Apple Adds New Controls to macOS Full Disk Access Over AI Agent Risks

Apple will add new controls to macOS Full Disk Access after warning that autonomous AI agents increase the risk of broad data exposure.

The news

Apple announced it will tighten controls around the macOS Full Disk Access permission. The change addresses risks from AI agents that can access files, mail, messages, and browsing history without users fully understanding the scope.

Context

The company posted the update on its developer news site. It noted that some developers already use the permission in ways that expose broad system data. With the rise of always-on AI agents such as Meta's Muse and OpenAI's Dots, Apple warned that the same level of access becomes more dangerous as agents grow more capable and autonomous.

Full Disk Access has long allowed apps to read and write across a user's entire drive. Prior to this announcement, the permission operated with a single broad grant. Apple now states that this model no longer matches the threat model created by persistent, goal-directed AI software.

Details

In the announcement, Apple said: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding."

The company added: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

No timeline for the new controls was given. Apple also stated that it continues to provide developers with powerful APIs for building app capabilities, though the post cuts off before completing that sentence.

The two cited sources report the same core message with only minor differences in phrasing. Neither provides further technical specifications or examples of the upcoming controls.

Why it matters

Developers who rely on Full Disk Access for legitimate indexing or backup tools will face new friction when the changes ship. Users gain an extra layer of review, but the permission's value drops if agents cannot operate across the full system without repeated prompts.

The move signals that Apple views AI agents as a distinct category from traditional apps. Where earlier permissions focused on static software behavior, the new controls target agents that can act over time and chain actions across data sources. This distinction matters for anyone building or using tools that run continuously in the background.

For macOS users, the change reduces the chance that a single grant hands an agent complete visibility into personal communications and files. For the broader developer community, it raises the cost of building agent-style features that need wide access. Companies shipping always-on agents will need to redesign around narrower APIs or accept additional user prompts.

The announcement does not address whether similar limits will appear on iOS or other platforms. It also leaves open how Apple will distinguish between acceptable and risky uses of the permission once the controls exist. Those details will determine whether the update meaningfully shifts the risk balance or simply adds another dialog users learn to click through.

---

Sources:

No comments yet