Apple is tightening one of the most powerful permissions on the Mac. In a developer blog post, the company said it is introducing new controls around macOS's Full Disk Access setting, warning that some developers are using the entitlement in ways that could expose a user's entire system — and that AI agents are making that level of access far more dangerous.

The move, reported by TechCrunch, arrives at a moment when desktop AI assistants are multiplying and increasingly acting on users' behalf. Full Disk Access was originally designed so that apps like backup software could function properly, but it grants extraordinary reach: permission to read a user's files, mail, messages, and even browsing history. For more context on this story, see our ongoing breaking AI news.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users' full knowledge and understanding," Apple said in the blog post aimed at developers.

Why Apple Is Acting Now

The announcement came days after Inc. columnist Jason Aten reported that Muse, an AI-powered app on the Mac, appeared to know the content of his private messages — even though he said he had not given the agent permission to read them. Meta, which owns Muse, disputed the claim, but the report put a spotlight on how much trust users are asked to place in desktop AI software that can read their files and control their systems.

Apple's decision also follows a Wired report describing a flaw in ChatGPT's Mac application that could have allowed hackers to access sensitive data from users' computers. Neither incident involved a confirmed breach of Apple's own platform security, but together they illustrate the new risk surface that AI agents create: software that is granted sweeping access, runs continuously, and acts with increasing autonomy is a far more valuable target — and a far bigger liability — than a traditional app.

In Muse's case, the AI app optionally allows users to enable Full Disk Access, which hands it the keys to files, mail, messages, and browsing history in one switch. That pattern — an AI assistant asking for the broadest possible permission so it can be maximally helpful — is exactly what Apple now wants to interrupt.

What Changes on the Mac

Going forward, Apple says it will introduce new controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can do so only with very explicit user action. In practice, that means fewer one-click consent dialogs buried in setup flows and a more deliberate, informed process before an app can see everything on a Mac.

"Addressing this is critical," Apple wrote. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

Apple did not respond to TechCrunch's inquiry about the feature change, and the company has not specified exactly when the new controls will ship or how they will appear in macOS. Developers that rely on Full Disk Access for legitimate purposes — backup tools, security software, and automation utilities — will be watching closely to see whether the tighter consent flow adds friction for their users.

A Signal for the Desktop AI Era

The policy shift reflects a broader reckoning in the AI industry about agent permissions. AI agents that operate on a user's desktop can draft documents, move files, send messages, and browse the web — capabilities that are only useful if the software can see and touch a great deal of personal data. That utility is inseparable from the risk.

The Permission Problem Agents Create

The tension Apple is trying to manage is structural. An AI agent's usefulness on a desktop is a direct function of what it can see: summarize your email, sort your downloads, schedule across your calendar, and draft replies, and it must read them all. Developers therefore have a commercial incentive to request the broadest entitlement available rather than assemble narrow, task-specific permissions — and Full Disk Access is the broadest there is.

Apple's framing is notable for how directly it names AI agents as the reason the calculus has changed. A backup utility with Full Disk Access has always been a concern; an autonomous agent with the same access can decide, on its own, what to do with everything it can read. By requiring very explicit user action before such access is granted, Apple is effectively building a consent architecture for the agent era — and putting pressure on AI developers to design products that need less access in the first place.

For users, the advice in the meantime is unchanged: audit which apps currently hold Full Disk Access in System Settings, revoke anything that cannot justify the permission, and be skeptical of any AI assistant that asks for the keys to the whole system to deliver a modest feature.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →