Apple Restricts macOS Full-Disk Access After Meta Muse Privacy Controversy
Apple is updating macOS privacy settings to block third-party AI apps from abusing full-disk access to read user messages, following a dispute over Meta's Muse assistant.

Apple has announced plans to modify macOS privacy settings in an effort to prevent third-party application developers from misusing system permissions to access user message histories. This decision follows a public dispute regarding how AI assistants handle sensitive local data, highlighting the tension between software capabilities and user privacy on desktop operating systems.
The change was prompted by an incident involving tech columnist Jason Aten and Meta's new general-purpose AI agent, Muse. Aten reported receiving an unsolicited notification from Muse that referenced an Apple Messages conversation between himself and a colleague. According to Aten, he had never granted the AI agent permission to read his private messages and believed that this data was entirely restricted. The incident sparked widespread discussion online, with many comparing AI assistants that have access to emails, calendars, messages, and shopping accounts to powerful tools that can cause real harm if not managed with extreme caution.
The Dispute Over Consent and Access
In response to the controversy, Meta Chief Technology Officer David Singleton defended the AI assistant's behavior. Singleton stated that for Muse to access Apple Messages, users must manually enable two distinct settings. First, they must grant the app system-level Full Disk Access (FDA) within macOS. Second, they must turn on a specific Messages connector within the Muse application itself.
According to Singleton, "The Messages integration in the Muse Mac app is opt in," and "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." The implication of this defense was that the columnist must have enabled both settings himself, shifting the responsibility away from Meta.
However, security professionals have raised doubts about this explanation. Patrick Wardle, a prominent macOS security expert, questioned the technical validity of Meta's defense. Wardle pointed out that once an application is granted Full Disk Access, it technically possesses the ability to read virtually any non-root file on the system, regardless of secondary in-app settings. Wardle explained, "From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc."
When asked to clarify how Muse could be prevented from reading messages once Full Disk Access was active—given that any other application with the same privilege could do so—Meta's public relations team declined to provide a technical explanation, choosing instead to repeat Singleton's original statement.
What it means for developers
Apple's decision to restrict full-disk access permissions signals a tighter, more sandboxed future for macOS applications, especially those utilizing AI. Developers building desktop integrations must prepare for an environment where broad system-level permissions are heavily scrutinized or restricted entirely. Relying on extensive local directory access to feed context to AI models will become increasingly difficult as Apple implements these new privacy safeguards.
To adapt to these tightening platform-level restrictions, developers may need to shift their architecture away from broad local file access and toward more controlled, API-driven data pipelines. For those looking to integrate advanced language models into their workflows without dealing with the complexities of managing native system permissions for multiple different AI providers, platforms like Apixo offer a streamlined alternative. Developers can access top AI models cheaply on a pay-per-token basis through a single API key at https://apixoai.online, allowing them to focus on secure data handling rather than platform-specific permission workarounds.
Ultimately, the macOS update serves as a reminder that developers must design their applications with data minimization in mind. As operating systems limit what third-party apps can see, building user trust through transparent data access and secure API integrations will be paramount for the next generation of AI tools.
Source: Apple changes full-disk access permissions to curb abuse from AI agents — Ars Technica AI. Written by the Apixo team from that report.
One key for Claude, GPT, GLM, DeepSeek and more. Pay per token with crypto.
Get your API key

