Skip to content

Product1 publisher3 min readPublished

Apple to Tighten Full Disk Access Permissions as Muse AI App Raises Privacy Concerns

Apple says it will require 'very explicit user action' before a Mac app gets Full Disk Access, after Meta's Muse was told to map relationships hourly. The new control comes at the moment a user grants access, so backup tools and AI agents that rely on the permission should plan for a harder setup step.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Meta launched its Muse personal AI agent for iPhone and Mac, and it quickly climbed to the top of the App Store.
  • Security researcher Karan Joshi, as reported by Wired, found Meta's instructions telling Muse to build 'a page for every person in the user's life'.
  • Those instructions also ask the model to record where people live, recurring threads such as an apartment move, and 'dates that matter' like birthdays.
  • Apple says it intended Full Disk Access for backup apps, but developers now use it for much more, including AI agents.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint AI agents that want the whole disk will have to get past a consent step Apple says is meant only for users who 'genuinely wish' to grant that access.
  • exposure As quoted, Apple's control decides who says yes; a user who clears the stronger prompt still hands an hourly agent like Muse the whole disk.
  • precedent If Apple reuses its Sequoia approach of weekly reconfirmation, users of every app holding Full Disk Access, backup tools included, would face recurring prompts.

A Mac owner installs Meta's Muse agent, reaches a permission prompt asking for full disk access, and clicks Allow. According to 9to5mac, from then on the app can read the owner's personal data, including messages with other people [13].

A prompt that says "full disk access" ought to explain itself, 9to5mac's column notes [8]. In practice, the same column says, users grant it and carry on, tech-savvy ones included [8].

Apple's response, in a blog post: "Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action" [6]. The company called the step "critical" [7]. The post as quoted promises a stronger consent step, but it does not give a date or say whether apps already holding the permission will be asked again. 9to5mac's columnist would accept a one-off confirmation for those existing grants [9].

Muse's instructions describe an hourly job that compiles data on family, partners, friends, colleagues, "collaborators" and people the user "follows" [2]. Over a seven-day week, the job would run 168 times [14].

Apple has hardened a dangerous permission before. In macOS Sequoia it made users reconfirm screen recording access weekly and after every restart [10]. 9to5mac says that change was condemned as turning macOS into Microsoft Vista and as "a subscription you didn't buy and can't cancel" [11]. Side by side, Sequoia interrupted the user once a week, while Muse's instructions describe 168 runs in the same seven days [10][14].

I think Apple is right to make the grant harder. 9to5mac goes further. "Essentially, there is no wording that would be too strong," the columnist wrote [12]. The tradeoff lands on backup developers, the original audience for the permission [5]. Their customers will face the same heavier consent step as the customers of an AI agent.

For anyone deciding which Mac apps keep Full Disk Access, two questions sort the list. One is whether the task the user asked for fails without the whole disk. The other is whether the app reads the disk when the user acts or on a timer the developer set. Backup tools need the whole disk and run when the user says so or on a schedule the user chose. They keep the grant, and their users learn the new prompt. Apps that only work better with the whole disk, and read it on demand, can lose the grant at little cost. A whole-disk app on the developer's timer is the hard case, and it stays only if the developer can say what each run reads. The last quadrant is convenience access on the developer's clock. Muse's hourly instructions put it there [2], and that grant goes first.

What to watch

  • Apple publishing the actual Full Disk Access controls, including the macOS release they ship in.
  • Whether apps that already hold Full Disk Access must be re-approved once, on a schedule, or not at all.
  • Any change by Meta to the Muse instructions Karan Joshi found, or any App Store action on Muse.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories