With many users unknowingly granting AI agents Full Disk Access on their Macs, Apple is stepping in and introducing additional security measures.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users’ full knowledge and understanding,” Apple says in a post on its developer website.
One permission opens almost everything
AI agents like Muse, OpenAI’s Dots and others typically ask for Full Disk Access during the setup process. Most users end up giving this permission without fully understanding the implications.
While this enables AI agents to get things done, it also means that they can access your sensitive files, mail, messages and more. Plus, there’s also the risk of an AI agent silently accessing your browsing history and other data or going rogue.
The privacy implications extend beyond the person installing the agent. Apple warns that access to communication apps can also compromise the privacy of people they communicate with.
Apple wants you to think twice
To address this, Apple today announced it will introduce “additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.”
The company says, “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” This is a legitimate concern from Apple’s side, as AI agents are getting smarter and more capable with each passing day.
Apple has not detailed how the new controls will work or when they will arrive. The change will likely arrive in macOS Golden Gate 27.1 or 27.2.
For now, you can review these permissions under System Settings > Privacy & Security > Full Disk Access. Check which apps have access and revoke permissions you no longer need.