Apple tightens macOS Full Disk Access over AI agent risks
Apple is making it harder to grant apps access to the whole disk on macOS, saying always-on AI agents have made that permission far riskier.
What happened
On October 2 Apple said it will add controls to macOS Full Disk Access, the setting that lets an app read nearly all files, mail, messages and other apps' data. Apple said the setting was designed for backups, but AI agents have increased the risks of that level of access, so it will only be grantable through very explicit user action.
Why now
The move came days after a journalist claimed Meta's Muse app for Mac read their private messages, which Meta disputed, and amid the spread of always-on agents such as Muse and OpenAI's Dots. Apple said the risks of such access will grow substantially as agents become more capable and autonomous.
What the permission is
macOS normally gates access per folder and data type. Full Disk Access bypasses all of it, including Mail, Messages and Safari data. A compromised or misdirected agent holding it puts all of that at risk.
Why agents want it
An agent is only as useful as the data it can read, so developers reach for one broad permission. That also exposes unrelated data, and an agent steered by hidden instructions in a web page or email (prompt injection) would hand that access to an attacker.
A first at OS level
This is one of the first operating-system changes aimed squarely at AI agent risk, and similar steps on Windows and Android are expected. Agent makers will have to design for narrower permissions.
Who it affects
Backup, security and system tools genuinely need broad access and will see an extra step. Agent makers will have to justify why they ask for so much, and users will need to treat permission prompts as real decisions.
What it means for your business
Audit which apps hold Full Disk Access on company Macs, set a written policy for AI agent access, keep sensitive data out of general folders, and brief staff on why permission prompts now matter.
