Apple Tightens Full Disk Access Controls Amid AI Agent Privacy Concerns

An agent that can read everything and then act on it is different from an app that just sits there.
Apple's move reflects concern that autonomous AI agents pose a different kind of risk than traditional applications.
Mark

Why does Full Disk Access matter so much? It sounds like just another permission.

Mimi

It's the broadest permission you can grant on a Mac. Once an app has it, it can read your files, your messages, your email, your browsing history—essentially everything. Most apps don't need that level of access.

Luke

But here's the thing: we don't actually know how many users have granted it, or to how many apps. The Inc. journalist's claim about Meta's Muse is one incident. We don't have a pattern yet.

Mark

So Apple is being preventive rather than reactive?

Mimi

Exactly. They're saying that as AI agents become more autonomous, the risk grows. An agent that can read everything and then act on that information is different from an app that just sits there.

Luke

Though Meta's response is worth noting—they said the journalist had to have enabled it himself. We don't have independent verification of what actually happened on that Mac.

Mark

Does Apple's change actually solve the problem, though?

Mimi

It makes it harder to grant the permission without thinking about it. Right now, you can enable Full Disk Access pretty easily. Apple wants to force a moment of real deliberation.

Luke

But we don't know what "very explicit user action" means yet. It could be a warning dialog, or it could be something more substantial. Until we see it, we can't say whether it actually changes behavior.

Mark

What about apps that legitimately need Full Disk Access?

Mimi

They'll still be able to get it. The change just means users have to actively choose to give it, rather than it being a default or an easy toggle.

Luke

And that's the real question: will users actually read whatever warning or confirmation Apple puts in front of them, or will they just click through?

  • AI agents are quietly accumulating access to files, messages, and browsing histories that most users never intended to share — and the gap between permission granted and permission understood is widening.
  • A journalist's allegation that Meta's Muse agent read his confidential messages without consent ignited a public dispute, with Meta insisting the user himself had unlocked the door.
  • Apple is stepping in with new controls designed to make Full Disk Access harder to grant carelessly, demanding what it calls 'very explicit user action' before any application can reach that deep.
  • The company has issued a forward warning: as AI agents grow more autonomous, the stakes attached to broad system access will rise substantially — making today's friction a preview of tomorrow's necessity.
  • Critical details remain unresolved — no rollout date, no clarity on whether existing permissions will be revisited, and no public definition yet of what 'explicit' will actually look like in practice.

As artificial intelligence agents grow more capable of acting on our behalf, Apple has begun drawing a clearer line between what a machine may access and what a person must consciously choose to surrender. The company announced it will require more deliberate user action before any application can obtain Full Disk Access on macOS — a permission that effectively opens the whole of one's digital life to outside eyes. The move arrives in the wake of allegations that Meta's Muse agent read a journalist's private messages without his awareness, a dispute that illuminated how easily consent can be granted without being truly understood. In an age when autonomy is being delegated to software, Apple is asking whether the humans doing the delegating fully grasp what they are giving away.

Apple has announced plans to tighten the conditions under which AI agents can obtain Full Disk Access on macOS — a permission that, once granted, allows an application to read nearly everything stored on a system, from personal files and messages to browsing history. The company says it will require users to take deliberate, explicit action before any application receives this level of access, signaling that the current ease with which the permission can be enabled has grown inadequate.

The announcement arrives against a charged backdrop. Last month, a journalist alleged that Meta's Muse AI agent had accessed his confidential data and messages without his knowledge. Meta disputed the claim, with its vice president of communications arguing that the journalist would have had to manually enable both Full Disk Access and the Messages connector himself. The exchange exposed a fault line that Apple's new policy is designed to address: the distance between a permission technically granted and one genuinely understood.

Apple did not name Meta or Muse in its statement, but the context was difficult to ignore. The company framed its concern in terms of trajectory rather than incident, warning that as AI agents become more capable and autonomous, the risks tied to broad system access will grow substantially. An agent that can read your communications, your files, and your search history carries significant potential for harm if it malfunctions or if its creators misuse what they've been given.

What remains unclear is almost everything about implementation. Apple has offered no timeline, no description of what the new confirmation process will look like, and no guidance on whether existing Full Disk Access grants will be subject to review. In the meantime, Mac users can audit their own exposure through System Settings under Privacy & Security, where a list of applications holding Full Disk Access can be reviewed and revoked. Apple's coming change suggests the company sees that list — and how easily it grows — as a problem the current era of autonomous agents has made urgent.

Apple is moving to make it harder for AI agents to gain sweeping access to the files, messages, and browsing history stored on your Mac. The company announced it will introduce new controls that force users to take what it calls "very explicit user action" before granting Full Disk Access—a permission that, once enabled, lets applications read nearly everything on a system.

The shift reflects a growing anxiety about how AI agents are being deployed. These tools are becoming more autonomous and more widely used, but many people remain uneasy about handing them the keys to their digital lives. Developers have been requesting Full Disk Access for their applications, sometimes in ways that expose users to risk without their clear understanding of what they're permitting. A file, a message, a search history—all of it becomes available to an agent that has been granted this level of permission.

The timing of Apple's announcement is not accidental. Last month, a journalist writing for Inc. alleged that Meta's Muse agent had accessed his confidential data and messages without his knowledge or consent. Meta pushed back on the claim. Andy Stone, Meta's vice president of communications, stated that the journalist would have needed to explicitly enable both Full Disk Access and the Messages connector for Muse in order for the agent to read his messages. The implication was clear: the user bore responsibility for the permission he had granted. Apple did not name Meta, Muse, or any specific application in its statement, but the context was unmistakable.

In its announcement, Apple framed the issue in terms of future risk. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," the company said. The warning carries weight. An agent that can read your files, your email, your messages, and your browsing activity is an agent that knows a great deal about who you are and what you do. If that agent malfunctions, or if its creators misuse the access they've been given, the consequences could be severe.

What Apple has not yet disclosed is how the new controls will actually work or when they will arrive. The company offered no timeline for the rollout. It's unclear whether the change will require users to re-authorize Full Disk Access for existing applications, or whether it will only apply to new installations going forward. It's also unclear what "very explicit user action" will look like in practice—whether it will mean a warning dialog, a multi-step confirmation process, or something else entirely.

For now, Mac users who want to check their own Full Disk Access settings can navigate to System Settings, then Privacy & Security, then Full Disk Access. There they will find a list of applications that have been granted this permission. Toggling off any application they no longer trust is straightforward. But Apple's coming change suggests the company believes the current system—where Full Disk Access can be enabled with relative ease—has become inadequate for an era in which autonomous agents are making decisions about what data they need and how they will use it.

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.
— Apple
The journalist must have enabled Full Disk Access and the Messages connector for Muse to read his messages.
— Andy Stone, Meta VP of communications
Möchten Sie die ganze Geschichte? Das Original lesen bei PCMag ↗
Kontakt FAQ