Apple Locks Down Mac Full Disk Access Over AI Agent Risks
3 min readApple is tightening one of the most powerful permissions on the Mac. On October 2 the company said it will add new controls around macOS Full Disk Access, warning that AI agents running on the desktop have raised the risks attached to that level of access. The change arrives days after a journalist reported that Meta’s Muse agent read his private messages.
What Full Disk Access Does
Full Disk Access is a macOS setting that lets an application read nearly everything on the computer: files, mail, messages and even browsing history. Apple designed it so backup tools could do their job. Most users granted it a handful of times and forgot about it.
That assumption breaks down with desktop AI agents. These apps ask for broad access so they can act on a user’s behalf, which means a single permission toggle can hand an autonomous system the full contents of a machine.
What Apple Announced
In a post aimed at developers, Apple said some developers are using Full Disk Access in ways that could put users at risk by exposing everything on their systems without full knowledge and understanding. Going forward, users who want to grant an app this level of access will be able to do so only through what Apple called very explicit user action.
The company framed the move as urgent. As agents become more capable and autonomous, Apple wrote, the risks associated with this access will grow substantially, and it wants users to clearly understand those risks before saying yes. Apple did not answer TechCrunch‘s questions about how the new controls will work or when they ship.
The timing is not accidental. Inc. columnist Jason Aten reported that Muse knew the content of his private messages despite him never granting it permission, a claim Meta disputes. Muse offers Full Disk Access as an optional setting. Separately, Wired reported a flaw in ChatGPT’s Mac app that could have let attackers grab sensitive data.
Why It Matters
Apple is the first platform owner to change an operating system permission specifically because of AI agents. That sets a precedent. Microsoft, Google and Linux desktop maintainers now face the same question: should a permission built for backup software be available to an autonomous agent at all?
For agent developers, the message is that frictionless onboarding is over on the Mac. Expect more granular prompts, more scoped access and more pressure to explain exactly what an agent reads. For users, the practical step is simple: open System Settings and review which apps already hold Full Disk Access today.
Watch for the details in an upcoming macOS release, and for whether Meta and OpenAI adjust how their Mac apps request access in response.
