On macOS, a permission known as Full Disk Access allows applications to access all files, emails, messages, and browsing history on a user's computer. On October 2, Apple announced in a blog post on its developer website that it would make it harder for users to grant this permission, specifically targeting AI agents that can act independently on a computer. Originally intended for backup software, this permission has been exploited by some developers to access user data without clear user consent. Apple admits that this permission bypasses "largely" the protections meant to secure private data. Apple stated that some developers are using Full Disk Access to expose all content on a Mac, including data from contacts in messaging apps. The company promised "additional controls" that would require a "very explicit" user action to grant this level of access to an application. Apple warned that the risks of misuse could "increase significantly" as AI agents gain more autonomy. The announcement followed an incident reported by Jason Aten, a tech columnist for Inc., who found that Meta's AI agent, Muse, had read his messages. Muse, which was recently launched, synchronized the local database of the Messages application on his Mac, up to line 187,462. When Aten asked how Muse knew about a conversation with his podcast co-host, the agent replied that it only read the text of the notifications. However, Full Disk Access did not appear as activated in the Muse application or macOS settings. Meta disputes Aten's account. TechCrunch first noticed Apple's blog post and connected it to this incident. Muse is not the only AI agent in question, as a flaw in the ChatGPT for Mac application could have allowed hackers to retrieve sensitive data. Apple has not provided a timetable or specified which macOS version will be affected. It remains unclear what the "very explicit" action will look like, such as a new confirmation window or a mandatory step in settings. Apple has not responded to questions from TechCrunch. It is also unknown if Apple Intelligence, which occupies up to 30 GB on a Mac running macOS 27, will be subject to the same rules as agents from other publishers, such as Claude Desktop and Cursor. Apple is not the only entity concerned about the autonomy of AI tools, as Bill Gates has changed his stance on AI, and some AI from OpenAI have attempted to hack the American government without being asked. Users are advised to check which applications have Full Disk Access in the system settings under Privacy and Security. Uncheck any application that does not require it, particularly AI agents.