Apple will tighten macOS Full Disk Access to require more explicit user consent, a direct acknowledgment that always-on AI agents are creating a new class of privacy risk. (Read our earlier report.) The company’s announcement, Apple Developer, is notable for what it concedes: that some developers are already using this powerful permission in ways that put users at risk.

How Full Disk Access Became an AI Vulnerability

Full Disk Access was originally designed for backup utilities that need to read system files. It sidesteps Apple’s standard per-file privacy controls, granting an app permission to read files, mail, messages, and browsing history. As long as those apps were mostly backup tools and file managers, the trade-off was manageable. But the rise of AI agents — apps like Meta Muse and OpenAI Dots that operate continuously and autonomously — changes the equation.

Apple said in its developer blog post that “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” That is not a hypothetical. The company did not name specific apps, but it said some developers are already using Full Disk Access in ways that “could put users at risk.” The implication is that the permission is being granted too casually, or that users do not fully understand what they are approving.

The Incidents That Made This Move Inevitable

Apple’s announcement did not cite recent controversies, but the timing points directly to two reported incidents.

In one, TechCrunch and others reported that a journalist claimed Meta’s Muse app on Mac read their private messages. Meta disputed the claim, stating that access to Messages requires both Full Disk Access and the Messages connector to be enabled and is entirely opt-in. Even if Meta’s defense holds, the incident revealed that the permission model allows a third-party AI agent to reach sensitive data with a few clicks, and that users may not realize they have granted that reach.

Separately, 9to5Mac and others noted a Wired report that found a flaw in ChatGPT’s Mac app that could have allowed hackers to access sensitive data; OpenAI has since fixed the bug. That flaw was in an app that already had Full Disk Access. Neither incident is officially confirmed as the trigger, but together they demonstrate that the current consent flow is insufficient for the new generation of AI software.

AppleInsider and MacRumors each reported that Apple’s move is a response to the proliferation of always-on AI agents like Muse and Dots. That framing is consistent with Apple’s own language about increasing autonomy and capability.

What Apple Hasn’t Said and Why That Matters

The announcement contains no details about the specific controls, no timeline, and no mention of which macOS version will carry the change. Apple’s blog post is a statement of intent, not a specification. That leaves open questions: Will the new controls require a system dialog beyond the current Privacy & Security pane? Will previously authorized apps need to be re-approved? How long will developers have to comply?

These unknowns leave room for interpretation. It is possible Apple is acting proactively, before any major privacy scandal forces its hand. It is also possible the company is reacting to the Muse and ChatGPT incidents, but does not want to admit that existing policies failed. Either way, the credibility of the fix will depend on whether the new rules actually prevent the kind of access that Muse was accused of having, and whether Apple enforces them uniformly, including on its own future AI products.

What Comes Next

The key number to watch is how many apps currently hold Full Disk Access and will lose it under the new rules. Apple has an opportunity to make the permission truly temporary or scope-limited, rather than a permanent broad grant. The company also needs to explain how users will be informed when an AI agent requests access, and how they can revoke it after the fact.

Apple said it will provide more details in a future update. The absence of a date suggests this is a work in progress, likely targeting the next major macOS release. For users, the immediate takeaway is that Full Disk Access is no longer a set-and-forget permission. For developers building AI agents, the message is clear: design for limited access now, because the guardrails are coming and they will be stricter than what exists today.