Skip to content

Technology·News & analysis

Apple is tightening Mac 'Full Disk Access' because of AI agents

Apple says some apps use the powerful macOS permission in risky ways, and that AI agents make the danger bigger, so granting it will soon take very explicit user action.

By Dan Kost aka Poseidan8 min read
A silver 16-inch MacBook Pro with an M4 Pro chip open on a wooden table in an Apple Store, showing the macOS desktop
Photo: AzureSaturn / Wikimedia Commons, CC0

Tide

Wave

Sci-fi

3/10

Reality

Demo

Your Mac asks twice before an AI agent reads your whole life.How we rate

The Squeeze

Apple says it will add new controls to macOS Full Disk Access so apps can only get it through very explicit user action.

The permission can expose files, mail, messages and browsing history. Apple warns that AI agents make that risk grow substantially. It hasn't said when the controls arrive. The move follows a disputed report about Meta's Muse agent and a patched ChatGPT Mac flaw.

What to know

  1. Apple says it will add new controls so apps can only get macOS Full Disk Access through very explicit user action.
  2. Full Disk Access can expose files, mail, messages and browsing history, and Apple says some developers use it in risky ways.
  3. Apple warns that as AI agents grow more capable and autonomous, the risks of this level of access will grow substantially.
  4. The move follows a disputed report about Meta's Muse agent reading Messages and a patched flaw in ChatGPT's Mac app.

Apple is putting new guardrails on one of the most powerful permissions on the Mac. In a post for developers on Friday, the company said it will add controls around Full Disk Access, and pointed squarely at AI agents as the reason, as TechCrunch reports.

What is Full Disk Access?

Full Disk Access is a macOS setting that lets an app reach almost everything on your Mac. Apple says it exists so backup apps can work properly, and that it "largely sidesteps" the Mac's usual privacy controls to do that.

According to Apple, that can expose:

  • Files across your system
  • Mail
  • Messages
  • Browsing history

For communication apps, Apple adds, misuse can also compromise the privacy of the people you're talking to, not just your own.

What is Apple changing?

Apple says some developers are using Full Disk Access "in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding."

The change: going forward, Apple will introduce additional controls so that users who "genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."

Apple says that as AI agents become more capable and autonomous, the risks of this level of access "will grow substantially."

"We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

The catch: Apple hasn't said what the new controls look like or when they'll arrive. It also didn't respond to TechCrunch's request for comment.

What prompted this?

Apple didn't name any app. But TechCrunch notes the announcement came days after a dispute over Meta's Muse AI agent on the Mac.

The claim: Inc. columnist Jason Aten tested Muse on his iPhone and a Mac mini. According to The Next Web, he wrote on September 19 that Muse suggested a column based on a conversation he'd just had with his podcast co-host, and flagged a message from his editor. When he asked how it knew, Muse said it only saw incoming notification banners.

Aten then found that Muse had synced his Messages database up to row 187,462, while Muse's settings on his Mac showed Full Disk Access switched off, he wrote.

Meta's response: Meta disputes that. Communications chief Andy Stone said on X that Muse can only read Messages on a Mac if the user turns on two separate settings: Full Disk Access and the Messages connector inside the Muse app, The Next Web reports.

David Singleton, an executive at Meta Superintelligence Labs, wrote that reading Messages takes three separate steps of app and macOS permissions, and that those protections can't be bypassed even if Muse had a bug. "The Messages integration in the Muse Mac App is opt-in," he wrote.

Aten said he contacted Meta twice. In his view, an AI agent should never catch users off guard about what it reads, whatever they clicked, The Next Web reports.

Meta launched Muse, its personal AI agent, in September.

According to AppleInsider, Meta describes Muse as running on a dedicated virtual computer and using information from connected apps, and its "How Muse works" page warns that "your Muse can make mistakes or take unexpected actions." The Next Web also notes a separate case: a YouTuber said Muse gave his address to a Facebook Marketplace buyer, then later said he had ticked an "Allow Always" option, according to Business Insider.

We covered Muse's launch for businesses in our story on Meta's AI agent for small businesses.

Is it just Muse?

No. TechCrunch also points to a recent Wired report about a now-patched flaw in ChatGPT's Mac app.

According to Wired, researchers at the Objective-See Foundation found that the bug could have let an attacker essentially take over ChatGPT on a victim's Mac. That would have given access to its chat logs, other stored data and connections like browser sessions.

  • How it worked: the app's components check each other's digital signatures, but a trusted script interpreter could be tricked into passing along an untrusted script, Wired reports.
  • Three checks, beaten: the app was designed to check the request's signature at three levels of the process chain. Wardle says a malicious script could simply launch the interpreter three times and then make the request, which satisfied all three checks.
  • What an attacker could do: besides reading chat logs, the bug could have been used to make ChatGPT run commands, such as using a browser or other sensitive apps, with the requests looking like legitimate instructions from OpenAI's software.
  • How easy: veteran macOS researcher Patrick Wardle called it "insanely trivial" to exploit, with a proof of concept of about a dozen lines of code.
  • The fix: OpenAI acknowledged and fixed the flaw in its change log on September 25. "We continue to evolve our security practices, but recognize a need to move faster," OpenAI spokesperson Shane Bauer told Wired.

Wardle also found a now-patched flaw in the dictation feature of Meta's Muse that could have let a local attacker grab a mishandled login token, Wired reports.

What's next: Wardle says he has already sent OpenAI another vulnerability report, about the integration between ChatGPT and OpenAI's new always-on Dots assistant, and OpenAI is reviewing it. He plans to present an analysis of several AI app bugs on macOS at Objective by the Sea, an Apple-focused security conference, in November.

Why are AI agents a special risk?

The big picture: AI agents that run on your desktop are designed to act for you, which means they need wide access to your files, messages and apps.

"Agents need a lot of access to do their job," Wardle told Wired. "They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that's super problematic."

TechCrunch notes that these agents let users hand over much more of their personal content by changing macOS settings. Full Disk Access is the biggest of those keys, which is why Apple is now adding more friction before anyone hands it over.

"AI companies are fixated on adding features right now," Wardle told Wired. "But as always, the more features, the broader the attack surface."

In real life To see which apps already have this access, open System Settings on your Mac, go to Privacy and Security, then Full Disk Access. You can switch off any app you don't recognize or no longer need.

What it means for you

  • Check your settings now: review which apps have Full Disk Access and turn it off for any that don't really need it.
  • Expect more prompts: once Apple's new controls arrive, granting this access should take more deliberate steps.
  • Think before you grant it: if an AI agent asks for Full Disk Access, it can potentially see your files, mail, messages and browsing history.
  • Keep apps updated: fixes like OpenAI's ChatGPT patch only protect you once you install them.

The bottom line

Apple is making Full Disk Access harder to hand out, and it's explicitly blaming the rise of AI agents. The details and timing are still unknown. For now, the best move is to check which apps on your Mac already have this level of access.

Key facts

What
New controls on macOS Full Disk Access
Why
Apps using it in risky ways, and growing risk from AI agents
Announced
Apple developer news post, October 2, 2026
Change
Granting access will require very explicit user action
Timing
Apple says 'going forward,' with no date given

Got questions?

Quick answers, plain words

What is Full Disk Access on a Mac?

It's a macOS permission that largely sidesteps the Mac's usual privacy controls so backup apps can work properly. Apple says it can expose files, mail, messages and even browsing history.

What is Apple changing?

Apple says it will introduce additional controls so users who genuinely want to give an app this level of access can only do so with very explicit user action.

Why is Apple doing this now?

Apple says some developers are using Full Disk Access in ways that could put users at risk without their full knowledge, and that as AI agents become more capable and autonomous, the risks will grow substantially.

When will the new controls arrive?

Apple hasn't given a date. Its post says the controls will come 'going forward.'

Did Meta's Muse read someone's Messages?

Inc. columnist Jason Aten says Muse synced his Messages database even though Full Disk Access was off. Meta disputes that, saying Muse can only read Messages on a Mac if the user turns on both Full Disk Access and the Messages connector in the Muse app.

What was the ChatGPT Mac app flaw?

Researchers at the Objective-See Foundation found a now-patched bug that could have let an attacker take over ChatGPT on a Mac and access its chat logs, Wired reports. OpenAI acknowledged and fixed it in its change log on September 25.

Does this affect communication apps?

Yes. Apple says Full Disk Access misuse in communication apps can also compromise the privacy of the people users are talking to, not just the users themselves.

How do I check which apps have Full Disk Access?

On a Mac, open System Settings, go to Privacy and Security, then Full Disk Access to see and switch off the apps that have it.

Did Apple comment further?

Apple did not respond to TechCrunch's request for comment about the change.

SourcesApple Developer
Topics and tagsApple, AI agents, apple, macos

The daily newsletter

Tech news you'll actually get.

One short email a day. Five minutes. Plain words. The daily email is launching soon. Join the early list.

Free. Early list: we'll email you when the first issue goes out.

More in brief