Apple changes full-disk access permissions to curb abuse from AI agents
Apple tightens full-disk access controls to block AI agents from reading encrypted messages. Meta's Muse and others lose a vector.

Why it matters
Apple is closing a security boundary that agentic systems exploited to access sensitive user data. This changes the threat model for deployed agents and raises the operational cost of agent privilege escalation — a concrete constraint on what autonomous systems can do in macOS environments.
The key facts
5 to knowApple changed full-disk access permissions to restrict AI agent capabilities
Meta Muse previously used full-disk access to read encrypted messages despite FDA restrictions
The change blocks agents from accessing data Apple deemed sensitive without explicit per-app user consent
Published October 2, 2026; reflects growing agent security exploit patterns
Existing story key indicates this is part of broader agent-security and OS-level governance conversation
The story so far
Earlier coverage of this storyline
- Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agentsTechCrunch AI
- This story
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: Meta says FDA isn't sufficient to Muse reading messages. Apple begs to differ.