Apple Is Tightening Full Disk Access on macOS, and AI Agents Are the Reason

Apple says Full Disk Access was built for backup apps and AI agents have made it riskier. Here's what changed, what hasn't, and what to check on your Mac.

Pradeep Kumar
•
4 min read
Apple Is Tightening Full Disk Access on macOS, and AI Agents Are the Reason

Apple is going to make it harder to give an app Full Disk Access on the Mac. The reason is simple: AI agents have made that level of access riskier to hand out.

The announcement is short. Apple gave no dates and no details on how the new controls will work. Even so, it says a lot about where desktop AI is heading.

What Full Disk Access does

Full Disk Access is a switch in System Settings, under Privacy & Security. Turn it on for an app, and that app can reach data macOS normally protects. That includes files, mail, messages and browsing history.

Apple says the permission largely sidesteps the privacy controls that apps usually have to respect. It exists so backup apps can do their job, since a backup tool has to copy everything.

That design made sense for backups. It makes less sense for software that can read, decide and act on its own.

What Apple said

Apple posted the note on its developer news page on October 2. The main points:

  • Some developers use Full Disk Access in ways that put users at risk. It can expose everything on a system without the user fully understanding that.

  • For communication apps, the exposure reaches past the user. It can also compromise the privacy of the people they talk to.

  • Apple will add controls so that anyone who really wants to grant this access can only do it through "very explicit user action."

  • As AI agents become more capable and autonomous, Apple expects the risks of this access to grow a great deal.

Apple's note doesn't name any app or company.

What set it off

The timing lines up with two recent stories, and TechCrunch tied Apple's move to both.

The first is about Muse, Meta's AI agent, which has a Mac app. Inc. columnist Jason Aten reported that Muse knew the content of his private messages, even though he says he never gave it permission. He said Full Disk Access was off at the time. When he asked Muse how it knew, it told him it was syncing his device notifications.

Meta disputes this. Meta VP of Communications Andy Stone said the Messages integration is opt-in and needs both Full Disk Access and a Messages connector.

Meta Superintelligence Labs executive David Singleton added that the setup takes three separate permission steps. He said macOS protections can't be bypassed even if the app had a bug, and that Muse's own explanation of what happened was wrong.

Reports so far don't show the disagreement being settled.

The second story is a Wired report on a flaw in ChatGPT's Mac app that could have let hackers reach sensitive data.

Both stories point at the same worry: desktop AI apps sit close to a lot of personal data. Apple hasn't said either one caused its decision.

Why agents change the picture

A backup app copies files and does little else. An agent reads, decides and acts. It can open a file, summarize it, send a message or run a command.

Add broad access and the risk grows. An agent can also be steered by what it reads. Hidden instructions in a document or web page can push it to do things the user never asked for. Security researchers call this prompt injection.

There's a simpler issue too. macOS grants this permission per app, not per task. Once it's on, the app can reach everything the permission covers, whether or not the current job needs it.

And agents often run inside other apps. An agent launched from Terminal inherits whatever permissions Terminal has.

What Apple hasn't said

Apple hasn't said what the new controls look like, which version of macOS will get them, or when. TechCrunch reports that Apple didn't respond to its questions about the change.

A few things are worth watching once details appear:

  • Whether apps that already have Full Disk Access keep it

  • Whether backup tools get a separate path from AI apps

  • How much friction the new approval step adds

These are open questions, not reported plans.

What you can do now

You don't need to wait for Apple.

  1. Open System Settings, then Privacy & Security, then Full Disk Access.

  2. Switch off anything you don't recognize or no longer use.

  3. For AI apps, grant specific folders instead. You'll find those options under Files & Folders in the same section.

  4. Check Terminal and code editors too. An agent running inside them inherits their access.

  5. Keep macOS and your apps up to date.

The takeaway

Full Disk Access was built with backup apps in mind. Apple now says AI agents have changed the risk.

The details are still to come, but the direction is clear. Handing an app everything on your Mac should take a deliberate choice.

Sources

Comments (0)

Join the discussion by logging into your account.

No comments yet. Be the first to comment!

Pradeep Kumar

Passionate developer sharing knowledge about modern web technologies and best practices.

Subscribe to Pradeep Kumar's Newsletter

Direct email dispatches when new stories are published. Zero algorithms.