AI · Oct 2, 2026
Apple will limit Mac disk access as AI agents ‘substantially’ increase riskApple changes full-disk access permissions to curb abuse from AI agents
Oct 2, 2026, 4:03 PM · Ars Technica

After Muse’s Messages scare and Meta’s “you opted in” defense, Apple is rewriting full-disk access so AI agents can’t treat FDA like a master key users never meant to hand over.
Why it matters
Ars Technica’s Dan Goodin reports Apple is changing macOS Full Disk Access after a two-week fight over Meta’s Muse. Columnist Jason Aten said Muse referenced an Apple Messages thread he never knowingly unlocked; Meta CTO David Singleton replied that Messages requires both FDA and an in-app Messages connector — implying the user opted in.
macOS security researcher Patrick Wardle told Ars that FDA already makes non-root files readable — browsing history, cookies, chats. Apple’s Friday statement didn’t name Meta, but said some developers use FDA in ways that expose files, mail, messages, and history “without users’ full knowledge,” and that as AI agents get more autonomous those risks “will grow substantially.”
From the desk
We’re taking Apple’s timing seriously even if the statement is carefully nameless.
Singleton’s opt-in story and Wardle’s technical read can’t both be comforting. If FDA is the skeleton key, a secondary “Messages connector” toggle is product theater unless the OS enforces it. Apple is effectively saying the permission model failed the informed-consent test — backup-era privileges colliding with agent-era autonomy.
Useful agents will still need deep access to do real work. The fix isn’t banning agents; it’s making extraordinary access look extraordinary. Apple promising clearer understanding before grant is the minimum. The harder question is whether FDA remains a single all-or-nothing switch while agents can read mail, messages, and history in one gulp.
This also sits next to Wardle’s earlier Muse finding: any local code with access to the assistant could ride its privileges, including via ClickFix-style injection. Amazon blocked Muse from its platform over participation norms. Pattern: Muse’s ambition is outrunning the trust architecture around it.
For users, the practical move is boring and right — revoke FDA you don’t remember granting, and don’t treat a cute agent prompt as a security boundary. For platforms, the practical move is finer entitlements. I’m watching whether Apple’s change is UI friction, cryptographic tightening, or both — and whether Meta updates its Mac app story to match Apple’s contradiction of the “connector-only” denial.
Context
Apple framed FDA historically as a way for backup apps to work around finer privacy controls. No ship date was given. Meta PR repeated Singleton’s line and didn’t answer Ars’s Friday questions.
Who feels it
- Mac users running AI agents
- Re-audit FDA grants now. An agent with FDA can see far more than a Messages toggle implies.
- Agent developers
- Expect “very explicit” FDA UX soon; design least-privilege connectors instead of treating full disk as the default integration path.
- Enterprises
- MDM and endpoint policy should treat AI clients with FDA as high-sensitivity apps, not chat toys.
What to watch
- Apple’s actual FDA UX change and whether it ships with a public timeline
- Meta’s response to Apple’s statement contradicting the connector-only framing
- Whether other agent apps quietly relied on FDA for mail/messages access
Companies: Meta