Apple is preparing tighter privacy controls for Mac computers as artificial intelligence agents increasingly seek broad access to users’ files, emails, messages and browsing histories.
The company said it will introduce additional safeguards around a powerful macOS permission called “Full Disk Access”, which can allow an application to reach data that would normally be protected by the operating system.
Apple warned that some developers are using the permission in ways that could expose users’ private information without them fully understanding what they have authorised.
The company specifically linked the change to the rise of increasingly autonomous AI agents.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple said in a developer notice published on October 2.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
What Is ‘Full Disk Access’ on a Mac?
Normally, macOS limits how much information an application can access.
Apps running inside Apple’s sandbox are generally restricted to their own data and files that a user explicitly allows them to open.
Full Disk Access is an exception.
It was designed partly for software such as backup applications that genuinely need to inspect files across a computer.
When users grant this permission, an application can potentially access far more sensitive information, including protected files and data associated with other apps.
Apple said the permission can expose “everything” on a system, including files, mail, messages and browsing history.
For communication applications, this can create another privacy problem: information belonging to people communicating with the Mac owner may also become accessible.
AI Agents Make Broad Permissions More Powerful
The concern becomes more significant with AI agents because these systems are designed to do more than simply answer questions.
An AI agent may read information, interact with applications and take actions on a user’s behalf.
For such tools to perform tasks across a computer, developers may seek access to emails, messages, documents, calendars or other information stored on the device.
The more access an autonomous system receives, the greater the potential damage if it behaves unexpectedly, misunderstands an instruction or exposes information it should not use.
Apple said this is why users need to clearly understand the consequences before granting such extensive permissions.
Apple Says Approval Will Require ‘Very Explicit User Action’
Mac users already have to approve Full Disk Access through macOS privacy settings.
An application cannot simply give itself the permission through ordinary code.
But Apple now believes the existing process needs additional safeguards.
The company said future controls will ensure that someone who genuinely wants to grant an application Full Disk Access can do so only through “very explicit user action”.
Apple has not yet explained what that additional step will involve.
It has also not announced which macOS update will introduce the change.
The company’s announcement therefore signals the direction of the security policy rather than providing a complete technical specification.
Apple Says Some Developers Are Already Creating Privacy Risks
Apple did not publicly identify any developer or application in its announcement.
However, it said some developers were already using Full Disk Access in ways that could put users at risk and expose data without their “full knowledge and understanding”.
The warning comes as AI companies race to build agents capable of interacting with software across a user’s computer.
The Economic Times, citing Bloomberg, noted that some AI tools increasingly request broad Mac permissions because they need access to personal information to carry out tasks on a user’s behalf.
That creates a security trade-off.
An agent may become substantially more useful when it can read messages, search files or interact with other applications.
But the same access also gives the software a much larger amount of sensitive information to process.
Meta’s Muse Has Added to Debate Over AI Agent Access
The announcement also comes amid scrutiny of Meta’s Muse AI agent.
Reuters reported that complaints had been raised over whether Muse accessed private Mac messages without users clearly understanding the extent of the permission being granted.
Meta disputed claims that its software accessed information without permission and said the relevant data was available only after users enabled the necessary access.
Apple did not name Muse or Meta in its announcement.
The company instead presented the issue as a broader macOS privacy problem affecting applications that seek unusually extensive access.
That distinction matters: Apple’s planned restrictions are not aimed at one AI product.
They are designed to change how applications generally obtain one of the Mac’s most powerful privacy permissions.
Why Macs Face a Different Problem From iPhones
Mac computers traditionally allow users and developers greater freedom than iPhones and iPads.
Apple’s mobile platforms rely heavily on sandboxing, which separates applications and restricts access to information belonging to other apps.
macOS also uses sandboxing, but desktop software sometimes needs broader filesystem access for legitimate functions such as backup, system management and professional workflows.
That flexibility becomes more complicated when an application is an AI agent capable of making decisions and taking actions automatically.
A conventional backup application may simply copy files.
An AI agent could potentially interpret those files, combine their contents with messages or browsing activity and act using that information.
Apple’s announcement suggests the company now sees that difference as important enough to justify additional user-consent controls.
Permission Does Not Mean an App Is Malicious
Granting Full Disk Access does not mean an application is malware or that it will misuse private information.
Many legitimate applications need broad access for specific purposes.
The problem is whether users understand how much data becomes available after they enable it.
Apple’s concern is particularly relevant when a single permission may give an AI system access to multiple categories of personal information at once.
The company said its aim is to ensure users can make an informed decision before granting that level of access.
AI Security Is Moving From Models to Device Permissions
Much of the AI safety debate has focused on what models might generate or how autonomous agents might behave.
Apple’s move highlights a more immediate security issue: what an AI agent is actually allowed to see on a person’s computer.
An agent cannot expose a private message it was never permitted to access.
But once broad device permissions are granted, the amount of information potentially available to the system expands dramatically.
That makes operating-system permissions an increasingly important layer of AI security.
For Apple, the challenge is allowing powerful agents to work across the Mac without turning convenience into unrestricted access to a user’s digital life.
What this means for you
Mac users should treat Full Disk Access as an unusually powerful permission, particularly when enabling it for AI applications. Before approving it, check why the app needs access to your entire computer and whether a more limited permission can accomplish the same task.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics