Apple told Mac developers on October 2 that it will add new controls around Full Disk Access, the macOS permission that hands an app a whole machine at once, and it named autonomous AI agents as the reason. The permission exists so backup software can work, Apple said, but some developers are now using it in ways that could put users at risk.
In a post on its developer news channel, Apple wrote that granting Full Disk Access exposes files, mail, messages and even browsing history, and that it is often happening without users' full knowledge and understanding. Going forward, it said, users who genuinely wish to grant an app that level of access will be able to do so only through very explicit user action.
Key takeaways
- Apple will add new consent controls to macOS Full Disk Access, which currently exposes files, mail, messages and browsing history to any app a user approves.
- Apple's stated reason is AI agents: it says the risks tied to this level of access will grow substantially as agents become more capable and autonomous.
- The post names no app, no macOS version and no shipping date, and Apple declined to answer press questions about the change.
What Full Disk Access actually hands over
Full Disk Access is the broadest consent prompt on macOS. It was designed for software that has a legitimate need to read everything β backup tools, chiefly β and it is granted once, in System Settings, with no per-folder scoping afterward. An approved app can read the Mail store, the Messages database and browser history alongside ordinary documents.
That design assumed the approved app was a passive utility. Desktop generative AI assistants break the assumption, because they act on what they read and decide for themselves which files to open next. Apple's framing is explicit on this point: as agents become more capable and autonomous, it argued, the risk attached to a one-time blanket grant grows substantially, and users should understand that risk before they accept it.
The narrower alternative already exists. macOS has offered scoped prompts for folders such as Desktop, Documents and Downloads for years, so an assistant that only needs a working directory can ask for that instead. The practical problem is that scoped consent is a worse onboarding experience, since each folder is its own dialog, while Full Disk Access clears every obstacle in a single approval. Shifting the friction from the precise option to the blunt one is the lever Apple is reaching for.
The incidents that preceded the post
Apple did not cite a specific product, but the timing sits close to two reports. Days earlier, Inc. columnist Jason Aten wrote that Meta's Muse app on the Mac knew the contents of his private messages despite his saying he had never granted it permission β a claim Meta disputed. Muse offers Full Disk Access as an optional toggle rather than a requirement. Our earlier coverage detailed how Meta characterised Muse's filesystem reads as intended behaviour.
Separately, Wired reported that a flaw in ChatGPT's Mac app could have let attackers reach sensitive data. Taken together, the two episodes point at the same structural problem: the permission model cannot distinguish an agent that reads a file to back it up from one that reads it to reason about it, and users approving the prompt have no way to tell either.
What Apple did not say
The post is unusually short on specifics for a platform change of this scope. Apple named no macOS release, gave no date, and did not say what very explicit user action means in practice β a re-consent interval, per-category control, or a hardware-backed confirmation. It also did not answer TechCrunch's questions about the change.
The vagueness carries its own signal. A direction announced through developer news rather than a release note typically lands ahead of the code, which hands app makers a window to retreat from the permission voluntarily before a changed prompt makes the decision for them. The ones that wait will be explaining a new scary dialog to their own users.
For developers shipping Mac agents, that leaves a planning gap. Any product whose onboarding currently asks for Full Disk Access should expect the grant to become harder to obtain and easier for users to refuse, which argues for designing around narrower, scoped permissions now rather than after the control lands.
FAQ
What does Full Disk Access let a Mac app see?
Apple says the permission gives an app access to files, mail, messages and browsing history. It is granted in System Settings and applies system-wide rather than to a chosen folder, which is why Apple describes it as an extraordinary level of access.
Is Apple removing Full Disk Access?
No. Apple said it will add controls so that users who genuinely want to grant the permission can still do so, but only through very explicit user action. The permission remains available for software such as backup tools that legitimately need it.
When do the new controls arrive?
Apple has not said. The developer post gives no macOS version number and no timeline, and the company did not answer press inquiries about the schedule, so developers have a stated direction but no date to build against.






