· via TechCrunch
Apple tightens macOS Full Disk Access over privacy risks from AI agents
Apple will require far more explicit user action before macOS apps get Full Disk Access, citing growing privacy and security risks from desktop AI agents that read files, messages and browsing history.

Apple is tightening how apps obtain Full Disk Access on macOS, arguing that desktop AI agents have sharply raised the stakes of handing a single application the keys to everything stored on a user's computer. According to TechCrunch, the company set out the change in a blog post addressed to developers, arriving shortly after a public dispute over an AI app that a journalist said had read his private messages.
What Full Disk Access does
Full Disk Access is a macOS permission that Apple says was originally designed so backup tools could work correctly. Once granted, it lets an app reach protected data across the system, including files, mail, messages and browsing history. Desktop AI agents have changed what that means in practice: these tools are built to act on a user's behalf, reading local content and controlling parts of the machine, so a permission that was reasonable for a backup utility becomes a pipeline for an autonomous assistant.
According to TechCrunch, Apple's complaint centres on consent. The company said some developers use Full Disk Access in ways that could expose everything on a user's system without the user genuinely understanding what they agreed to, and it committed to making sure people grasp the risks before granting such sweeping access.
The incidents behind the announcement
The timing is hard to miss. TechCrunch reports that Apple's statement came days after Inc. columnist Jason Aten wrote that Meta's Muse app on the Mac appeared to know the contents of his private messages, even though he said he had never given the AI agent permission. Meta disputed the claim. Muse optionally asks users to enable Full Disk Access, which would cover exactly the kind of data Aten described.
Separately, TechCrunch points to a Wired report describing a flaw in the Mac version of ChatGPT that could have let hackers reach sensitive data. Together the episodes put fresh pressure on how desktop AI handles permissions.
What Apple is changing
Apple says that going forward, users who genuinely want to give an app this level of access will only be able to do so through a deliberately explicit action. The company framed the problem as urgent, arguing that as AI agents grow more capable and autonomous, the dangers of broad disk access will grow with them, and that users must be able to make informed decisions about their own data and privacy.
Many specifics are still unknown. Apple did not respond to TechCrunch's inquiry about the change, and the post leaves open how the new consent flow will work in practice and when it will ship.
Why it matters
This is one of the clearest signals yet that platform vendors are treating AI agents as a distinct security category rather than just another kind of app. A permission designed for backup software now sits underneath tools that can act autonomously, and Apple is effectively saying the old consent model is no longer adequate. Developers of backup, sync and assistant apps should expect friction: prompts will get stricter, and granting deep access will demand more deliberate user intent. For users, the change aims to make it much harder to hand over an entire disk by accident. The Muse controversy shows why that matters — trust in desktop AI depends on permissions being transparent, and Apple appears willing to impose that transparency at the platform level.
- #apple
- #macos
- #ai-agents
- #privacy
- #security