Apple says AI agents force new limits on macOS Full Disk Access
Apple says it will make users take "very explicit" action before an app gets Full Disk Access, citing AI agents that may read files, mail, messages and browsing history.
Apple said on Friday it will add new controls around Full Disk Access, the macOS permission that lets an app see nearly everything on a Mac. According to TechCrunch, the company warned that some developers use the setting in ways that could put users at risk, exposing their systems without users' full knowledge and understanding.
Apple said it wants users who truly wish to grant that level of access to do so only through "very explicit user action". It also said that as AI agents become more capable and autonomous, the risks tied to such access "will grow substantially", as quoted by 9to5Mac and TechCrunch.
Apple has not said what the new controls will look like or when they will arrive, according to 9to5Mac. Engadget reports that the company named no particular app in its statement, though desktop AI clients such as OpenClaw, Dots and Muse are among those that request broad access to files, messages and mail.
The announcement follows a dispute over Meta's Muse agent. TechCrunch says a user reported that Muse read private Mac messages without permission, and that Meta disputes the claim. TechCrunch also points to a Wired report on a security flaw in ChatGPT's Mac app that could let attackers reach sensitive data. Neither case is confirmed to have prompted Apple's change.
Full Disk Access was designed so that backup tools could copy a whole disk, TechCrunch notes. Nothing in the coverage says Apple will remove the permission, only that granting it will need more deliberate steps. How far that slows agent products that depend on it will not be clear until Apple publishes details.