
Apple announced new controls for macOS Full Disk Access following reports that AI agents like Meta's Muse and ChatGPT's Mac app could access private messages and sensitive data without explicit user permission, citing growing risks as AI becomes more autonomous.
AI-generated summary
Reports emerged that AI agents such as Meta's Muse and ChatGPT's Mac app could access private messages and sensitive data through macOS Full Disk Access settings, prompting user privacy concerns.
Days after a journalist claimed that Meta’s Muse app on Mac read their private messages — a claim that Meta disputed — Apple announced that it’s introducing additional controls around a setting called “Full Disk Access” on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased “the risks associated with this level of access,” Apple said.
Apple’s statement comes shortly after Inc. columnist Jason Aten reported that Muse knew the content of his private messages — even though he claimed to have not given the AI agent permission. The report raised questions about the level of security and trust users have in desktop-based AI, which can control things on their systems and read their files and messages.
The decision to limit the Mac feature also comes after a Wired report cited that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data.
AI agents that run on the desktop allow users to provide their respective apps with greater access to the files, messages, and other personal content on their computers by adjusting macOS settings.
In Muse’s case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems… without users’ full knowledge and understanding,” Apple said in a new blog post aimed at developers.
The company says that, going forward, it will introduce new controls aimed at ensuring that users who “genuinely wish to grant an app this extraordinary level of access” can do so only with “very explicit user action.”
“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple wrote.
Apple did not immediately respond to TechCrunch’s inquiry about the feature change.
AI outlook — possibilities, not facts
Apple will release the new Full Disk Access controls in a future macOS update
Likely · Within weeks

OpenAI's new AI agent platform Dots, featuring customizable blob avatars, is positioned as enterprise-focused software for automating work tasks rather than personal errands, with testing showing strengths in workflow automation but weaknesses in navigating consumer websites due to security checks, requiring manual intervention for tasks like online ordering and account logins.

Circuit Breaker Labs, a TechCrunch 2026 Startup Battlefield finalist, uses AI agents simulating diverse users to test models for psychological safety risks, motivated by lawsuits linking chatbots to youth suicides. The startup aims to prevent AI from enabling harmful parasocial relationships through adversarial testing and explainable scoring.

Creators who previously avoided Substack's 10% transaction fee are now facing a new price increase of at least $10 per month, according to The Verge Daily.

Pope Leo XIV has issued a statement on X distinguishing human art from AI-generated content, arguing that algorithms lack the 'spark of humanity' found in human creation. This follows his May encyclical on human dignity in an age of automation.

The .si domain, associated with Slovenia, is seeing a massive registration surge after a U.S. executive order mandated government agencies refer to AI as 'super intelligence.' Registrars report thousands of new sign-ups, driven by speculation and branding.

Epic has paused most product development for six weeks to remediate security flaws in its MyChart software. The vulnerabilities, identified by an AI model, could potentially allow unauthorized access to patient records without triggering system logs.