Apple to Tighten Mac "Full Disk Access" Controls as AI Agents Raise Privacy Risks
Apple says new macOS controls will require "very explicit user action" before apps get Full Disk Access, citing growing risks from autonomous AI agents.

Apple has announced it will tighten how the "Full Disk Access" permission works on Mac, saying AI agents make the risks of that setting much greater. The company posted the update for developers on Friday, and it has drawn coverage from The Verge, Engadget and TechCrunch.
What Apple said
Full Disk Access is a macOS permission that gives an app reach across a user's entire system. Apple says it "largely sidesteps" the privacy controls users normally have, and that it exists so backup apps can work properly.
According to Apple, some developers are using it in ways that could put users at risk. That can expose files, mail, messages and even browsing history "without users' full knowledge and understanding." For communication apps, Apple added, it can also compromise the privacy of the people users are talking to.
Going forward, Apple says it will introduce additional controls so that users who "genuinely wish" to grant this "extraordinary level of access" can only do so with "very explicit user action." It also warned that as AI agents become more capable and autonomous, the risks "will grow substantially."

What we don't know
Apple has not said when the update will arrive or what exactly will change compared with today's setup. Engadget notes the company did not detail the new controls. The Verge reports Apple did not immediately respond to a request for comment.
Apple's note does not name any specific app or company.
The Muse dispute behind the timing
The announcement comes weeks after Inc. columnist Jason Aten reported that Meta's Muse AI seemed to know the contents of his messages, even though he believed he had not given it permission on his iPhone or Mac.
Meta spokesperson Andy Stone pushed back, saying access to Messages is "entirely opt-in." He said users must enable both Full Disk Access and the Messages connector for Muse to read message content. Meta also said, as Engadget reports, that if Aten's messages synced, he must have opted in.
TechCrunch adds that the decision also follows a Wired report saying a flaw in ChatGPT's Mac app could have allowed hackers to access sensitive data.
Why AI agents want this access
Desktop AI agents such as OpenClaw, Dots and Muse often encourage users to grant Full Disk Access so they can work with files, messages and other data. That lets them complete more kinds of tasks, but it also carries significant risk, Engadget notes. Some people run agents on dedicated machines instead, which Engadget says has helped fuel Mac Mini shortages this year.
Also read NASA's SpaceX Crew-13 Lifts Off From Florida for the Space Station
What it means for you
If you use an AI agent on a Mac, it's worth checking which apps currently hold Full Disk Access in your system's privacy settings, and whether each one really needs it. Apple's own description is that the permission exposes everything on the machine.
Apple's new controls should make granting that access a more deliberate step, but with no release date given, current settings remain the only safeguard for now. Watch for details from Apple on timing and how the new prompts work.
Keep it in Saved stories on this device to read later.


