New Mac controls will narrow full disk access for AI agents

Apple says it will add new controls around full disk access on Mac because AI agents make broad system permissions riskier. Apps seeking this level of reach will need very explicit user action, though Apple has not said when the update will arrive.

WTF Index TERMINATOR
◄ Terminator 3 Idiocracy 0 ►

The story centers on more capable autonomous AI agents increasing privacy and system-control risks from broad Mac permissions.

New Mac controls will narrow full disk access for AI agents

Apple is preparing to tighten one of the broadest permissions available on macOS: full disk access. The company says new controls are coming because AI agents are becoming more capable and autonomous, raising the stakes when an app can reach across a user’s system.

The change is aimed at making sure a Mac app can receive this extraordinary level of access only when the user takes very explicit action. Apple has not said when the update will roll out.

What Apple is changing on Mac

Full disk access is a macOS permission that gives an app access to a user’s entire system. Apple describes the permission as one that can “largely sidesteps” the privacy controls users normally rely on, because it exists to let backup apps work properly on Mac.

That breadth is exactly why Apple is adding new limits. In an update on Friday, the company said it wants to “ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.”

In practical terms, the issue is not simply whether an app asks for permission. The concern is whether users clearly understand what they are granting when a Mac app receives full disk access. Apple’s framing suggests the company sees this permission as different from a narrower request, because it can expose information across many parts of the system.

Why AI agents raise the risk

Apple tied the new controls directly to AI agents. The company said some developers are using full disk access in ways that could put users at risk by exposing everything on their systems, including files, mail, messages, and browsing history, without users’ full knowledge and understanding.

Apple also warned that the risk will grow as AI agents become more capable and autonomous. The key point is that an app with broad access can potentially work across sensitive data categories at once. When that app also has AI features that can process or act on information, the permission becomes more consequential.

The concern is not limited to one type of file or one privacy category. The source describes a permission that can reach the entire system, which means the possible exposure can include several kinds of personal data at the same time.

  • Files stored on the Mac
  • Mail content
  • Messages
  • Browsing history

That makes user consent harder to treat as a routine prompt. Apple is now emphasizing a higher bar: a user should not end up granting this level of access without a clear and deliberate action.

The Meta Muse AI episode

The change follows an incident involving Meta’s Muse AI. Inc’s Jason Aten found that Meta’s Muse AI somehow knew the contents of his messages, despite not giving the chatbot explicit permission to access them on his iPhone or Mac.

Meta spokesperson Andy Stone pushed back on the report. He said access to Messages is “entirely opt-in.” Stone also said a user must “enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content.”

That exchange highlights the kind of confusion Apple appears to be addressing. If an app requires multiple settings before it can read a sensitive category such as Messages, the user still needs to understand the meaning of each step. A broad system permission can be easy to underestimate, especially when it is presented alongside a feature-specific connector.

Apple’s response does not describe the Meta situation as the only reason for the change. But the timing connects the broader policy shift to a public example of concern over what AI software can see once permissions are enabled.

What remains unclear

Apple has said new controls are coming, but it has not provided a rollout date. The company also did not immediately respond to The Verge’s request for comment.

For now, the clearest takeaway is that full disk access on Mac is being treated as an exceptional permission, not a routine checkbox. Apple is signaling that AI agents make the old balance harder to defend, because systemwide access can combine with more autonomous software behavior.

That does not mean full disk access is going away. Apple notes that the feature exists so backup apps can function properly on Mac. The change is about making the path to that permission more explicit, especially when apps can reach sensitive information across the system.

For users, the issue is simple: full disk access is powerful. For developers, Apple’s message is equally direct: asking for that permission will face more scrutiny as AI agents become part of more Mac software.