Safety & Security

Apple moves to rein in AI agents with new macOS 'Full Disk Access' controls

Apple said it will tighten macOS Full Disk Access for AI agents, citing risks to files, mail, and messages. The move follows complaints about Meta's Muse reading user data without clear consent.

By James Calloway5 min read

Updated

Why it matters

  • Apple said it will add 'additional controls' to Full Disk Access in macOS to address AI agent risks.
  • Apple did not announce a release date or describe the specific technical changes.
  • Inc. columnist Jason Aten reported that Meta's Muse Mac app accessed his messages despite believing he had denied permission.
  • Meta told Aten that his messages must have synced, meaning he had opted in.
  • Mac Mini shortages this year have been linked to users running AI agents on dedicated machines.

Cupertino warns that some AI developers aren't being upfront with users about privacy tradeoffs.

Apple said this week it will tighten the way macOS grants "Full Disk Access" to applications, citing risks created by AI agents that read mail, messages, and files on users' machines.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding," the company said in an update to its developer guidance.

The Cupertino company framed the move as a response to a category of software that has spread quickly over the past year: AI agents that need broad system access to act on a user's behalf. Desktop clients for tools like OpenClaw, Dots, and Meta's Muse routinely instruct users to grant Full Disk Access so the agents can manipulate files, draft messages, and complete workflows across apps.

What does Apple actually plan to change?

Apple did not name a release date or describe the specific technical changes it will make. Its statement stops short of restricting Full Disk Access outright. Instead, it commits to "additional controls" and "very explicit user action" before an app receives the privilege.

"Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action," Apple said.

The phrasing leaves open whether the company will require re-confirmation prompts, step-up authentication, or a dedicated toggle for AI agents. macOS has long required users to authenticate before granting Full Disk Access, but a single approval is enough for indefinite background access. Apple has not said whether the new controls will apply retroactively to apps that already hold the permission.

Why is Apple sounding the alarm now?

The new language arrives weeks after users of Meta's Muse agent raised complaints about the software reading personal data without clear consent. Inc. tech columnist Jason Aten wrote that the Muse Mac app accessed his messages despite believing he had denied the permission. Meta responded that if his messages synced, he must have opted in.

Apple's warning does not mention Muse or Meta by name. But the timing, and the explicit reference to "communication apps" exposing "the privacy of the people users are communicating with," points to a debate that has shifted from developer forums into the consumer press.

"For communication apps, this can also compromise the privacy of the people users are communicating with," Apple said.

That phrasing matters because it extends the privacy stakes beyond a single user. A grant of Full Disk Access to an AI agent does not just expose the user's own files. It exposes the metadata and content of every person who has messaged, emailed, or shared a file with that user.

How exposed are users today?

Full Disk Access on macOS is a coarse-grained permission. Once granted, an app can read any file the user account can access, query the Mail and Messages databases, and watch browser history. The capability predates the AI agent era by years. It was designed for backup utilities, antivirus tools, and other software that legitimately needs wide reach.

AI agents have stretched that design in two ways. They act continuously rather than on demand, and they send summaries of what they read back to remote servers for processing. Apple appears to want users to understand both behaviors before granting access.

"Addressing this is critical," Apple said. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

Has the AI agent boom already changed Apple's hardware market?

Yes, and in measurable ways. A dedicated machine is one of the few ways a privacy-conscious user can isolate an AI agent's reach. Demand for low-cost Macs capable of running these agents has surged this year, and Mac Mini shortages have followed.

Apple's framing treats that workaround as a signal of the underlying problem: users are buying separate hardware because they do not trust their primary machines to host software with system-wide read access. New software controls would reduce, though not eliminate, the appeal of that workaround by making the primary machine a less risky place to run an agent.

What does Apple's move signal for the broader AI agent market?

The statement marks the first time Apple has publicly cast AI agents as a privacy risk class warranting platform-level intervention. No equivalent operating-system-level restriction on desktop AI agents has been announced by other major desktop platforms to date.

That silence from competitors creates two near-term scenarios. Smaller AI developers may have to redesign their onboarding flows to meet Apple's stricter consent expectations. Larger platforms will be watched for matching responses as desktop agents continue to spread across macOS, Windows, and Linux.

Apple's statement does not propose a ban. It proposes friction. The company is betting that explicit, repeated consent will be enough to make users aware of what an agent can see, while preserving the workflow gains that have made tools like OpenClaw, Dots, and Muse attractive in the first place. The rollout, when it arrives, will test whether friction alone resolves a problem that the rest of the desktop industry has so far been willing to leave alone.

What should users do in the meantime?

Until Apple ships the new controls, the existing privacy menu in System Settings remains the only line of defense. Users can revoke Full Disk Access for any app at any time, and the Mac Mini workaround remains the most aggressive option for users who do not want an agent touching their personal files at all. Developers of agentic tools, meanwhile, should expect Apple to scrutinize their permission requests more closely once the new controls arrive.

Original: developer.apple.com

Share this article:

More from James Calloway

James Calloway

Show full bio

News editor covering industry trends and analytics at AI In Context.

200 articles

Related articles

  1. Apple to Restrict Mac Full Disk Access as AI Agents Raise Risk
  2. Apple to Restrict macOS 'Full Disk Access' Over AI Agent Risks
  3. Apple Tightens macOS Permissions to Block AI Agents From Reading Messages
  4. Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
  5. Meta's Muse Builds Dossiers on Everyone in Your Life

« Previous article