What Full Disk Access exposes
A Muse user, Inc. columnist Jason Aten, reported that the AI agent knew the contents of his private messages, though he said he had not allowed it to read them. Meta disputed Aten’s claim.
Separately, Wired reported a vulnerability in the ChatGPT app for Mac that could have let hackers access confidential data. These reports put attention on a permission that users may enable themselves to give desktop agents broader access.
Apple says Full Disk Access can expose files, email, messages and browser history. The company said some apps obtain system-wide access without users fully understanding what they are agreeing to.
A higher bar for permission
Apple says it will add safeguards so an app can receive this breadth of access only after a “very explicit action” by the user. The company wants people to understand the risks and make an informed choice about their data and privacy.
The timing matters: Apple says those risks will grow as AI agents become more capable and autonomous. But its developer blog does not explain what the new confirmation will look like, and Apple did not tell TechCrunch how the feature will change.
I think the unresolved issue is whether a stronger prompt can make a broad permission understandable at the moment it is requested. A deliberate click is not the same as informed consent if users cannot tell what an agent will read or do with access. Apple is raising the bar for granting the permission; the announcement leaves open how much users will be able to see before they cross it.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X