Apple Tightens macOS Disk Access for AI Agents
Apple has said it is tightening how macOS grants Full Disk Access, with AI agents as the stated reason. Apps will get the permission only with "very explicit user action", and Apple warned the risks "will grow substantially" as agents become more capable.
Apple has not published timing or implementation details, so this article covers what was said and what is still open.
⚡ Quick facts
- What changes: Full Disk Access will require very explicit user action
- What it covers: Access to files, mail, messages and browsing history
- Why: Apple says agent risks will grow substantially as agents become more capable
- Examples cited in coverage: Reports on Meta's Muse app reading private messages and a ChatGPT Mac app flaw
- Unknown: Timing and exact implementation, neither detailed by Apple
What Full Disk Access is
Full Disk Access is a macOS privacy permission that lets an app read protected data across your Mac, including files, mail, messages and browsing history. It exists for backup and security tools, but it is also exactly what an AI agent would want in order to act on your behalf.
Why Apple is acting now
Apple said the risks grow as agents become more capable. Coverage by Engadget and MacRumors points to recent concerns: reports about Meta's Muse app reading private messages, and a Wired report on a flaw in the ChatGPT Mac app. Agents named in coverage include OpenClaw, Dots and Muse.
What we know and do not know
Apple has given no date and no details on what the "very explicit" step will look like, such as a new prompt or extra confirmation. Developers building agents should expect narrower, per-folder permissions to become the norm.
What Mac users can do today
Review System Settings, Privacy & Security, Full Disk Access and remove anything you do not recognise. Prefer agents that ask for specific folders. The risk of broad agent access is also covered in our AI agent security explainer and the Muse story.
Frequently asked questions
What did Apple announce?
Apple said apps will get macOS Full Disk Access only with very explicit user action, citing the growing risks from AI agents.
What can Full Disk Access reach?
Files, mail, messages and browsing history.
When does the change start?
Apple has not given timing or implementation details.
Which apps prompted the concern?
Coverage mentions reports about Meta's Muse app reading private messages and a ChatGPT Mac app flaw, plus agents such as OpenClaw and Dots.
What should I do now?
Check Full Disk Access in System Settings and remove apps you do not need or recognise.
Sources
- Engadget: Apple sounds the alarm on AI agents and Full Disk Access
- MacRumors forums: Apple announces Full Disk Access changes on macOS
- AI Weekly: Apple tightens macOS Full Disk Access citing AI agent risks