Agents AI

AgentsNews

Apple Will Tighten macOS Full Disk Access, Citing Risks From AI Agents

Apple says it will add controls so Mac apps can only get Full Disk Access through 'very explicit user action', warning that the risks grow as AI agents become more autonomous. No timeline was given.

AgentsAI NewsroomOctober 6, 20263 min read

Apple says it will change how Mac apps obtain Full Disk Access, the macOS permission that lets an app read nearly everything on a computer. In a short post on its developer news site dated October 2, the company tied the change directly to the spread of autonomous AI agents.

What Apple said

Apple explained that Full Disk Access "largely sidesteps" the privacy controls that normally govern what apps can read, and that it exists mainly so backup software works properly. According to the post, some developers are using it in ways that expose files, mail, messages and browsing history "without users' full knowledge and understanding," and for communication apps that can also compromise the privacy of the people users talk to.

Going forward, Apple says it will add controls so that users who genuinely want to grant this level of access can only do so through "very explicit user action." The post adds that the risks of this access "will grow substantially" as AI agents become more capable and autonomous. Apple did not say when the controls will ship, which macOS version they will arrive in, or what the new consent flow will look like, and it did not comment further to TechCrunch.

Why agents are in the frame

Always-on desktop agents commonly ask for Full Disk Access because it lets them read local files, email and message history to act on a user's behalf. Engadget names OpenClaw, OpenAI's newly launched Dots and Meta's Muse among the agent apps that request it.

The announcement followed a dispute over Muse. Inc. columnist Jason Aten reported that the Muse Mac app had accessed his private messages even though he believed he had not granted permission. Meta disputed the account, saying that if his messages synced to the app, he must have consented during setup. Apple's post does not name any app or developer.

What it means for users and builders

For users, the change should make it harder to hand an agent sweeping access by clicking through a setup screen. For developers of desktop agents, it signals that broad, always-on access to a Mac will carry more friction, and that products relying on it may need to work with narrower, purpose-specific permissions. Some users already run agents on dedicated machines rather than their main computer, Engadget notes. Until Apple publishes details, the practical impact on existing apps that already hold the permission remains unclear.

AI-assisted reporting, overseen by the AgentsAI team. Spotted an error? Let us know.