Apple is set to introduce new limitations for “full disk access” on Mac systems in response to security risks posed by the evolution of AI agents. In a recent update, the company stated it is rolling out new controls to “ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.”
The Growing Risk of Autonomous Agents
The policy shift addresses concerns regarding how developers utilize sweeping permissions. Apple noted that some applications are using Full Disk Access in ways that could expose a user's entire system—including files, emails, messages, and browsing history—often without the user’s full understanding. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” the company warned.
Full disk access is a specific macOS permission that allows an app to bypass standard privacy controls. According to Apple, this feature was originally intended to allow backup applications to function correctly, but its broad nature has become a liability in the age of AI.
Context: The Meta Muse Controversy
The update follows a report by Inc’s Jason Aten, who discovered that Meta’s Muse AI appeared to know the contents of his private messages despite not having explicit permission. Meta spokesperson Andy Stone contested the report, asserting that access to Messages is “entirely opt-in” and requires users to manually enable both Full Disk Access and a specific Messages connector.
Apple’s proactive stance suggests a move to close potential loopholes before AI-driven data harvesting becomes more prevalent. The company has not yet provided a specific timeline for when these new macOS controls will be implemented.