> ## Content Index
> Fetch the complete content index at: https://www.implicator.ai/llms.txt
> Use this file to discover other available public pages before exploring further.

# Apple Will Require Explicit Consent for Mac Full Disk Access, Citing AI Agent Risks
- URL: https://www.implicator.ai/apple-will-require-explicit-consent-for-mac-full-disk-access-citing-ai-agent-risks/
- Published: 2026-10-04T16:40:22.000Z
- Updated: 2026-10-04T16:40:22.000Z
- Description: Apple says Mac users will need to take very explicit action before granting apps Full Disk Access, citing AI agents. It named no app and gave no date. The post follows a dispute over Meta's Muse and Apple Messages, and Mac developers worry the change could hit their utilities.
- Author: Marcus Schuler
- Tags: AI News

Apple will add controls requiring Mac users to take “very explicit user action” before granting an app [Full Disk Access](https://developer.apple.com/news/?id=p6zjojqw&ref=implicator.ai), citing growing risks from AI agents. The permission “largely sidesteps” macOS privacy controls to let backup apps work and can expose files, mail, messages and browsing history. For communication apps, that access can also compromise the privacy of people exchanging messages with the user, Apple said.

The company announced the change on Friday, Oct. 2\. It gave no rollout date, macOS version or description of the controls, and named no app or developer. Apple declined to comment beyond its post.

What Changed

- Apple will require "very explicit user action" before a Mac app gets Full Disk Access, citing the growing risks from AI agents.
- Apple gave no rollout date, macOS version or description of the controls, and named no app or developer.
- About two weeks earlier, Inc. columnist Jason Aten said Meta's Muse referenced a private Messages thread; Meta says Muse needs both Full Disk Access and its Messages connector.
- Mac writers John Voorhees and John Gruber worry the controls could hamper utilities that are not backup apps.

AI-generated summary, reviewed by an editor. [More on our AI guidelines](https://www.implicator.ai/about/).

## The Muse permissions dispute

About two weeks earlier, Inc. columnist Jason Aten [said Meta’s Muse AI agent had referenced a private Apple Messages conversation](https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/?ref=implicator.ai) with a co-worker in an unsolicited notification. He said he had never given the assistant permission to read his messages. Meta disputes his account.

“You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” Meta spokesperson Andy Stone [wrote on X](https://www.channelnewsasia.com/business/apple-says-it-will-flag-ai-requests-mac-data-after-metas-muse-draws-complaints-6428346?ref=implicator.ai). “It can’t read your Messages unless you do this. And it can be revoked at any time.”

FREE AI BRIEFING · WEEKDAYS

Track what AI agents can reach on your devices.

Get the AI stories shaping the day, with concise context from San Francisco. The briefing takes about five minutes and arrives at 4:45 a.m. Pacific, 7:45 a.m. Eastern.

Email address 

Keep me informed 

Check your inbox for the confirmation link.

Free. No hype. Unsubscribe anytime.

Patrick Wardle, a software analyst at the Objective-See Foundation and longtime macOS researcher, questioned Meta’s assertion, saying Full Disk Access by itself makes any non-root file readable. “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc,” he told Ars Technica.

## Other agent security findings

On Sept. 21, Wardle disclosed a Muse configuration that allowed any app or code already running on a Mac to take control of the assistant. That included commands introduced through ClickFix attacks. An attacker could then reach the resources available to Muse.

On Sept. 25, OpenAI acknowledged a [flaw in its ChatGPT Mac app](https://www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/?ref=implicator.ai) and its fix in its system change log. Researchers at Wardle’s organization, the Objective-See Foundation, found the flaw. Exploiting it required malware already installed on the machine. Wardle called it “insanely trivial” to exploit; his proof of concept needed about a dozen lines of code.

Wardle also found a now-patched flaw in Muse’s dictation feature that could let a local attacker obtain a mishandled authentication token and access user data.

Know someone who'd find this useful? [✉️ Email it to a friend in one click](mailto:?subject=A%20newsletter%20I%20think%20you%27d%20like&body=This%20is%20one%20of%20maybe%20three%20newsletters%20I%20actually%20read.%20The%20rest%20just%20pile%20up%2C%20unread%2C%20judging%20me.%0A%0AAnd%20yes%2C%20this%20email%20mostly%20wrote%20itself%2C%20which%20is%20a%20little%20on%20the%20nose%20for%20an%20AI%20newsletter.%20Doesn%27t%20make%20it%20wrong.%20implicator.ai%20is%20good.%0A%0ASubscribe%20free%3A%20https%3A%2F%2Fwww.implicator.ai%2Fsubscribe%2F%3Futm%5Fsource%3Dnewsletter%26utm%5Fmedium%3Dforward%26utm%5Fcampaign%3Demail%5Fforward), or they can [subscribe free here](https://www.implicator.ai/subscribe/?utm%5Fsource=newsletter&utm%5Fmedium=forward&utm%5Fcampaign=forward%5Fto%5Fcolleague).

## Mac utilities depend on access

John Voorhees of MacStories called Apple’s [backup-apps framing](https://www.macstories.net/linked/apple-announces-plan-to-impose-new-full-disk-access-controls-on-mac-developers/?ref=implicator.ai) “nonsense.” Apps holding Full Disk Access on his MacBook Pro included the Finder replacement Bloom, Alfred, PopClip, Apple’s own Pixelmator Pro and Hazel. He said Apple’s concerns about agents were well-founded, while worrying that the controls, which Apple had not yet described, might restrict which kinds of apps could use the permission.

John Gruber of Daring Fireball [also expressed concern](https://daringfireball.net/2026/10/apple%5Ffull%5Fdisk%5Faccess?ref=implicator.ai) about how far Apple would lock down access. Several apps he uses “couldn’t function properly without it,” he wrote. He worried that, under the controls Apple had not yet described, requiring authorization every time they acted would severely hamper them.

Gruber estimated the worldwide Mac user base at around 150 million and wrote that most were “unsophisticated technically.” Many, he wrote, assume Apple protects them from dangerous permissions as it does on an iPhone, without understanding how much access they grant on a Mac.

“Apple needs to find a way enable reasonable customer protections without hamstringing the Mac’s utility,” Voorhees wrote.

Frequently Asked Questions

What is Full Disk Access on macOS?

It is a Mac permission that, in Apple's words, largely sidesteps macOS privacy controls so backup apps can work. An app holding it can reach files, mail, messages and browsing history. For communication apps, Apple says, it can also expose the privacy of the people a user exchanges messages with.

When will Apple's new Full Disk Access controls arrive?

Apple has not said. Its Oct. 2 developer post gave no rollout date, no macOS version and no description of the controls, beyond saying users will have to take very explicit action to grant the permission. Apple declined to comment beyond the post.

What does Meta's Muse have to do with the change?

Apple named no app. About two weeks before its post, Inc. columnist Jason Aten said Muse referenced a private Apple Messages conversation he never gave it permission to read. Meta spokesperson Andy Stone said Muse can read Messages only if users enable both Full Disk Access and its Messages connector. Researcher Patrick Wardle said Full Disk Access alone makes any non-root file readable.

Why are some Mac users worried about the change?

Many apps that are not backup tools use Full Disk Access. John Voorhees listed Bloom, Alfred, PopClip, Hazel and Apple's own Pixelmator Pro on his MacBook Pro and worried Apple might restrict which apps can use it. John Gruber worried that repeated manual authorization would hamper apps he relies on.

Have AI apps on the Mac had other security problems?

Yes. On Sept. 21, Wardle disclosed a Muse configuration that let any code running on a Mac take control of the assistant. On Sept. 25, OpenAI acknowledged a flaw in its ChatGPT Mac app, and its fix, in its change log. Wardle also found a now-patched flaw in Muse's dictation feature.

AI-generated summary, reviewed by an editor. [More on our AI guidelines](https://www.implicator.ai/about/).

[Nvidia Says Its New Agent Safety Platform Could Have Stopped the Hugging Face BreachNvidia launched its Open Agent Safety Platform on Monday and said it could have stopped OpenAI’s agents from breaching Hugging Face in July. The system pairs an open-source runtime that limits agent aThe Implicator![](https://www.implicator.ai/content/images/2026/09/nvidia-agent-safety-platform.webp)](https://www.implicator.ai/nvidia-agent-safety-platform-hugging-face-claim/)

[OpenAI Agent Broke Into Australia's Medicare Portal and Wrote Files, Albanese SaysAn OpenAI agent broke into an Australian government Medicare statistics portal on June 18 and reached non-public files, Prime Minister Anthony Albanese said. The internal model was researching public The Implicator![](https://www.implicator.ai/content/images/2026/09/20260924-032248-medicare_portal_officer.webp)](https://www.implicator.ai/openai-agent-broke-into-australias-medicare-portal-and-wrote-files-albanese-says/)

[OpenAI agent bypassed Medicare defenses; White House memo targets Dario AmodeiIMPLICATOR .ai Morning Briefing · From San Francisco Friday, September 25, 2026 11 stops From San Francisco 1 The Editorial Morning, humans. AI systems keep excThe Implicator![](https://www.implicator.ai/content/images/2026/09/20260924-215247-nl_open_gate.webp)](https://www.implicator.ai/openai-medicare-agent-white-house-amodei-memo/)