2026-10-03 11:25 UTC
DANGMUAAI & Developer Tools, Decoded
BackIndustry

Apple Tightens macOS Full Disk Access Over AI Agent Risk

Apple will add new controls to macOS Full Disk Access, warning that increasingly autonomous AI agents make system-wide file access far riskier.

DangMua EditorialOct 03, 20263 min read
Apple Tightens macOS Full Disk Access Over AI Agent Risk

Apple will add new controls to macOS Full Disk Access, saying increasingly autonomous AI agents make the permission riskier for users' files and messages.

The company disclosed the change in a post aimed at developers, days after a journalist said Meta's Muse app on Mac knew the contents of his private messages — a claim Meta disputed.

What Apple said

Apple's statement is unusually direct about the cause. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users' full knowledge and understanding," the company wrote.

On the agent angle, Apple said: "Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

Going forward, Apple says it will introduce controls ensuring that users who "genuinely wish to grant an app this extraordinary level of access" can do so only with "very explicit user action."

The reports behind the change

Inc. columnist Jason Aten reported that Meta's Muse AI knew the content of his private messages despite his not having granted the chatbot explicit permission on his iPhone or Mac. Meta spokesperson Andy Stone pushed back, saying access to Messages is "entirely opt-in" and that a user must "enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content."

TechCrunch also notes the timing follows a Wired report that a flaw in ChatGPT's Mac app could have allowed hackers to access sensitive data. Both items point the same way: desktop AI apps are asking for system-wide reach, and users are approving it without a clear mental model of what they granted.

What the permission actually grants

Full Disk Access gives an app access to files, mail, messages and browsing history — in The Verge's description, a user's entire system. Apple says the permission "largely sidesteps" the privacy controls offered to users, and existed to let backup apps function properly on Mac.

That origin is the whole problem. A permission scoped for nightly backups is now the same switch an agent flips to read a project folder, and macOS does not distinguish between the two intents.

If you ship a Mac app

Analysis, not Apple guidance: if your app requests Full Disk Access today, assume the grant flow gets harder and plan a narrower path now. Scoped folder access and user-initiated file pickers survive a tightening; a blanket prompt during onboarding probably does not. Agent products that treat Full Disk Access as a launch requirement are the most exposed, because the fallback has to be designed, not toggled.

Still unknown

Apple has not said when the update ships, and has not said whether apps holding the permission today will keep it or be reset. Apple did not respond to inquiries from TechCrunch and did not immediately respond to The Verge. Until a release lands, the only concrete action is on the user side: audit the Full Disk Access list and remove anything that is not a backup tool.

More from DangMua