I think Apple is getting ready to make it harder for applications to gain Full Disk Access on macOS. Apple says this is because privacy and security are growing concerns. Apple believes that AI agents are becoming more powerful and can reach users’ files, messages, and other private data.
During an October 2 developer announcement, Apple said that some developers are using Full Disk Access in ways that could put users at risk. Apple says these developers expose files, email, messages, and browsing history without users understanding what is happening.
Apple said it will add controls. Apple says users will have to take steps before giving an app the extraordinary level of access that was called Full Disk Access.
AI agents raise fresh privacy concerns
Apple said the dangers that come with having system access are growing bigger as AI agents get more powerful and work on their own more often.
Unlike apps, AI agents can do several steps in a task, talk to files and use tools that are connected without needing much help from the user. Apple said this means it is very important for people to know what they are letting an app access before they give it system permissions.
The company also talked about the privacy issues for apps that handle messages. Getting access to messages and other kinds of communication can show not only the user’s information but also the private details of the people the user talks to.
Full Disk Access may expose sensitive data
Full Disk Access skips most of the privacy rules that come with macOS. It is meant for apps like tools that need to access almost everything on a Mac’s storage.
Apple mentioned that some programmers are using this permission in ways that might show a lot of information. This includes files, emails, and messages. Even browsing history.
The new changes are meant to make sure that people who really need this kind of access have to think carefully before giving it.
Apple has not said yet what the new rules will be or when they will happen.
Reports involving AI agents fuel growing concerns
Apple’s announcement comes at a time when there are growing concerns about AI applications accessing information on computers.
Reports from Neowin and other outlets suggested that Meta’s Muse could read messages on Macs. This reportedly happened when users had given Full Disk Access and turned on the Messages integration feature. Meta executive David Singleton responded by saying the feature is optional and needs permissions, including Full Disk Access, before Muse can access any messages.
These reports have led to questions about how much system access users should allow autonomous AI agents.
Apple did not name Meta’s Muse directly in its announcement. It also did not point to any app as the reason for its change. Instead, Apple described the move as part of a response to the increasing power of AI agents and the risks that come with giving them unrestricted access to a computer system.
Apple is already developing stricter controls for AI agents
Apple has been expanding support for AI across macOS. At WWDC 2026, the company showed a security method where the system can control how AI agents access files and apply rules on what they can read or change.
Apple has also introduced tools that let agentic AI workflows run directly on Macs. This focus on local processing highlights privacy and on-device handling as parts of Apple’s AI strategy.
The changes to Full Disk Access show that Apple is now thinking beyond individual AI models. Instead, the company is focusing on the system-level permissions that allow agents to interact with users’ digital environments.
