Apple plans to tighten the way Mac applications obtain full-disk access, citing the heightened risks created by AI agents that can act with growing capability and autonomy. The change, disclosed in a developer update and reported by The Verge on October 2, is intended to make the grant of this unusually broad permission depend on unmistakable user action.
Full-disk access is one of macOS’s most powerful permissions. It can allow an application to reach data across a user’s system, including files, email, messages and browsing history. Apple said the permission was designed in large part so backup applications could function properly, but acknowledged that it can bypass many of the privacy controls users ordinarily rely on.
According to The Verge, Apple said some developers are now using the permission in ways that may expose sensitive information without users fully understanding the scope of what they approved. The company did not describe the final design of the new controls, but said users who truly intend to provide this level of access should have to take a very explicit action.
The timing matters because AI agents are built to do more than answer questions. When software can search, organize and act across a computer, a broad permission is no longer merely a way to read stored data; it can become the foundation for a much wider set of automated tasks. That is an inference from the access Apple described, and it helps explain why a permission long associated with utilities is receiving new scrutiny.
The announcement follows a recent dispute involving Meta’s Muse AI. The Verge reported that Inc. writer Jason Aten said Muse appeared to know the contents of his messages even though he had not knowingly given the chatbot explicit permission to read them on his iPhone or Mac.
Meta spokesperson Andy Stone disputed the implication that Muse receives that access by default. He said access to Messages is opt-in and requires a user to enable both macOS Full Disk Access and a separate Messages connector. The two accounts leave an important point unresolved: a technically opt-in process may still fail to communicate the practical reach of a permission clearly enough to every user.
Apple has not announced when the tighter controls will arrive, and The Verge said the company did not immediately provide additional comment. That leaves open questions about which macOS version will include the change, how many approval steps will be required and whether existing grants will be reviewed or preserved.
Even without those implementation details, Apple’s decision signals a shift in the security assumptions surrounding desktop AI. Permissions designed for conventional applications are being reassessed for software that can interpret private information and take actions with limited supervision. The effectiveness of Apple’s response will depend on whether the new approval flow gives users genuine understanding and control, rather than adding another warning that is easy to click through.