Apple Tightens macOS Full Disk Access Over AI Agent Risks

A single toggle buried in macOS System Settings has quietly become one of the most powerful switches on your Mac. Apple now says it is going to make that switch much harder to flip.

In a post on its developer site on October 2, the company announced it will add “additional controls” around Full Disk Access, the macOS permission that lets an app read essentially everything stored on your machine. The reason, in Apple’s own words, is the arrival of AI agents that are “increasingly capable and autonomous.”

Apple did not say when the change ships, what it will look like, or which macOS version will carry it. For now, this is a statement of intent aimed squarely at developers.

What Full Disk Access actually does

Most macOS permissions are narrow by design. An app asks for the camera, the microphone, your Contacts, or one specific folder, and you approve each request separately. That system (Apple calls it a set of controls built to protect private data) is why a photo editor cannot quietly read your email.

Full Disk Access is the exception. Apple describes it as a permission that “largely sidesteps” those protections. It exists because backup software genuinely needs to copy everything, including the parts of your drive that normal apps can never touch.

Grant it, and an app can reach your files, your Mail database, your Messages history, and your browsing history. Apple also points out a consequence many users miss: for communication apps, handing over this access exposes the privacy of the people you have been talking to, not just your own.

Why AI agents changed the calculation

Full Disk Access has been in macOS for years without this kind of warning. What changed is who is asking for it.

Desktop AI agents want broad access by design. Their value proposition is reading your stuff and acting on it. Apple’s announcement follows the rise of always-on assistants including Meta’s Muse and OpenAI’s Dots, both of which request substantial access to personal data.

The immediate trigger appears to be a specific incident. According to TechCrunch and The Verge, Inc. columnist Jason Aten reported that Meta’s Muse app knew the contents of his private messages even though he said he had not granted that permission.

Meta disputes the account. Spokesperson Andy Stone told The Verge that access to Messages is “entirely opt-in,” and that a user has to enable both Full Disk Access and the Messages connector before Muse can read message content. So the facts of that single case remain contested, but the structural point stands either way. Two toggles, one of which sounds like a technical housekeeping setting, is a thin barrier for that much data.

TechCrunch also notes a separate Wired report describing a flaw in ChatGPT’s Mac app that could have exposed sensitive data. Digital Trends adds that users have reported agents deleting work, files, and personal photos and videos. Those reports are user accounts rather than confirmed vendor disclosures, and none of the sources quantify how widespread the problem is.

What the sources confirm, and what they don’t

ItemStatus
Apple will add “additional controls” to Full Disk AccessConfirmed by Apple’s developer post
Reason given: risk from autonomous AI agentsConfirmed by Apple
Release date or macOS versionNot announced
Specific design of the new controlsNot announced
Muse read messages without permissionReported by Inc., disputed by Meta
Apple comment to press beyond the blog postThe Verge and TechCrunch say Apple did not respond

What this changes for developers

Read Apple’s language carefully and the direction is clear. Access will require “very explicit user action,” which strongly suggests more friction: extra confirmation steps, clearer warnings about what is being exposed, or both.

If you ship a Mac app that asks for Full Disk Access as a convenience, expect fewer users to complete the flow. Teams building agents and automation tools should start planning narrower paths now: scoped folder permissions, user-initiated file pickers, and per-service connectors instead of one blanket grant. Apple’s post frames Full Disk Access as something intended for backup tools, and that framing is a hint about which apps will keep an easy approval path.

This mirrors a pattern we have seen before on mobile, where platform owners revisited permissions that developers had stretched well past their original purpose, much like when Google began reviewing Android apps that track location in the background.

How to audit Full Disk Access on your Mac today

You do not need to wait for Apple’s update. The permission list is already visible.

  1. Open System Settings.
  2. Go to Privacy & Security.
  3. Select Full Disk Access.
  4. Review every entry in the list.

Work through it with three questions. Does this app need to read my entire drive to do its job? Did I knowingly turn this on? Do I still use it?

Backup utilities, disk cleaners, and some security tools have a legitimate claim. A chat app, a note-taker, or an AI assistant you installed once and forgot usually does not. Toggle off anything you cannot justify. You can always re-enable it if something breaks.

Then check the adjacent categories in the same Privacy & Security panel: Files and Folders, Accessibility, and Screen Recording. Accessibility permissions in particular let an app control your Mac, which matters just as much for agents as reading files does.

What this means for you

  • Nothing has changed on your Mac yet. Apple announced intent, not a shipping feature. No date, no version number.
  • Audit now anyway. The riskiest grants are the ones you forgot about. Five minutes in Privacy & Security is the highest-value security action available to most Mac users this week.
  • Treat AI agents as a distinct category. An agent with Full Disk Access can read your drive and take actions on it. The reported data-loss incidents came from agents acting, not just reading.
  • Granting access affects other people. Your Messages and Mail contain other people’s words. They did not consent to your permission decision.
  • Expect more friction, and accept it. When the change lands, approving Full Disk Access will likely take extra steps. That is the point.
  • Watch for vendor pushback. Apple’s definition of acceptable use will be contested by companies whose products depend on broad access. Meta has already disputed the reporting that preceded this announcement.

The open question is how far Apple goes. Extra warning dialogs are one outcome. A formal entitlement that restricts Full Disk Access to approved categories of app would be far more disruptive, and Apple’s post stops well short of promising it.

Written by

Haseeb Ahmed

Comments