Policy & Regulation

Apple to Restrict Mac Full Disk Access as AI Agents Raise Risk

Apple will restrict macOS full disk access, citing substantial new risks from AI agents. New controls require "very explicit user action" to grant apps total file access.

Apple will limit Mac disk access as AI agents ‘substantially’ increase risk
Apple will limit Mac disk access as AI agents ‘substantially’ increase riskAI-generated
By Rebecca Stone4 min read

Updated

Why it matters

  • Apple announced new controls on "full disk access" in macOS in a developer update on Friday, citing risks from AI agents.
  • Apple says the controls ensure users can grant this "extraordinary level of access" only with "very explicit user action."
  • The change comes weeks after Inc's Jason Aten reported that Meta's Muse AI knew his messages' contents without explicit permission; Meta's Andy Stone said Messages access is "entirely opt-in."

Apple will impose new restrictions on "full disk access" permissions in macOS, citing a risk profile that the company says AI agents have changed in a substantial way.

The company confirmed the change in an update to developers published on Friday. Apple says it is rolling out new controls designed, in its words, "to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."

TechCrunch reported the news earlier before Apple's developer update made the policy shift official.

The move targets one of the most powerful permissions in macOS. Full disk access allows an application to read essentially everything stored on a Mac: files in other apps' containers, mail databases, message archives, backups, and sensitive system data. Historically, a relatively small set of tools — backup utilities, disk recovery software, search indexers — legitimately needed that level of reach, and users granted it through System Settings with a couple of clicks.

That permission model is now under strain. The rise of AI agents — software that takes actions on a user's behalf, reads documents, executes multi-step tasks, and interacts with other applications — means an increasing number of programs have a built-in appetite for broad file access. A permission designed for a narrow class of maintenance tools is being requested by software with far less predictable behavior.

Apple's own framing makes the connection explicit. The company describes the new controls as a response to risks from AI agents, and characterizes full disk access as an "extraordinary level of access" that deserves friction proportionate to its danger.

The timing is hard to separate from a recent high-profile privacy incident. Just weeks before Apple's announcement, Jason Aten of Inc. reported that Meta's Muse AI chatbot appeared to know the contents of his messages, even though he had never given the chatbot explicit permission to access them on his iPhone or Mac.

Meta disputed that account. Company spokesperson Andy Stone pushed back publicly, stating that access to Messages is "entirely opt-in."

The details of exactly how Muse gained access to the message content remain contested between the reporter and the company. But the episode landed at a moment of heightened scrutiny over how AI products obtain, inherit, or infer access to deeply personal data on Apple's platforms — and it put a public face on the class of risks Apple now says it is acting against.

For developers, the change signals a tighter approval path ahead. Apps that request full disk access will face new gates intended to make casual or deceptive grants impossible. Apple's stated goal is not to eliminate the permission but to guarantee that it is only ever granted deliberately, with the user fully aware of what is being handed over. Developers whose AI-powered products depend on sweeping file access — agent frameworks, personal assistants, workspace search tools — will need to design around the assumption that the permission cannot be quietly obtained.

For users, the practical effect is that granting an application the ability to read an entire disk will become a more deliberate, interruptive act. That is a meaningful shift for a permission that has until now sat behind a standard toggle, one that many users grant reflexively when an app asks.

The policy shift also matters beyond Apple's ecosystem. Apple's permission architecture — TCC, or Transparency, Consent, and Control — has long served as a de facto reference point for how desktop operating systems mediate sensitive data access. When Apple decides that a permission category no longer matches the threat environment, other platform vendors, and the AI developers building on top of those platforms, tend to treat it as a signal. The company is effectively declaring that the agentic AI era requires a re-examination of assumptions baked into permissions designed years before chatbots roamed users' filesystems.

It also draws a sharper line in an ongoing industry argument about how much access AI assistants should have by default. Some AI vendors argue that agents are only useful in proportion to how much of a user's digital life they can see and act on. Privacy advocates, and increasingly regulators, counter that broad default access turns a convenience feature into a surveillance surface. Apple has now placed itself squarely on the side of explicit, hard-to-accidentally-grant consent.

What Apple has not yet detailed, based on the announcement so far, is the precise mechanical form the new controls will take — whether that means additional confirmation dialogs, changed entitlement review for apps distributed through its channels, or other enforcement layers. The company framed the goal rather than the implementation: users who genuinely want to grant full disk access will still be able to, but only through action Apple considers unambiguous.

How developers of agent-style applications respond — redesigning their access models around narrower, more granular permissions or pushing back on the added friction — will shape whether Apple's approach becomes the template the rest of the AI industry follows.

Original: techcrunch.com

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

184 articles

Related articles

  1. Apple to Restrict macOS 'Full Disk Access' Over AI Agent Risks
  2. OpenAI built a Windows sandbox for Codex from scratch
  3. Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
  4. Rabbit's OS3 Brings Its AI Agent Beyond the R1 Hardware
  5. OpenAI adds Lockdown Mode and risk labels to ChatGPT

« Previous article