Apple announced on October 2 that it will implement stricter controls on macOS for applications requesting extensive access to user data. The decision follows complaints regarding Meta’s Muse and highlights broader concerns about how AI agents access, communicate, and regulate user data.
Changes to Full Disk Access
In a developer update, Apple noted that Full Disk Access can allow apps to bypass safeguards protecting app data, granting entry to files, emails, messages, and browsing history. Apple stated it will introduce additional controls requiring explicit user action to grant this level of access, emphasizing that risks will grow substantially as AI agents become more capable and autonomous.
Unlike iPhones and iPads, which default to separating applications, macOS allows an application with Full Disk Access to view broad segments of user data. The policy adjustment follows criticism from Inc columnist Jason Aten, who stated that Muse read private messages without explicit Full Disk Access enabled. Meta disputed the claim, stating that access to Apple Messages is opt-in, requiring users to enable both Full Disk Access and the Messages connector. Muse previously faced scrutiny when a researcher discovered a flaw, classified as SEV-2, that could have potentially allowed an attacker access to virtual machines, emails, and files.
AI Agent Governance and Industry Trust
As autonomous AI capabilities expand, organizations are exploring frameworks to manage agentic AI safely:
- World Economic Forum (WEF): Recommends an Agent Capability and Authorization Profile to define and track agent limits and permissions.
- PwC: Suggests companies manage AI agents like a digital workforce with task-based access and strict limits.
- OECD: Maintains a cautious stance, stating that agentic AI is still evolving and requires further work to achieve trustworthiness.
Trust concerns are directly impacting business deployments. Research by FTI Consulting indicates that 60% of large enterprises have slowed, stopped, or postponed AI deployment due to trust, regulation, and reputation concerns. Furthermore, a SAS report found that 76% of participants trust generative AI, while only 66% trust agentic AI.
Market Projections and Spending
Financial forecasts highlight substantial investments despite ongoing adoption friction. Gartner projects investments in AI models and platforms will increase from $39.3 billion in 2025 to $64.3 billion in 2026. Capgemini estimates that AI agents could generate up to $450 billion in value by 2028, even though only 2% of companies have fully implemented AI systems.
While Apple’s tighter controls introduce initial friction, clear and revocable permissions may increase user confidence, making permission design an essential part of product development for autonomous systems.


