate file access.
Why It Matters for AI Agents
The controversy began when tech columnist Jason Aten received an unsolicited notification from Meta’s Muse AI that referenced a private thread in Apple Messages. Aten said he never enabled any setting that would let Muse read his messages, and his experience sparked a wider conversation about AI assistants that operate across calendars, emails, and shopping accounts.
Meta’s CTO David Singleton responded by pointing out that Muse can read Messages only if the user manually enables two privileges: full‑disk access and the Messages connector. He called the integration “opt‑in,” implying that the onus is on the user. However, macOS security expert Patrick Wardle argued that once an app has FDA, it can read any file, including Messages, unless the app itself enforces additional checks. Wardle’s comment highlights a technical gray area: the operating system grants broad file access, but the app must respect the extra connector setting.
For small‑business owners and nonprofit teams, the issue is practical. Many productivity tools now embed AI features that can draft emails, summarize meetings, or suggest actions based on past communications. If those tools obtain FDA, they could inadvertently expose sensitive client or donor information. The new Apple controls aim to make that risk more visible and give administrators a way to lock down AI integrations at the app level.
How to Protect Your Data
Take a few minutes to audit the permissions on each Mac in your organization. Follow these steps:
- Open System Settings > Privacy & Security > Full Disk Access.
- Review the list of apps that have FDA. Remove any that are not essential for daily work.
- For each AI‑enabled app, open the app’s preferences and look for a “Messages” or “Chat” connector. Disable it unless the feature is required.
- Enable FileVault encryption to add a layer of protection if a device is lost or stolen.
- Consider using a mobile device management (MDM) solution to enforce a policy that blocks FDA for non‑approved apps across all company Macs.
- Keep macOS up to date, as Apple may refine the permission dialogs in future releases.
By limiting both the system‑level permission and the app‑specific connector, you reduce the chance that an AI assistant can read private conversations without you knowing.
What to Expect Going Forward
Apple’s change is a response to a specific incident, but it signals a broader shift toward tighter privacy controls for AI features on consumer devices. Future macOS releases may introduce similar dual‑permission models for other data stores, such as Calendar or Contacts. Developers are likely to adapt by building clearer consent flows inside their apps, and users can expect more granular prompts when granting access.
For organizations, the practical takeaway is to treat AI‑enabled software as a new category of data processor. Conduct regular permission reviews, document which tools need full‑disk access, and train staff to recognize permission dialogs that request broad file access. Staying proactive now will help avoid surprises when the next AI‑related privacy update lands.
If you need help reviewing your Mac security settings or selecting AI tools that respect privacy, our team can provide a plain‑English audit and recommendations. Reach out through our AI roadmap page for a quick consult.
Sources
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.