Apple restricts macOS Full Disk Access over AI agent risks
Apple is tightening its macOS Full Disk Access controls to prevent increasingly autonomous AI agents from silently accessing sensitive user data like messages and browsing histories.

Apple announced plans to introduce stricter controls for its macOS Full Disk Access setting, a feature originally designed to help backup utilities function. The company explained that the rise of highly capable and autonomous AI agents has dramatically increased the security risks associated with granting this level of system permission. Under the new policy, users who want to grant an application this broad access will have to go through a process requiring what Apple calls very explicit user action.
The policy shift follows recent security controversies involving desktop AI applications. Columnist Jason Aten recently reported that Meta's Muse app on Mac accessed his private messages without permission, a claim that Meta has disputed. Additionally, a security flaw discovered in the ChatGPT Mac app reportedly could have allowed hackers to steal sensitive user data. These incidents have highlighted how desktop-based AI tools can exploit broad system permissions to read private files, emails, and browsing histories.
For software developers and AI practitioners, this change means that relying on Full Disk Access to power desktop agents will become significantly more difficult. Apple warned that some developers currently use the setting in ways that put users at risk by exposing entire systems without their full understanding. As Apple implements these stricter prompts, developers will need to design their applications to operate with more limited permissions or prepare users for highly conspicuous security warnings. Apple emphasized that as AI agents grow more autonomous, the risks associated with this level of access will grow substantially, making clear user consent a critical priority.
This is our own summary of reporting by TechCrunch AI



