Apple Will Tighten macOS Full Disk Access, Citing Risks From AI Agents
Apple says it will add controls so Mac apps can only get Full Disk Access through 'very explicit user action', warning that the risks grow as AI agents become more autonomous. No timeline was given.
Apple says it will change how Mac apps obtain Full Disk Access, the macOS permission that lets an app read nearly everything on a computer. In a short post on its developer news site dated October 2, the company tied the change directly to the spread of autonomous AI agents.
What Apple said
Apple explained that Full Disk Access "largely sidesteps" the privacy controls that normally govern what apps can read, and that it exists mainly so backup software works properly. According to the post, some developers are using it in ways that expose files, mail, messages and browsing history "without users' full knowledge and understanding," and for communication apps that can also compromise the privacy of the people users talk to.
Going forward, Apple says it will add controls so that users who genuinely want to grant this level of access can only do so through "very explicit user action." The post adds that the risks of this access "will grow substantially" as AI agents become more capable and autonomous. Apple did not say when the controls will ship, which macOS version they will arrive in, or what the new consent flow will look like, and it did not comment further to TechCrunch.
Why agents are in the frame
Always-on desktop agents commonly ask for Full Disk Access because it lets them read local files, email and message history to act on a user's behalf. Engadget names OpenClaw, OpenAI's newly launched Dots and Meta's Muse among the agent apps that request it.
The announcement followed a dispute over Muse. Inc. columnist Jason Aten reported that the Muse Mac app had accessed his private messages even though he believed he had not granted permission. Meta disputed the account, saying that if his messages synced to the app, he must have consented during setup. Apple's post does not name any app or developer.
What it means for users and builders
For users, the change should make it harder to hand an agent sweeping access by clicking through a setup screen. For developers of desktop agents, it signals that broad, always-on access to a Mac will carry more friction, and that products relying on it may need to work with narrower, purpose-specific permissions. Some users already run agents on dedicated machines rather than their main computer, Engadget notes. Until Apple publishes details, the practical impact on existing apps that already hold the permission remains unclear.
Sources
- Updates to Full Disk Access in macOS — Apple Developer
- Apple says it's tightening macOS 'Full Disk Access' controls due to new risks from AI agents — TechCrunch
- Apple Announces 'Full Disk Access' Changes on macOS Due to AI Agents — MacRumors
- Apple sounds the alarm on AI agents and 'Full Disk Access' — Engadget
AI-assisted reporting, overseen by the AgentsAI team. Spotted an error? Let us know.
Related agents
More agents news
OpenAI's Dots Bring Always-On Agents to ChatGPT Pro and Business Premium
Unveiled at DevDay 2026, dots are persistent GPT-6 Astra agents with their own cloud computer that work toward user goals around the clock. They are rolling out to ChatGPT Pro and Business Premium, with the EU, Switzerland and UK excluded for Pro.
Cognition Launches SWE-2, a Cheaper Coding Model Built Into Devin
Cognition released SWE-2, a coding model post-trained from Moonshot AI's open-weight Kimi K3, that it says nearly matches Claude Fable 5.1 on the FrontierCode 1.1 benchmark at roughly 64% lower cost, and shipped it immediately inside Devin.
Salesforce Launches Seven 'Job-Ready' Agentforce Agents and a Long-Horizon Runtime
Salesforce unveiled seven named Agentforce agents built for specific roles across sales, service, HR and supply chain, plus a new runtime that lets an agent pursue a goal over days or weeks instead of a single session.
OpenAI Opens Its Codex Agent Harness to Developers With New Agents API
OpenAI launched the Agents API in public beta, giving developers direct access to the same orchestration harness that powers Codex — session management, context compaction, subagents and sandboxed execution — behind a single API.