AI

Why Apple Is Tightening Mac Full Disk Access Over AI Agent Risks

Apple announced plans to introduce stricter macOS Full Disk Access controls, warning that increasingly capable desktop AI agents pose serious privacy risks.

Editorial Team
2 min read
A Mac displaying the macOS Privacy and Security system settings panel with Full Disk Access toggles

Apple plans to introduce tighter restrictions on macOS Full Disk Access, citing rising security and privacy risks posed by autonomous desktop AI software. In a notice published on its developer website on October 2, 2026, titled "Updates to Full Disk Access in macOS," the company announced that granting the permission will soon require "very explicit user action."

Apple explained that the Full Disk Access setting was originally created to allow backup applications to operate properly by bypassing standard privacy controls. When granted, the permission exposes broad system data—including files, mail, messages, and browsing history—and can compromise the privacy of people communicating with the user.

Concerns Over Desktop AI Agents

In the developer update, Apple cautioned against using the setting as a general shortcut for software functionality. "Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac," the notice stated. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding."

Apple pointed directly to artificial intelligence as the driver for tightening the setting: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

The policy change follows mounting scrutiny of desktop AI assistants that request broad operating system permissions. Tools such as Meta's Muse, OpenClaw, and Dots routinely encourage users to grant Full Disk Access to perform cross-application tasks.

The practice has already led to disputes over data handling. Inc. columnist Jason Aten reported that Meta's Muse assistant accessed and referenced his private text messages and emails despite him stating he had opted out. Aten wrote, "Not only had I not asked it to do that sort of thing, I never gave it permission to read my messages." Meta disputed the account, stating that the data could only synchronize if the user opted in.

Security researchers have highlighted related vulnerabilities. A report by Wired detailed a flaw in OpenAI's ChatGPT macOS desktop app that could have permitted attackers to access sensitive system data or execute malicious commands under certain conditions.

Pending Implementation Details

Apple has not announced a release date or specified which macOS version or software update will introduce the new controls. The company has also not detailed the exact technical modifications or interface adjustments it plans to make.

Apple stated only that going forward, it will add safeguards "to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."

Digital music workstation mixing interface showing synthesized audio waveforms and sequencing tracks
Up next

Sean Parker Is Rebuilding Stability AI Around Music With Label Backing

More in AI