Apple to Tighten Mac Full Disk Access Prompts After Muse Privacy Dispute
Apple will require explicit user action before Mac apps can claim Full Disk Access, following Inc columnist Jason Aten's claim about Meta's Muse.

Apple to Tighten Mac Full Disk Access Prompts After Muse Privacy Dispute
Apple will require explicit user action before Mac apps can claim Full Disk Access, following Inc columnist Jason Aten’s claim that Meta’s Muse read his private messages. Meta says the access is entirely opt-in.
Apple said on Friday that it will change macOS so apps can’t obtain Full Disk Access, the system permission that lets software read nearly everything on a Mac, without users clearly understanding what they are granting. The announcement, reported by Reuters, follows public complaints that Meta’s Muse, an AI agent that carries out tasks on users’ behalf, accessed private messages on at least one user’s Mac.
“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” Apple wrote in a post, according to Reuters. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”
Apple’s post did not name Meta or Muse, and the company declined to comment beyond the post. But Reuters described the change as a direct response to the complaints.
Why Full Disk Access Matters
On iPhones and iPads, sandboxing means no single app can read data inside another app by default. Macs are more flexible: Full Disk Access lets apps such as cloud backup services read files anywhere on the machine, with the user’s permission. Apple said on Friday that some developers were using the permission “in ways that could put users at risk.”
The Muse Dispute Behind the Timing
The complaints center on Inc technology columnist Jason Aten, who said Muse referenced private iMessage conversations (including texts with his podcast co-host about new iPhones and a message from his editor) even though he had declined Messages access during setup.
When Aten asked Muse how it knew about the conversations, the agent said it had only seen incoming notification previews, not his message history. Aten later reported that Muse had in fact synced roughly 187,000 rows from the local Messages database on his Mac mini, and that Messages access appeared enabled inside Muse’s own settings despite his refusal, according to 9to5Mac’s account of his column.
Meta’s Response
Meta spokesperson Andy Stone pushed back on X last week, writing that the Messages integration in the Muse Mac app is “entirely opt-in.”
“You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” Stone wrote. “It can’t read your Messages unless you do this. And it can be revoked at any time.”
David Singleton, an executive with Meta Superintelligence Labs, wrote on Threads that Messages access requires three separate steps (granting Full Disk Access, selecting a Messages access level inside the Muse app, and confirming the choice in macOS, which restarts the app), and said a bug in Muse could not bypass those protections, according to a summary of the exchange.
Reuters reported that Meta did not immediately respond to its request for comment.
What It Means for Muse Users
The core dispute remains unresolved: Aten says he never granted the access; Meta says the access is impossible without it. Apple’s move sidesteps that question and instead raises the bar for every AI agent on the Mac, including Muse.
Mac users running Muse can check exactly what they have granted in System Settings under Privacy and Security, and inside the Muse app’s own connector settings. Our beginner’s guide to AI agent privacy and safety walks through how to review those grants. The dispute also landed a week after a zero-day in the Muse Mac app showed how much damage a compromised agent could do.


