VMTech
Discuss a project →

Apple plans stricter macOS Full Disk Access controls for AI agents

Apple plans stricter macOS Full Disk Access controls for AI agents

Apple says it will introduce additional macOS controls around Full Disk Access, a permission that can allow an application to reach files, Mail, Messages and browsing history. The company said the change responds to growing risks as desktop AI agents become more capable and autonomous.

The announcement followed questions about Meta’s Muse app for Mac. Inc. columnist Jason Aten reported that Muse appeared to know the contents of private messages despite what he said was no permission for that access; Meta disputed the claim. In Muse, users can optionally enable Full Disk Access.

An extraordinary level of access

Apple said Full Disk Access was designed to let backups function properly. Yet applications using the permission may gain access to a broad range of personal material stored on a Mac, including files, mail, messages and browsing history.

“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems… without users’ full knowledge and understanding,” Apple said in a developer blog post. The company did not provide a timetable or technical specification for the planned controls.

The issue is particularly acute for desktop-based AI agents because users may adjust macOS settings to give those apps access to files, messages and other content so that the software can perform tasks on their behalf. Apple said users who genuinely want to make such a grant should be able to do so only through very explicit action.

Why desktop AI changes the security discussion

Apple said it is critical to address the permission model because the risks will grow substantially as AI agents become increasingly capable and autonomous. The company said its objective is to make sure people clearly understand the risks before they grant the access, allowing informed decisions about data and privacy.

The decision also arrives after Wired reported that a flaw in ChatGPT’s Mac app could have allowed hackers to obtain sensitive data. That report, along with the Muse dispute, has focused attention on the degree of trust required when an AI application can control a desktop environment and inspect material held on it.

Practical implication for organisations

Businesses using desktop AI should identify which applications have Full Disk Access, verify why each permission is needed and ensure employees understand the data an agent may reach. Explicit approval can improve user awareness, but permission reviews remain necessary when software is allowed to access sensitive information across a Mac.

#macos#aiagents#dataprivacy#cybersecurity
Open analytics
On the site 0 views
min read 3 02.10.2026
Instagram

Apple plans stricter macOS Full Disk Access controls for AI agents

Open the post on Instagram ↗