Apple2 mins read

Apple Tightens macOS Full Disk Access Controls as AI Agent Risks Grow

Apple says it will add new controls around macOS Full Disk Access, warning that AI agents make broad access to files, messages, mail, and browsing history riskier.

M2 Apple Macbook Air, open on desk
Image credits:Brian Heater

Apple Is Reworking a Powerful macOS Permission

Apple says it will introduce additional controls around macOS “Full Disk Access,” a setting originally designed to let tools like backup apps function properly. The company says increasingly capable AI agents raise the risks tied to granting apps this level of access. The change is focused on making sure users understand when an app can reach sensitive data across their Mac.

Why Full Disk Access Matters More With AI Agents

Full Disk Access can give an app permission to access files, mail, messages, and browsing history. Desktop-based AI agents may need broader system access to act on a user’s behalf, but that same access can expose personal content if users do not fully understand what they are approving. Apple said some developers are using Full Disk Access in ways that could put users at risk by exposing everything on their systems without full user knowledge and understanding.

Recent Reports Put Desktop AI Trust Under Scrutiny

The move follows a report from Inc. columnist Jason Aten claiming Meta’s Muse app on Mac knew the content of his private messages, a claim Meta disputed. TechCrunch also cited a Wired report saying a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. Together, the reports underscore why permissions that once seemed routine for utility software are being reevaluated in the AI agent era.

What Users and Developers Should Watch Next

Apple says future access to this “extraordinary level” of permission should require “very explicit user action.” For users, the practical takeaway is to treat Full Disk Access as a high-risk permission and review which apps have it enabled. For developers, Apple’s message is clear: broad access needs stronger justification, clearer consent, and better user understanding.

Discover More

    A digitally generated image showing several AI chatbot assistants standing on a segmented or sliced floor surface, symbolizing the distributed and modular nature of artificial intelligence systems.
    Instinct adds AI group chats

    Instinct’s AI agent can now join group chats for shared planning and coordination, with permission controls around personal data.

    AI AgentsInstinct
    AI agents, AI swarm, agent hackers
    Armadin Raises $255.5M

    Kevin Mandia’s new agent swarm security startup is now valued at more than $2.5 billion.

    CybersecurityStartups