Apple is preparing to tighten privacy controls on its Mac computers as autonomous AI agents seek access to data across applications, highlighting a growing problem for the technology industry: the more capable AI assistants become, the more access they need to a user’s digital life.
Apple said Friday that it plans to change its Mac operating system so that users receive clearer warnings and more explicit controls when AI agents or other applications request access to data across their computers.
The move follows criticism surrounding Meta’s Muse, an AI agent designed to perform complex tasks on behalf of users, including canceling unused subscriptions and negotiating for better prices. Some users have alleged that Muse accessed private messages they believed should have remained inaccessible.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
The controversy has put greater attention on a longstanding difference between Apple’s Macs and its iPhones and iPads.
On iPhones and iPads, applications are generally sandboxed, meaning one app cannot access another app’s data by default. Macs offer greater flexibility for applications that legitimately need broad system access. One example is the “Full Disk Access” setting, which allows an application to access essentially all data on a Mac when the user grants permission.
That flexibility was designed for legitimate use cases, including cloud backup services that need access to files across a computer. But Apple now says some developers are using the permission in ways that could expose users to greater risks, particularly as AI agents become more autonomous.
“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” Apple wrote in a post.
The wording points to a broader change in how Apple views system-level permissions. Full Disk Access was already powerful, but an ordinary application with broad access is fundamentally different from an AI agent that can interpret information, make decisions, and take actions across multiple applications.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple said. “We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”
AI Agents Create A New Privacy Problem
The dispute involving Muse illustrates why the issue is becoming more difficult.
Jason Aten, a technology columnist at Inc. magazine, accused Meta’s Muse of reading private messages on his Mac. Aten said he had not enabled Full Disk Access, raising questions about how an AI agent could obtain access to information stored within Apple’s Messages application.
Meta rejected the characterization.
Andy Stone, a Meta spokesperson, said last week that Muse’s access to Messages is strictly opt-in and requires users to enable both Full Disk Access and the Messages connector.
“You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” Stone wrote on X. “It can’t read your Messages unless you do this. And it can be revoked at any time.”
The disagreement reveals that AI agents are facing a major challenge: permission can be technically granted while remaining poorly understood by the person granting it.
Traditional software typically performs a defined set of tasks. An AI agent is designed to operate more broadly, interpreting information and taking actions in response to a user’s instructions. That makes broad permissions more useful, but it also increases the potential consequences if an agent is given access to sensitive information.
For users, the distinction between “the application has permission” and “the AI can now inspect and act on information across my computer” may not always be obvious.
Apple’s proposed changes therefore appear aimed not at eliminating broad permissions, but at making them harder to grant accidentally or without understanding their consequences. That is considered relevant as technology companies move AI assistants beyond question-answering into systems capable of acting on a user’s behalf. An agent that can cancel subscriptions, compare prices, or manipulate information across different applications needs considerably more access than a conventional chatbot.
The trade-off is straightforward but difficult to manage. Restrict access too aggressively and agents become less useful because they cannot interact with the applications and information needed to complete tasks. Allow broad access too easily and the potential damage from misuse, security vulnerabilities, or misunderstood permissions increases.
Apple’s decision also signals that operating-system security models designed before the rise of autonomous AI may need to evolve. Sandboxing works well when applications are relatively isolated, and users explicitly interact with them. AI agents blur those boundaries because their purpose is precisely to move between applications and information sources on behalf of the user.
The result could be a new layer of permission controls specifically designed around agentic computing rather than traditional applications.
Apple has not said exactly when the new controls will be introduced or detailed the final design. But its announcement suggests the company sees AI agents as creating a fundamentally different risk profile for broad system access.
The perception is expected to impact the company’s policy as agents move from assisting users to acting for them. The privacy concern has moved from an application accessing a file or message to users understanding what an autonomous system can do once that access has been granted.



