Apple Tightens Mac Full Disk Access for AI Agents
Apple tightens Mac Full Disk Access for AI agents after warning that the permission can expose files, email, messages and browsing history. The company says future macOS controls will make users take a more explicit action before granting that reach.
Apple announced the plan on October 2 as complaints surrounding Meta's Muse renewed scrutiny of broad agent permissions. The change centers on three points:
- Full Disk Access bypasses narrower privacy controls.
- AI agents can act across more sensitive data.
- Apple has not disclosed a release timeline.
Apple Tightens Mac Full Disk Access for AI Agents
In its developer notice, Apple said Full Disk Access largely sidesteps the privacy controls that normally limit what an app can see. The capability exists so software such as backup tools can work across a Mac, but Apple now says some developers are using it in ways that could put users at risk.
Apple did not describe the additional controls in technical detail. Its clearest commitment is that a person who genuinely wants to grant the permission will have to complete a highly explicit action, with enough information to understand the consequences before proceeding.
The distinction matters because a stronger prompt is not the same as a narrower permission. Apple has not said whether macOS will divide Full Disk Access into smaller categories, require renewed consent, display agent-specific warnings or add controls for individual tasks.
Until Apple publishes those mechanics, developers cannot assume that existing workflows will continue unchanged. Backup utilities, security products and automation software all use broad access for legitimate reasons, so Apple must raise the consent barrier without breaking tools whose core function depends on system-wide visibility.
Why Full Disk Access Creates a Wider Mac Risk
Apple's support documentation says Full Disk Access can reach all files on a computer, including data from Mail, Messages, Safari and Home. It also covers Time Machine backups and certain administrative settings for every user on the Mac.
That is much broader than the permissions people routinely approve for contacts, calendars, photos or a single folder. On iPhone and iPad, sandboxing separates one app's data from another by default. Macs remain more flexible because desktop software often needs to work across files and applications.
An autonomous agent changes the risk calculation. Conventional software usually performs a defined set of functions, while an agent may interpret a goal, inspect several data sources and take a chain of actions. A single broad permission can therefore support tasks that were not obvious when the user first approved access.
Communication data creates an additional privacy problem. Apple noted that access to messages can affect people who never installed the agent or consented to its use. Their words may still enter an agent's working context because they communicated with the Mac owner.
The design challenge is not limited to disclosure language. Effective controls must help users understand which data an agent needs, why it needs that data and whether access continues after a task ends. Clear revocation and audit trails would also help people verify what remains connected.
Meta Disputes the Muse Permission Complaint
Apple's announcement followed a complaint from Inc. technology columnist Jason Aten, who said Muse referred to private Messages content on his Mac even though he had not enabled Full Disk Access. Reuters reported the allegation and Meta's denial; the account has not been independently resolved.
Meta spokesperson Andy Stone said Muse cannot read Messages unless the user enables both Full Disk Access and the Messages connector. He described the connection as opt-in and said it can be revoked at any time.
That dispute should not be treated as proof that Muse bypassed macOS security. It does show why permission boundaries need to be understandable after setup, not only during installation. When an agent surfaces sensitive information, users need a reliable way to determine which authorization supplied it.
Muse is designed to act across connected services and continue tasks inside a cloud-hosted environment. That persistent model can be useful for travel, shopping and subscription management, but it also makes data provenance and consent records central to trust.
Apple Has Not Set a Release Timeline
Apple said it will introduce the additional controls in the future, without naming a macOS version, beta build or deployment date. The company also declined to add details beyond its public developer post, according to Reuters.
The next useful evidence will be the design of the consent flow and the scope of the underlying permission. A warning that precisely identifies files, services and duration would give users more information than a generic confirmation, while per-task access could reduce the consequences of a mistaken approval.
Developers will also need migration guidance. If Apple changes the conditions for Full Disk Access, apps may require new explanations, setup paths or fallback behavior. Enterprise administrators will want to know whether managed permissions and existing security policies remain valid.
For now, Apple's announcement establishes a direction rather than a finished security model. The company accepts that a desktop permission built for trusted utilities carries greater stakes when software can plan and act autonomously. The quality of the fix will depend on whether explicit consent becomes specific, reviewable and easy to reverse.