TechArtificial Intelligence5 MIN READ

Apple Tightens macOS 'Full Disk Access' as AI Agents Turn Broad Permissions Into a Bigger Security Risk

Apple says it will require more explicit user action before apps receive Full Disk Access on Macs, warning that increasingly capable AI agents make broad file access far riskier for users.

3 October 2026New
Apple Tightens macOS 'Full Disk Access' as AI Agents Turn Broad Permissions Into a Bigger Security Risk

Apple is tightening one of the most powerful permissions available to software on its Mac computers, citing the rapid rise of artificial intelligence agents that can act on users' behalf.

The company said on 2 October that it will introduce new controls around macOS's "Full Disk Access" permission, requiring more explicit action from users before an app is granted that level of access, according to TechCrunch. The change will also bring stricter requirements for developers who ask for the permission.

Apple was direct about its reasons. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems without users' full knowledge," the company said. It added: "Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

Apple did not specify which version of macOS will include the changes or when they will take effect, and it did not respond to TechCrunch's request for further details on implementation.

Apple Announces macOS AI Access Changes.png

What Full Disk Access means

Modern versions of macOS protect sensitive data behind a permission system. Apps must ask before they can read a user's contacts, photos, location or files in certain folders. Full Disk Access is the broadest of these permissions. An app that holds it can read almost everything on the computer, including email databases, messages, browser history, documents and backups.

The permission exists for good reasons. Backup software, security tools and some system utilities genuinely need broad access to do their jobs. Historically, it has been granted by users through a settings panel, often after an app prompted them to enable it.

The problem is that many users approve such requests without fully understanding what they are allowing. Once granted, Full Disk Access is rarely revisited, and the app can continue to read sensitive data indefinitely.

Why AI agents change the equation

AI agents are software systems that can take actions, not just answer questions. They can read files, browse the web, fill in forms, send messages and operate other applications on a user's behalf. To be useful, many of them want broad access to a user's data: an agent that is asked to find a document, summarise recent emails or prepare a report needs to see the relevant information.

That creates a new kind of risk. A traditional application with Full Disk Access does what its code tells it to do. An AI agent's behaviour is more open-ended. It may interpret instructions in unexpected ways, be manipulated by malicious content it encounters, a technique known as prompt injection, or send data to remote servers for processing. When such a system has access to everything on a computer, the consequences of an error or an attack can be severe.

Apple's statement reflects that shift. A permission designed for a world of predictable utilities is being requested by software whose actions are far harder to anticipate.

The incidents behind the decision

TechCrunch reported that recent episodes had highlighted the risks. Meta's Muse app allegedly read a journalist's private messages without explicit permission, and a flaw in ChatGPT's Mac app could have exposed sensitive data. Such incidents have fuelled concern among security researchers about how AI tools handle the access they are given.

“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
— Apple

The timing is notable. The technology industry is racing to build agents that can operate computers directly. Major AI companies have released tools that control browsers and desktop applications, and startups are building agents for specific professional tasks. Many of these products depend on broad system permissions to work as intended.

What it means for developers

For developers, Apple's change is likely to mean more friction. Apps that rely on Full Disk Access will have to justify their requests more clearly and guide users through more explicit consent steps. Some may need to redesign features to work with narrower permissions, such as access to specific folders chosen by the user.

That could slow the adoption of some AI agent products on the Mac. It could also push developers towards architectures that process data locally, request access only to what is needed for a specific task and give users clearer visibility into what an agent is doing. Security experts have long advocated such principles of least privilege.

Apple has a history of using its control over its platforms to impose privacy and security rules that affect other companies' business models, most notably with App Tracking Transparency on iPhones, which required apps to ask permission before tracking users across other apps and websites. That change had significant consequences for the digital advertising industry. The Full Disk Access changes are narrower, but they show Apple again setting the terms for how third-party software can use data on its devices. Users can take some steps themselves. Security experts recommend reviewing which applications already hold Full Disk Access in macOS settings, removing it from software that no longer needs it and being cautious about granting broad permissions to new AI tools, especially those that send data to remote servers.

A wider debate about agent permissions

Apple's move is part of a broader reckoning with the security implications of agentic AI. Regulators, security researchers and companies are asking how much access AI systems should have, how users can understand and control what agents do, and who is responsible when something goes wrong.

For businesses, the questions are particularly pressing. Employees are experimenting with AI tools that may access corporate files, emails and systems, sometimes without formal approval. A single agent with broad access on a laptop could expose confidential data. Corporate IT teams are increasingly setting policies on which AI tools are permitted and what access they may have.

The issue has resonance in India, where enterprises and regulators are working through the implications of the Digital Personal Data Protection Act. Companies that deploy AI agents handling personal data will need to show that access is limited and that users have given meaningful consent, principles closely aligned with Apple's reasoning.

The trade-off

There is an inherent tension in agentic AI. The more an agent can access, the more useful it can be, and the more damage it can do if it misbehaves. Apple has signalled where it wants that balance to sit on the Mac: broad access should be rare, deliberate and clearly understood.

Developers will have to adapt. Users may face a few more prompts. But if the change reduces the risk that a helpful assistant becomes an unwitting channel for data exposure, many will consider the trade worthwhile.

TagsApplemacOSFull Disk AccessAI AgentsCybersecurityPrivacyData ProtectionDevelopersOpenAIChatGPTMetaAgentic AIEnterprise SecurityArtificial Intelligence

Reader reviews

Sign in to rate and review this article.
Loading reviews…