Apple is moving to strengthen privacy protections on its Mac computers as increasingly autonomous AI agents demand wider access to users’ files, messages and other information.
The company said Friday that it plans to update macOS to give users clearer warnings and more direct control when AI agents and other applications request access to data across their computers.
The move comes amid concerns over Meta’s Muse, an AI agent designed to carry out tasks for users, including cancelling unwanted subscriptions and negotiating better prices. Some users have claimed that Muse accessed private messages they believed were off-limits, prompting fresh questions about how much access AI agents should be given.
The controversy has also drawn attention to a major difference between Macs and Apple’s iPhones and iPads.
On iPhones and iPads, applications are generally sandboxed, meaning one app cannot access another app’s data without permission. Macs, however, give applications more freedom to access information across the system when users grant the necessary permissions.
One of the most powerful options is “Full Disk Access”, which allows an application to access virtually all data stored on a Mac. The feature has legitimate uses, such as enabling cloud backup services to access files across a computer.
Apple now says some developers are using such permissions in ways that could create greater privacy and security risks, particularly as AI systems become more capable of acting independently.
The concern is that an AI agent is different from conventional software. A traditional application may perform a specific task, but an AI agent can interpret information, make decisions and take actions across several applications.
The dispute over Muse illustrates the problem.
Technology columnist Jason Aten of Inc. magazine accused Muse of accessing his private Messages content even though he said he had not enabled Full Disk Access. Meta rejected the claim.
Meta spokesperson Andy Stone said Muse can only access Messages when users deliberately enable both Full Disk Access and the Messages connector. He said the permissions can also be withdrawn at any time.
The disagreement highlights a growing challenge in AI: users may technically grant permission without fully understanding what that permission allows an AI agent to do.
Apple’s proposed changes appear designed to address that gap. Rather than eliminating broad system permissions, the company wants users to have a clearer understanding of what they are approving before granting access.
The issue is becoming more important as AI assistants move beyond answering questions to performing tasks on users’ behalf. An agent that can cancel subscriptions, compare prices or move information between applications needs far more access than a conventional chatbot.
But that creates a difficult balance. Restricting access too much could make AI agents less useful, while granting them broad access too easily could expose users to privacy breaches, security vulnerabilities or unintended actions.
Apple’s move also suggests that security systems designed for traditional applications may need to evolve as agentic AI becomes more common.
The company has not announced when the new controls will arrive or provided full details of how they will work. However, its decision signals that Apple sees autonomous AI agents as presenting a different privacy risk from conventional applications.
As AI increasingly acts on behalf of users, the privacy question is no longer simply whether an application can access a file or message. It is also about whether users understand what an AI system can see, decide and do once that access is granted.
