AI News Feed
Market watch
Cybersecurity

Apple to tighten macOS Full Disk Access controls over AI agent risks

Apple plans new controls for macOS Full Disk Access after saying some developers expose user data, with AI agents cited as a main risk. The move follows reports about Meta's Muse AI agent, while new Siri privacy settings and an Apple Intelligence removal tool show users gaining more control.

Full Disk Access can give an app access to files and documents, emails, messages, browser history and other data on a Mac. Apple said: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems." It added: "We will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action." Apple did not detail the new interface or timing. TechRadar reported that there is no indication the changes are included in the beta version of the upcoming macOS 27.2, though both beta versions predate the October announcement.

TechRadar reported that the change was likely triggered by a recent report that Meta's Muse AI agent had accessed a user's messages. Meta spokesperson Andy Stone said in a post on X that both Full Disk Access and the Messages connector are "entirely opt-in" for each user, according to TechRadar. 9to5Mac, citing Wired, reported that security researcher Karan Joshi found Meta had instructed Muse to extract information needed to construct a complete map of a user's relationships. The instructions reportedly called for creating "a page for every person in the user's life" and described an hourly process compiling data on family, partners, friends, colleagues, collaborators and people the user follows. The data could include where people live, what they do, recurring threads, birthdays, anniversaries and relationship history, according to 9to5Mac's account of the instructions. Meta launched Muse as a Personal AI Agent for iPhone and Mac, and the app quickly rose to the top of the App Store, 9to5Mac reported.

9to5Mac argued that Apple needs to warn users far more explicitly before they grant Full Disk Access, saying the existing permission prompt does not communicate the gravity of giving an app an "access-all-areas pass" to a Mac. It said Apple should not repeat the approach it took with screen recording in macOS Sequoia, which forced users to confirm permissions weekly and after every restart. In that view, Apple can issue the strongest warnings, but macOS should accept a user's decision without forcing repeated confirmations.

The Full Disk Access debate is part of a broader set of privacy controls around Apple's AI features. Engadget reported that with iOS 27, Apple has begun rolling out a redesigned Siri that requires a waitlist. The new Siri AI can provide more personalized responses because a framework called App Intents allows Apple Intelligence tools, including Siri, to access data from apps on Apple devices. When Siri AI is enabled on an iPhone, iPad or Mac, Spotlight and Siri are unified under one interface, and by default Siri can search Apple apps including Notes and Messages for information relevant to a query. If a developer supports App Intents, Siri can scan that app too. Siri AI uses a combination of on-device models and Apple's Private Cloud Compute infrastructure, meaning some requests may be processed on remote servers. Apple says it does not store data sent to PCC after processing a request and cannot see the data.

Engadget said users can limit Siri's access by opening Settings, tapping Apps, selecting an app, tapping Search and toggling off Show Content in Search. After that, Siri will not pull information from that app, even if asked directly. The report also noted that on-screen awareness lets Siri read screenshots and images, which can be useful but may send content to PCC servers, and that users can check Privacy & Security, then Analytics & Improvements, to disable Improve Siri & Dictation if it is on. Engadget said users can also revert to the older version of Siri.

Separately, The Verge reported that an open-source command line tool called RemoveMacAI lets macOS users delete Apple Intelligence data. The Verge said macOS 27 removed a single Settings toggle for disabling Apple Intelligence, leaving models on disk and splitting features across different settings panes. RemoveMacAI, spotted earlier by MacRumors, turns off Siri, Writing Tools, Genmoji, Image Playground, the ChatGPT extension and summaries, then deletes the models and stops macOS from downloading them again, according to the developer. The developer said the models take up "about 12GB" and that changes persist across macOS updates, while Dictation still works. A "removemacai revert" command can turn everything back on, and a "removemacai status" command shows the size of each AI model. The Verge noted that some users reported more than 12GB; on the author's MacBook Air, Apple Intelligence was listed at 35.05GB.

Editor's Summary

Apple is tightening macOS Full Disk Access controls after saying some developers expose user data, with AI agents cited as the main concern. The move follows reports about Meta's Muse AI agent mapping users' relationships, while Apple's new Siri and third-party tools such as RemoveMacAI show users are gaining more ways to limit or remove AI access to their data.