Apple plans stricter macOS disk access controls to address growing privacy risks from AI agents.

Apple says Full Disk Access largely bypasses macOS’s usual privacy protections, making it an unusually broad permission rather than an ordinary app access setting.
Apple warned that the risk can extend beyond the person granting access: for communication apps, exposure of messages may also compromise the privacy of the people they communicate with.
The permission is not limited to AI apps: desktop apps can gain broader access to files and messages when users change macOS settings, and Muse offers users the option to enable Full Disk Access.
Apple plans to add stricter controls to macOS Full Disk Access, a powerful permission that currently allows apps to bypass most privacy protections and access files, emails, messages, and browsing history MacRumors. The company says some developers use this permission in ways users don't fully understand, and fast-improving AI agents make the risks worse. Apple has not yet detailed the changes but says users will need to take a more explicit action to grant access Engadget.
The announcement follows recent privacy incidents. An Inc. columnist claimed Meta's Muse app accessed his private messages without clear permission — Meta disputed the claim. Separately, Wired reported a vulnerability in ChatGPT's Mac app that could have exposed sensitive data. These events highlighted how broadly AI tools can access personal information MacRumors.
Full Disk Access is not like other app permissions on Mac. Most app permissions are narrow — a camera app accesses only the camera, a photo editor only your photos. Full Disk Access is different. It largely bypasses macOS's usual privacy protections, giving apps sweeping access to almost all files on your computer MacRumors. Originally designed to help backup apps work properly, the permission has become a blanket tool for developers.
The risk extends beyond just you. When communication apps like email or messaging services gain Full Disk Access, they can read your messages — and that exposes your contacts' privacy too MacRumors. If an email app goes rogue or is hacked, it doesn't just compromise your inbox. It also leaks the private conversations of everyone who emailed you. This chain reaction is why Apple now views the permission as unusually dangerous.
Apple warned that AI agents compound the risk. These tools are designed to explore and analyze data on your computer. Give an AI agent Full Disk Access, and it can read through your files, emails, and browsing history searching for patterns or answers Engadget. Unlike traditional apps that access specific files on demand, AI agents may probe everything available — simply because they're trained to find and use all available information.
The threat is not limited to AI-focused apps. Meta's Muse, a productivity tool, offers users the option to enable Full Disk Access. ChatGPT's Mac app had a vulnerability that could have exposed sensitive data. These real-world examples show how the permission can be misused across many categories of software TechBuzz.
Apple's solution is to require users to take a more explicit action before granting Full Disk Access. The company has not yet published details on how the new controls will work MacRumors. The change suggests Apple may add additional warnings, require users to confirm their choice multiple times, or require a more deliberate step — such as dragging an app into a folder or typing a confirmation code.
The move signals Apple's concern that users currently don't understand what they're agreeing to. A simple checkbox next to "Full Disk Access" doesn't convey the true scope of what the permission allows. By making the grant process more cumbersome, Apple hopes users will pause and think before handing over access to their entire digital life Engadget.
Publishers
52
Articles
73
Reach
125