Generated by Codex with GPT 5.6 Sol High
Techmeme surfaced Apple’s October 2 developer notice, “Updates to Full Disk Access in macOS”. Apple says it will add controls that make granting this permission require unusually explicit user action, because AI agents turn a broad but historically specialized capability into a much larger privacy risk. The announcement is short and leaves the design unfinished, but its premise is important: consent that was barely adequate for conventional software becomes weaker when the recipient can plan, infer, and act on its own.
A permission designed as an exception
macOS normally asks separately before apps can reach protected locations such as Documents, Downloads, Desktop, iCloud Drive, and network volumes. Apple’s platform-security documentation says applications have needed user consent for those areas since macOS 10.15, while full-storage access has required a manual change in system privacy settings since macOS 10.13.
Full Disk Access is deliberately different. Backup and security tools may need to inspect an entire machine, so the permission largely bypasses those ordinary boundaries. Apple now warns that some developers are using it in ways that expose files, mail, messages, and browsing history without users fully understanding the scope. For communication data, one person’s approval can also expose people who never made a choice at all.
That breadth has always been sensitive. Agents change the threat model because access is no longer exercised only through features a person deliberately invokes. A persistent assistant can scan many sources, combine details across them, react to new events, and take follow-up actions. A single approval in Settings can therefore become authorization for behavior the user did not specifically imagine at the moment of consent.
The result is a mismatch between system policy and product interface. An agent may present a narrow connector—messages, calendar, or mail—while the operating-system permission beneath it grants much more. Product-level toggles can express the developer’s intended behavior, but the OS must still defend against bugs, compromised code, misleading interfaces, and instructions that cause an agent to use capabilities outside the immediate task.
The Muse dispute shows the ambiguity
Apple did not name Meta or its Muse agent. The timing nevertheless follows a public dispute in which journalist Jason Aten said Muse referenced private Messages conversations despite his decision not to connect Messages. Meta replied that reading Messages requires both macOS Full Disk Access and an enabled Muse connector, and that the integration is opt-in. Aten said Full Disk Access was off and suggested Muse may instead have processed notification text. The available reporting does not establish exactly what happened.
The disagreement is still instructive. Meta described three permission steps and a forced app restart as evidence that the user could not grant access accidentally. But more prompts do not necessarily create precise consent. If a system-level switch unlocks a large data surface and an app-level switch promises to narrow it, users must understand which boundary is technically enforced and which depends on the application behaving as advertised.
Security researcher Patrick Wardle told Ars Technica that Full Disk Access makes ordinary non-root files—including chats, browser history, and cookies—readable. Ars also reported that Wardle had disclosed a separate Muse configuration through which injected commands could take control of the assistant and inherit its access. Those claims do not prove Aten’s account, but they illustrate why an agent’s effective authority includes both its permissions and every path by which its instructions can be manipulated.
A promise, not yet a protection
Apple has not said what the additional controls will be, when they will arrive, or whether existing grants will change. The notice promises more explicit action, not per-file scopes, time limits, just-in-time approval, read-versus-write separation, or a public record of what an agent accessed. It also does not explain how backup software, enterprise management, accessibility tools, or other legitimate users of Full Disk Access will be affected.
That missing detail matters because consent friction and capability restriction solve different problems. A stronger warning can reduce casual grants, while narrower and revocable permissions can limit damage after a mistaken grant, software defect, or attack. Agents need both: interfaces that make the stakes legible and technical boundaries that keep a broad objective from silently becoming broad authority.
The durable lesson is that autonomy changes the meaning of access. Traditional permission systems ask whether an application may reach a resource. Agentic systems also need to ask for which task, for how long, under whose immediate supervision, and with what audit trail. Apple’s announcement recognizes that the old binary grant is becoming too coarse. Whether macOS actually closes the gap will depend on the controls Apple has not yet described.