Apple tightens macOS Full Disk Access, singles out AI agents

Apple published an announcement on its developer news page on October 2, saying it will change how macOS grants Full Disk Access: going forward, users will need to take "a very explicit user action" before an app can be given this permission. The announcement did not specify what the new interaction will look like, nor when it will ship.

The announcement singled out AI agents specifically. In Apple's own words:

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

A permission built for backup software

By Apple's own account, the various developer-facing interfaces on macOS sit behind a set of controls designed to protect user privacy, and Full Disk Access "largely bypasses those controls." It was originally designed so that backup software on a Mac could function properly.

Apple wrote in the announcement that the way some developers use this permission can expose everything on a user's system without their full awareness, including files, mail, messages, and even browsing history. For messaging apps, the privacy of the people a user chats with is affected too. macOS security researcher Patrick Wardle put it more bluntly to reporters: with this permission, an app can essentially read any non-root file on the system — the Messages chat database, browser history, and cookies all included.

Apple did not name any company.

The Muse messaging dispute in the background

The timing follows closely on a dispute over Meta's personal AI agent, Muse. Inc. columnist Jason Aten wrote in late September that the Mac version of Muse sent him a proactive notification referencing a private chat he'd had with a colleague in Apple Messages — something he says he never authorized Muse to read.

David Singleton of Meta Superintelligence Labs responded that the Messages integration is a feature users turn on themselves:

"Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled."

According to Ars Technica, Wardle has since questioned Meta's account this week. With both sides telling different stories, no independent party has been able to verify exactly what Aten consented to and when. Shortly before this, Wardle had also disclosed a hidden configuration setting in the Muse Mac client that could be overwritten by a local program; Meta has since pushed a hotfix for it.

What Mac users in mainland China can do for now

Before this change actually lands, there isn't much users can do, but one thing is simple: open System Settings → Privacy & Security → Full Disk Access, and check who's on the list.

Over the past year, the number of AI clients installed on Mac has kept growing — some are desktop apps from major international players, others are local assistants and productivity tools built by Chinese vendors. For an agent to help organize your files, go through your chat history, or summarize your email, it needs a matching read scope, and some apps simply steer users toward turning on Full Disk Access to save themselves the trouble. Once that switch is flipped, the scope an app gets far exceeds what its immediate task actually requires.

Changes on the developer side are predictable too. Apps that rely on this permission will likely need to add another authorization step going forward, and that's where some user drop-off will happen. Apple framed the reason for tightening the rule around "AI agents," so it's no surprise that this category of app will face closer scrutiny in future review. Exactly how the interaction will change, whether it ships with a new macOS version, and whether existing grants will need to be re-confirmed — Apple hasn't said.

Sources: Apple Developer News, Ars Technica, CocoLoop, TechCrunch; Apple's statements and the scope of the permission follow the developer announcement, and Meta's response is quoted from David Singleton's public remarks.