Apple says it will add new safeguards to Full Disk Access, one of the most powerful permissions on the Mac, warning that increasingly capable artificial intelligence agents make the setting a growing threat to user privacy.
In a notice posted Friday on its developer news site, Apple said some developers are using the permission in ways that can expose everything on a computer, including files, email, messages and browsing history, without users fully knowing or understanding it. Apple said it will introduce additional controls so that people who truly want to give an app that level of access can do so only through very explicit action.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple wrote.
Apple did not say when the changes will arrive or exactly how they will work, and it did not respond to an inquiry from TechCrunch. In a correction to its report, TechCrunch said the change is about making sure users give informed consent and is not a new limit on the permission.
Why AI agents raise the stakes
Full Disk Access exists mainly so backup software can work properly on the Mac, and it largely bypasses the privacy controls Apple builds into macOS, the company said in its post. Apple added that when communication apps hold the permission, the privacy of the people users talk to can also be put at risk.
The rise of AI agents, programs that can operate a computer and carry out tasks on a user’s behalf, has sharpened that concern. Desktop agent apps such as Meta’s Muse and OpenAI’s Dots often prompt users to turn on Full Disk Access, which lets the agents read files and messages, Engadget reported, and the privacy risks have led some people to run agents on dedicated computers.
Apple’s announcement came days after Inc. columnist Jason Aten wrote that Muse knew the contents of his private messages even though he said he had not given the agent permission, according to TechCrunch. Meta disputed his account, and Engadget reported that the company said he must have opted in if his messages synced. Apple’s post did not name Muse or Meta. TechCrunch also pointed to a recent Wired report about a flaw in ChatGPT’s Mac app that could have let hackers reach sensitive data.
What Mac users can do now
Mac owners do not have to wait for Apple’s update to check which apps hold this level of access. Apple’s support guide says the list can be reviewed and changed by choosing Apple menu > System Settings, clicking Privacy & Security in the sidebar and then selecting Full Disk Access. According to Apple, apps granted the permission can see data from other apps such as Mail, Messages and Safari, as well as Time Machine backups.
What’s next
Apple has not published technical details for developers, including how the new controls will work or which versions of macOS will include them. The company has said only that it wants users to understand the risks before they grant such access, so they can make informed choices about their data and privacy.




