Apple is preparing to tighten one of macOS’s most powerful permissions as AI agents gain the ability to act more independently across users’ computers.
TechCrunch reported that the company said it will introduce additional controls around Full Disk Access, a macOS permission that can give applications unusually broad access to information stored on a Mac. The move reflects growing concern that permissions originally designed for traditional applications may create greater risks when given to autonomous software.
Full Disk Access can expose far more than a single folder
Full Disk Access was designed partly so applications such as backup software could work across protected areas of a Mac. Apple says the permission largely sidesteps privacy controls that normally restrict what individual applications can reach.
The problem is the breadth of that access.
Apple warned that some applications using the permission could expose files, mail, messages and browsing history without users fully understanding how much information they had made available. For communication software, Apple added that broad access can also affect the privacy of other people involved in a user’s conversations.
That risk becomes more significant when software does more than simply read information.
Autonomous agents change the permission model
MacRumors noted that Apple’s announcement comes as always-on agents such as Meta’s Muse and OpenAI’s Dots expand what AI software can do on a computer.
Unlike a conventional application waiting for a user to click a button, an agent may search files, analyze conversations, interact with other applications and perform tasks across multiple steps.
AppleInsider shared that Apple explicitly connected its planned changes to that shift, warning that as AI agents become increasingly capable and autonomous, the risks associated with Full Disk Access will grow substantially.
AppleInsider also pointed to recent incidents illustrating the stakes, including concerns around Meta’s Muse and a flaw that OpenAI subsequently fixed in its Mac software that could have allowed an agent to be manipulated into executing malicious commands.
Apple wants permission to require more deliberate action
Apple has not yet detailed exactly what the redesigned controls will look like.
What it has confirmed is that granting this level of access will require very explicit user action, with the goal of ensuring people better understand what they are allowing before an application receives access. Apple has not announced when the changes will arrive.
For developers, the decision signals an important change in how operating systems may need to think about AI software.
Desktop permissions were largely designed around applications with relatively predictable functions. A photo editor edits images. A backup tool copies files. An AI agent can potentially cross those boundaries, combining access to email, files, messages, browsers and automation tools in a single workflow.
That makes least-privilege access increasingly important.
Instead of asking whether an application can be trusted with a broad permission once, operating systems may need to determine what an agent needs for a particular task—and how long it should retain that capability.
Apple’s Full Disk Access changes are therefore more than another privacy setting. They show how the rise of autonomous AI is beginning to force operating-system makers to rethink the security assumptions underneath desktop software itself.