Apple’s macOS has a Full Disk Access permission, designed to allow backup applications full access to, well, the disk, so they can perform their job properly. Apple posted a notice on its website that it’s going to further restrict this permission, because some applications were abusing this permission to gain access to users’ messages, emails, and so on, which it obviously isn’t intended for.
What kind of applications, you may ask?
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
↫ Announcement from Apple
This was prompted by a story a few weeks ago, where Facebook’s Muse “AI” tool was apparently reading people’s private messages and other data, and even sent messages on users’ behalf, without informing its users. It’s incredibly naive to think Facebook software in 2026 would not do creepy things, so I’m honestly not at all surprised. It makes sense in Apple’s worldview to further restrict permissions in response, but I’m sure more experienced macOS users are not going to like this.

Thom Holwerda,
It doesn’t seem clear from the evidence provided that full disk access was actually exploited, it could be a total red herring. I’d love to hear the end of this story, but currently the author isn’t certain what happened. Maybe Muse had access to notifications, but not the on disk messages. If so that’s certainly something to be aware of, but doesn’t necessarily imply permissions were ignored even if the author alleges it.
Personally I don’t have an issue with sandboxing so long as the owner genuinely controls the sandbox!! The role of the operating system is to be safe by default and empowering owners to have control over applications. IMHO many operating systems fall short when it comes to conveying what’s happening to the owner. Especially if there is no record informing owners of abuse, we’re left operating in the blind.
I don’t think “AI” is the culprit here. It’s always been unwise to grant unfettered access to applications belonging to publishers that can’t be trusted not to spy on you. It doesn’t matter that the application is AI, a game, or an application to deliver coupons…most of these don’t deserve access to your data. Assuming notifications are a vector for leaking private data, then I would think there should be a permission for that as well and it should be tightened by default.
BTW I lost my “verbose=1” comment flare? Fun while I had it 🙂