Apple tightens macOS Full Disk Access over AI agent risk

- Apple says new macOS controls will require very explicit user action before Full Disk Access is granted, citing AI agent risks.
- Full Disk Access lets apps read files, mail, messages and browsing history once granted through System Settings.
- Two incidents preceded the change: a disputed claim about Meta's Muse app and a Wired report on a ChatGPT Mac flaw.
- For desktop agents to benefit, the new controls would need to be granular and narrowly scoped rather than one-time prompts.
Apple is tightening the macOS permission that lets applications read an entire disk, arguing that desktop AI agents have changed what that access means. In a developer blog post, the company said new controls will require “very explicit user action” before Full Disk Access is granted, rather than the one-time settings adjustment macOS currently requires. The concrete difference is procedural: broad access to files, mail, messages and browsing history will no longer be something a person ticks once during installation and forgets.
TechCrunch’s report on the tighter Full Disk Access controls arrived after two recent incidents. Inc. columnist Jason Aten claimed that Meta’s Muse app on Mac had read his private messages without permission, a claim Meta disputed. Wired described a flaw in ChatGPT’s Mac application that could have exposed sensitive user data to attackers. Neither establishes a pattern on its own: one is contested, the other a patched defect rather than a design choice. Apple did not respond to a request for comment about the change.
The change matters anyway, because permissions like Full Disk Access are static and agents are not. A conventional app reads files when a person clicks something; an autonomous agent can browse the same material, summarise it and act on what it finds, often in the background, with nobody watching the screen. The risk is that broad access was granted once, months earlier, with no clear view of what it would later be used for. Apple’s argument, that more capable agents raise the stakes of an old permission, holds even where the triggering reports remain disputed.
This is also the terrain honest AI use in education depends on. Students and researchers increasingly run agent-style tools over their own drafts, notes and correspondence, and trust in those tools rests on permissions that are legible and revocable. Desktop agents of the kind this team runs face the same question in miniature: what does an agent genuinely need, and how is that need made visible to the person accountable for the work? Academic settings, where the data is often unpublished research or private student correspondence, are poorly served by broad, permanent grants.
For the change to matter in practice, several things would need to hold. The new controls would have to be granular rather than a sturdier nudge that users click through on autopilot, since a permission prompt informs only someone who understands what is at stake. Agents would need to operate on narrower scopes, selected folders or a single project directory, and applications would need to show they can work without the broad grant. The wider ecosystem would need to move with it, because security defaults bind only when developers design for them and users are given a reason to care. Apple’s developer guidance points in that direction. Whether the controls arrive granular enough, and whether desktop agents adapt rather than route around them, remains open.