Apple will add stricter macOS Full Disk Access controls as AI agents gain access to files and messages, raising new privacy and security demands.

Apple is preparing new controls for macOS’s Full Disk Access permission, warning that increasingly capable AI agents make unrestricted access to files, messages, mail, and browsing history more dangerous.
The company said developers are using the permission in ways that may expose a user’s entire computer “without users’ full knowledge and understanding.” Apple plans to require “very explicit user action” from people who want to grant an application this level of access, although it has not described the final interface, timing, or technical enforcement mechanism.
The announcement arrives amid growing scrutiny of desktop AI tools that can read local data and perform actions on a user’s behalf. It follows a public dispute over Meta Muse and a separate report about a potential security flaw in the ChatGPT Mac app, putting operating-system permissions at the center of the debate over how autonomous software should operate on personal computers.
Full Disk Access is a macOS privacy setting originally associated with applications such as backup tools that need broad visibility across a computer. Apple’s explanation of the permission says it can allow an application to access files, mail, messages, and browsing history.
That breadth is particularly significant for AI agents. Unlike a conventional application that performs a narrowly defined task, a desktop AI agent may be designed to search across documents, interpret communications, use other applications, or take actions based on information found on the system. A permission that was once mainly a technical requirement for system utilities can therefore become a gateway to highly sensitive personal and business information.
Apple said the risk will grow as AI agents become “increasingly capable and autonomous.” The company framed the planned changes as a way to ensure users understand what they are authorizing before handing an application access to data that may span nearly every part of their digital life.
The company has not said that Full Disk Access itself will be removed. Based on Apple’s statement, the change is intended to make broad authorization harder to grant accidentally or without a clear understanding of its consequences.
The immediate context includes a report by Inc. columnist Jason Aten, who said Meta Muse appeared to know the contents of his private messages even though he had not knowingly granted the AI agent permission to access them. Meta disputed the claim, according to TechCrunch’s reporting, so the incident does not establish that Muse bypassed macOS protections or improperly accessed the messages.
The episode nonetheless exposed a trust problem for desktop AI. Users may not know whether an agent is reading local content through an operating-system permission, through integrations they enabled elsewhere, or through another application already authorized to access their data. That uncertainty can make a permission prompt insufficient protection on its own.
TechCrunch also cited a Wired report describing a flaw in the ChatGPT Mac app that could have allowed hackers to access sensitive information. The available reporting does not establish the extent of exploitation or whether the issue remains active, but it illustrates a broader concern: an AI application with extensive local access can create a high-value target if its own security controls fail.
The reports involving Meta Muse and the ChatGPT Mac app are context for Apple’s policy response, not proof that all desktop AI agents misuse Full Disk Access. Apple’s statement was a general warning aimed at developers rather than an accusation against a named product.
Apple confirmed that it will introduce additional controls around Full Disk Access and that the controls will require explicit user action. It also said the goal is to help people make informed decisions about their data before granting an application what it called an “extraordinary level of access.”
The company has not provided a release date, identified the macOS version involved, or explained whether the change will affect applications that already have permission. It has also not detailed whether developers will face new review requirements, additional disclosures, or technical limits on how applications use the access once granted.
Those omissions matter for software teams. A more prominent warning could improve consent without changing an agent’s capabilities, while deeper enforcement could require developers to redesign file-search, messaging, backup, or automation workflows. Until Apple publishes implementation details, the operational impact remains uncertain.
The strongest claims in this story come from Apple’s own developer-facing statement and describe a risk assessment, not a measured incident rate or independent benchmark. Media reports provide the surrounding examples, but the available evidence does not quantify how often AI tools access data unexpectedly or how many users have been affected.
For AI developers, Apple’s move is a signal that broad desktop permissions will increasingly be treated as a product and security issue, not merely an onboarding step. Teams building AI agents for macOS may need to explain exactly which data sources are required, offer narrower alternatives where possible, and make permission-dependent features understandable before activation.
The change also raises architectural questions. An agent that can complete more tasks from a local computer may be more useful, but its failure modes become harder to isolate. Prompt injection in a document, malicious content in an email, or a compromised integration could potentially influence actions when the agent can both read sensitive information and operate other software. Apple’s announcement does not solve those risks, but it may force products to confront them more visibly.
Enterprise buyers should distinguish between an application’s stated capabilities and the access it actually receives. Organizations evaluating desktop AI should review macOS permissions, logging, data retention, administrative controls, and the ability to revoke access. They should also consider whether employees need full-system access at all, or whether a controlled workspace, approved connector, or limited document repository would meet the same business need.
For users, clearer consent is useful but not sufficient. A permission prompt cannot explain every way an autonomous system might process data after access is granted. Product documentation, visible activity histories, revocation controls, and safeguards against unintended actions will remain important alongside Apple’s operating-system changes.
The next important signal will be Apple’s technical documentation. Developers and security teams will need to know whether the new controls arrive in a specific macOS release, apply to existing grants, or introduce a new permission tier for AI applications.
Watch also for changes in how desktop AI products request access. A move from one broad authorization to task-specific permissions would materially alter the design of agents that search messages, manipulate files, or interact with other applications.
Finally, further reporting should clarify the Meta Muse incident and the ChatGPT Mac app issue. Confirmed technical findings, rather than disputed accounts or general warnings, will determine whether the central problem is permission design, application behavior, software vulnerabilities, or a combination of all three.
Apple’s announcement recognizes a practical mismatch between legacy desktop permissions and modern AI agents. Full Disk Access was already powerful, but an autonomous system can make broader and more frequent use of that access than many traditional utilities. Requiring more deliberate consent is a reasonable baseline response.
The harder challenge is accountability after consent. Builders and enterprises will need controls that show what an agent accessed, why it accessed it, and what it did next. Apple’s forthcoming implementation will be important, but trustworthy desktop AI will depend on product-level transparency and containment as much as on a stronger permission prompt.