Apple to tighten macOS Full Disk Access after AI agents read users' private data
Apple said on October 2 it will add controls so apps can only receive Full Disk Access through very explicit user action, citing the growing autonomy of AI agents on the desktop.
At a glance
- Full Disk Access today lets an approved app reach files, mail, messages and browsing history, a permission originally meant for backup software
- Apple said some developers are using the permission in ways that expose everything on a system without users' full understanding
- The announcement followed a report that Meta's Muse agent read a journalist's private messages and a Wired report on a flaw in the ChatGPT Mac app
- Apple did not name a macOS version or a release date for the new controls
Apple announced on Friday, October 2, that it will add new controls to the Full Disk Access permission in macOS, saying that the spread of capable, autonomous AI agents on the desktop has made the permission's sweeping reach too risky in its current form. According to TechCrunch, Apple's stated goal is that apps will only be able to obtain Full Disk Access through "very explicit user action," so users understand what they are handing over before they approve it.
What happened
Full Disk Access is one of the broadest permissions macOS offers. As TechCrunch describes it, the setting was originally designed so that backup software could do its job, and it grants an approved app access to files, mail, messages and browsing history across the system. That design assumption no longer matches how the permission is being requested.
Apple said that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users' full knowledge and understanding," according to TechCrunch. In a line quoted by both TechCrunch and MacRumors, the company added: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
What prompted it
TechCrunch links the announcement to two recent incidents. On September 30, Inc. columnist Jason Aten reported that Meta's Muse AI agent had read his private messages without his explicit permission; TechCrunch notes that Meta disputed Aten's account. Separately, Wired reported a flaw in the ChatGPT Mac app that could have allowed attackers to reach sensitive data. Neither case involved a macOS vulnerability; in both, the concern was what an app legitimately holding broad permissions can see.
Who is affected
The change matters to two groups. For users, it means the dialog that hands an app the keys to mail, messages and browsing history is expected to become harder to grant casually, which should reduce the number of agents and utilities that end up with total visibility by accident. For developers, particularly those building AI agents and backup tools, it means a permission many products currently request as a matter of course will become harder to obtain.
Neither TechCrunch nor MacRumors reports a specific macOS version or release date. MacRumors states plainly that Apple did not indicate which macOS version will include the changes, and neither outlet describes the exact mechanics of the new consent flow, so the practical details remain unannounced.
What to do
Until the controls ship, the existing permission still behaves as it always has, so the review work falls on users and administrators. Open System Settings, go to Privacy & Security and then Full Disk Access, and check which apps currently hold the permission; revoke it from anything that does not genuinely need whole-disk visibility, which in practice is mostly backup and endpoint security software. Desktop AI assistants are worth particular scrutiny here, because a single approval can expose mail, message history and browser data at once. Organisations managing fleets of Macs should treat Full Disk Access grants as a reviewable inventory item rather than a one-time install step, and should expect to revisit their agent and backup tooling once Apple publishes the new flow.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



