Apple Tightens macOS Full Disk Access Over AI Agent Risks

Apple Tightens macOS Full Disk Access Over AI Agent Risks

Apple is adding new restrictions to "Full Disk Access," one of the most powerful permissions an app can hold on macOS. The company says desktop AI agents have changed the risk picture. A setting that was once mostly about backups now opens a much bigger door.

The announcement came in a blog post aimed at developers. It follows a week of uncomfortable reporting about what AI apps on the Mac can see.

What Full Disk Access actually unlocks

Full Disk Access was built for a practical reason: backup software needs to reach everything on a machine to do its job. According to Apple, an app with this permission can read files, mail, messages and even browsing history.

That reach made sense for backup tools. It looks different when the app is an AI agent that can also act on what it reads. Desktop agents let users widen an app's access to files, messages and other personal content by changing macOS settings. Full Disk Access is the broadest version of that.

Apple's view is that some developers are already stretching it too far. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems...without users' full knowledge and understanding," the company wrote.

The Muse report that preceded it

The timing is hard to ignore. A few days before Apple's post, Inc. columnist Jason Aten reported that Muse, Meta's AI app for Mac, knew the content of his private messages. He said he had not given the agent permission to read them. Meta disputed the claim.

Muse lets users switch on Full Disk Access as an option. Whatever happened in Aten's case, the episode raised a broader question about how much users can trust desktop AI that controls parts of their system and reads their files and messages.

It was not the only warning sign. Wired separately reported a flaw in ChatGPT's Mac app that could have allowed hackers to reach sensitive data.

What Apple plans to change

Apple has not published technical details in the material available so far. It has described the goal, though. Users who "genuinely wish to grant an app this extraordinary level of access" will only be able to do so through "very explicit user action."

In other words, turning on Full Disk Access should become a deliberate step. It should not be something a user clicks through during setup without much thought.

Apple framed the change as forward-looking. "Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," the company wrote. It added that it wants users to understand those risks "before granting such access, so they can make informed decisions about their own data and privacy."

Apple did not respond to TechCrunch's request for comment on the change.

Why agents change the math

The core issue is simple. A backup tool reads data and copies it somewhere. An AI agent reads data, interprets it, and may take action based on it. That could mean sending a message, opening a file, or passing content to a remote model.

So the same permission carries more weight. A file the agent can read becomes context it can use, and possibly content it can leak. Apple's statement names this shift directly: as agents get more autonomous, broad access becomes riskier, not just more convenient.

The Bigger Picture

This move suggests the platform owners are starting to treat AI agents as a separate class of software, with their own risks, rather than just another app. That matters for anyone building or running desktop agents. The easy path of asking for everything up front is likely to get harder on the Mac.

It also fits a pattern we have tracked for weeks. Agent security problems keep showing up through ordinary channels, from screenshots leaking onto GitHub to disputes over what an agent did or did not read. Meanwhile, products like OpenAI's always-on Dots agents push toward more autonomy, not less. Apple's response is a permission-layer fix, and it works outside the model itself. That approach makes sense. A control the operating system enforces does not depend on the agent behaving well.

There is a known trade-off, though. More prompts and more friction can protect users, but they can also train people to approve requests without reading them. Whether Apple's "very explicit user action" avoids that trap will depend on the design.

Several things are worth watching. First, the exact form of the new controls and when they ship. Second, how Meta, OpenAI and other agent makers adjust their Mac apps. Third, whether other platforms adopt similar limits on broad system access for AI tools.