Skip to content

Apple says macOS will soon require "very explicit" permission for Full Disk Access, blaming AI agents

Apple says it will add new controls around macOS Full Disk Access after AI agents like Meta's Muse were accused of quietly reading users' messages and files.

By VibecodedThis 2 min read
A silver 15-inch MacBook Air, the kind of Mac whose Full Disk Access permission Apple says AI agents are abusing
AzureSaturn, CC0, via Wikimedia Commons

Apple is tightening one of the most powerful permissions on the Mac, and it is naming AI agents as the reason. In a post on its developer news website on Friday, the company said it will introduce "additional controls" around Full Disk Access, the macOS permission that lets an app read nearly everything on a machine, including files, mail, messages and browsing history.

The permission exists so backup apps can do their job. On iPhones and iPads, Apple notes, no single app can reach into another app's data by default, thanks to sandboxing. The Mac is more permissive, and Apple now says some developers have used Full Disk Access in ways that put users at risk without their full understanding. "Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action," Apple wrote.

The timing is not subtle. Complaints have piled up that always-on AI agents treat broad local access as a feature. Inc columnist Jason Aten wrote that Meta's Muse app had read his private messages without his permission, a claim Meta disputed. Meta spokesperson Andy Stone said Muse's access to Apple's Messages app is strictly opt-in: "You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content," he posted. "It can't read your Messages unless you do this. And it can be revoked at any time." TechCrunch also pointed to a flaw in the ChatGPT Mac app, documented by Wired, that could have let attackers reach sensitive data.

Apple is unusually blunt about where this is heading: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." The company did not say when the new controls arrive or which macOS release will carry them.

What this means for agent developers

The message to developers is that the era of quietly hoovering up a user's disk is ending. OpenAI said this week that more than 35 million people now use its agent products, ChatGPT Work and Codex, up from 10 million in July. Meta's Muse shot to the top of the app store charts after its launch. Every one of those products needs local access to do useful work, and Apple is now telling them the next version of that access will come with friction on purpose.

Developers shipping Mac agents should plan for a permission flow that looks more like iOS: ask early, ask narrowly, and assume the user is watching. Apple flagged one more consequence worth noting. "For communication apps, this can also compromise the privacy of the people users are communicating with," the company wrote, a reminder that an agent with Full Disk Access reads not just the user's data but the messages of everyone who talks to them. Reaction on Hacker News split along familiar lines, with some developers welcoming per-folder granularity and others bristling at Apple calling the permission "extraordinary." Either way, the platform owner has picked a side, and it is not the agents'.