Apple to Tighten Mac Full Disk Access Rules as AI Agent Risks Grow

Apple plans tighter Full Disk Access controls on macOS as AI agent risks grow.
Apple plans to tighten Full Disk Access controls on macOS as increasingly capable AI agents raise new privacy and security concerns.
The company said it will introduce additional safeguards that require users to take more explicit action before giving an application broad access to data stored on a Mac.
Apple announced the changes on October 2 in a developer update. It warned that some applications are using Full Disk Access in ways that could expose files, email, messages and browsing history without users fully understanding the consequences.
The company did not name a specific application or developer. However, the announcement comes amid growing scrutiny of AI agents that can access and act on information stored on users’ computers.
AI Agents Raise New Privacy Concerns
Apple said the risks associated with broad system access are becoming more significant as AI agents become more capable and autonomous.
Unlike conventional applications, AI agents can perform multiple tasks with limited user intervention. They can also interact with files, communications and other connected services.
Apple said users need to understand the implications before granting an application system-level access.
Shubman Gill Calls for India to Fix Death Bowling and Fielding Before World Cup
The company also highlighted risks involving communication applications. Access to messages can expose not only a user’s information but also private information belonging to people who communicate with them.
Full Disk Access Gives Apps Broad Permissions
Full Disk Access largely bypasses macOS privacy protections. Apple originally designed the permission to support applications such as backup tools that need access to large portions of a Mac’s storage.
The permission can allow applications to access files, mail, messages and browsing history.
Apple said some developers are using the permission in ways that could put users at risk. The company now plans to make the approval process more deliberate.
The company has not announced exactly how the new controls will work or when they will arrive.
Meta’s Muse Adds to AI Privacy Debate
Apple’s announcement follows scrutiny of Meta’s Muse, an AI agent for Mac computers.
A technology journalist recently alleged that Muse accessed private Apple Messages content. Meta disputed the suggestion that the application could access Messages without the required permissions.
Meta executive David Singleton said the Messages integration is opt-in. He said users must grant Full Disk Access and enable the Messages connector before Muse can read Messages content.
Apple did not identify Muse in its announcement. Therefore, the company has not said that the Meta application directly prompted the new controls.
However, the timing has intensified discussion about whether existing macOS permissions provide enough protection as AI agents gain broader capabilities.
Reuters reported that Apple plans to make it more obvious when AI agents request access to data across a Mac.
Apple Expands Controls for Agentic AI
The move also reflects Apple’s broader effort to establish stronger safeguards around AI agents.
As these systems become capable of completing multi-step tasks, their usefulness increasingly depends on access to files, applications and other digital resources.
That creates a new challenge for operating systems. Users may want AI agents to perform tasks automatically, but those capabilities can require permissions that expose sensitive information.
Apple’s latest announcement suggests it is focusing not only on individual AI applications but also on the operating-system permissions that allow them to access a user’s wider digital environment.
For Mac users, the forthcoming changes could make granting Full Disk Access a more visible and deliberate decision. For developers, they may also create additional requirements for applications that rely on broad system permissions.
