Apple says it will add new safeguards to a macOS permission that lets apps read nearly everything on a Mac, after AI agents began leaning on it in ways the company never intended.
The setting, Full Disk Access, was built so backup tools could reach every file. In a developer note published on October 2, Apple said the design “largely sidesteps” its normal privacy controls, and that some developers are now using it “in ways that could put users at risk.” Files, mail, messages and browsing history can all be exposed, it warned, without a user’s full knowledge.
Going forward, anyone who genuinely wants to grant that “extraordinary level of access” will have to do so through very explicit action, Apple said. It did not give a ship date or spell out the interface changes.
The shift follows an October report by Inc. columnist Jason Aten, who said Meta’s Mac agent Muse knew the contents of private messages he had not shared with it. Meta disputed the account. Days earlier, a separate disclosure showed that a flaw in OpenAI’s ChatGPT app for macOS could have handed local code access to data the assistant already held.
Apple framed the move as a response to scale. As agents grow more capable and autonomous, it said, the risk tied to broad disk access will grow substantially. The company said users should understand those risks before handing over the keys.
Full Disk Access sits outside the sandbox rules that govern ordinary apps, which is why it is treated as a last resort for tools that truly need the whole volume. Apple has not said which macOS release will carry the changes.