
www.Pixel.la Free Stock Photos / Wikimedia Commons · CC0 1.0
Apple Is Tightening macOS’s Most Powerful Permission, and AI Agents Are the Reason
Apple says Full Disk Access has become too easy to grant now that autonomous AI agents want it. New controls are coming; Apple has not set a date.
What Apple announced
On Friday, October 2, Apple published a short note on its developer news site announcing "additional controls" for Full Disk Access on the Mac. The wording was blunt for a company that usually announces restrictions as improvements. Apple said some developers are using the permission "in ways that could put users at risk," exposing files, mail, messages and even browsing history "without users' full knowledge and understanding."
The note also named the trend behind the change. "As AI agents become increasingly capable and autonomous," Apple wrote, "the risks associated with this level of access will grow substantially." Going forward, Apple said, a user who really wants to hand an app this "extraordinary level of access" will be able to do so only through "very explicit user action." Apple did not say what that action will be, which macOS release will carry it, or when it will arrive.
What Full Disk Access actually is
macOS already walls off sensitive data. Apps need the user's consent before reading protected locations such as Mail, Messages and Safari data, and later versions added prompts for folders like Desktop, Documents and Downloads. Each prompt covers one category, which keeps an app's reach narrow.
Full Disk Access is the exception that skips those categories. Apple's own note describes it as a setting that "largely sidesteps" the privacy controls so that backup apps can copy everything on a drive. One toggle in System Settings, under Privacy & Security, replaces dozens of separate decisions. Backup utilities, disk-cleaning tools and disk-usage mappers have legitimate reasons to want it: a program that must read the whole disk cannot work with a partial view.
The same property makes it attractive to anything else that wants to see everything. Apple's note points out a side effect that is easy to miss: for communication apps, broad access "can also compromise the privacy of the people users are communicating with," because a conversation lives in both participants' data.
Why AI agents change the arithmetic
A traditional app that holds Full Disk Access does what its code does. An agent is different: it decides at run time which files to open in order to finish a task. That makes the permission harder to reason about, because the user is approving a capability, not a function.
Meta's Muse offers a recent example. The company released a Mac version on September 17 as an agent that works with files, notes, calendars and mail, and that keeps running in the background after its window is closed. Meta described Full Disk Access as optional and said sensitive actions such as deleting files or sending messages require approval. A few days later, tech writer Jason Aten reported in Inc. that Muse had pushed a notification drawing on a private conversation, even though he remembered declining access to his messages. By his account, the app had synced his local Messages database, and it described its own behavior inaccurately when he asked. 9to5Mac, relaying the report, noted that Meta attributed some of the privacy issues users described to a bug. MacRumors, covering Apple's announcement, placed it against the rise of always-on agents such as Meta's Muse and OpenAI's Dots.
What Apple has not said
The announcement leaves several practical questions open. "Very explicit user action" could mean a password or biometric prompt, a more elaborate confirmation, or a permission that expires. Apple did not choose among them. Nor did it say whether the new rules will apply to apps already holding the permission, or only to new grants. Backup and cleanup tools, which are the legitimate users Apple names, will want to know whether their workflow gets longer.
Another question is Apple's own position. Siri AI is built into macOS and is the company's own agent. 9to5Mac's Ben Lovejoy has written that he trusts the safeguards Apple has put around it. Whether the new controls treat first-party and third-party agents identically is not stated, and developers of rival agents will likely ask.
What to check on your Mac now
Nothing needs to wait for a software update. Open System Settings, choose Privacy & Security, and open Full Disk Access. The list shows every app that currently holds the permission. Remove anything you do not recognise or no longer use; the toggle can be switched back on later if an app needs it.
For agents specifically, the more cautious route is to grant narrower permissions instead of Full Disk Access, such as access to a single folder, and to read each approval prompt rather than clicking through. Aten's experiment ran on a test machine rather than his main Mac, a precaution that costs little. Anyone who does grant broad access to an agent should treat what it reports about its own behavior as something to verify, not as proof.
Why it matters beyond one setting
Apple has spent a decade turning macOS permissions from a one-time agreement into a series of narrow, revocable grants. Full Disk Access was the deliberate hole in that wall, justified by backup software. The announcement is Apple saying that the hole was sized for a different era. If the new controls are well designed, the cost to ordinary users will be a more deliberate prompt; if they are clumsy, they could slow legitimate tools too. Apple has set no timetable, so for now the safeguard is the list in System Settings.