Apple macOS Full Disk Access changes: What AI agents mean for your Mac
Apple's macOS Full Disk Access changes are arriving because AI agents are gaining enough autonomy to turn a convenience permission into a serious privacy risk, and the company says it needs to act before that risk grows further. A notice posted on Apple's developer site states that going forward, anyone who wants to grant Full Disk Access (FDA), the macOS permission that lets an app slip past most of the system's privacy protections, will have to take "very explicit user action," as reported by Computerworld today and Macworld two days ago.
The permission itself isn't going away. Apple says customers will still be able to enable Full Disk Access; the company is adding friction and disclosure, not removing the option (Computerworld). Right now, granting FDA takes a single approval in System Settings, and that one-step consent is exactly what Apple now considers too thin for a permission this powerful.
What's missing is a timeline. Apple hasn't said when the new controls will roll out or what form they'll take (Macworld, two days ago). Until those details surface, anyone who's ever been asked to grant FDA, which covers a lot more than AI tools, has exactly one useful move available right now: open System Settings, go to Privacy & Security, then Full Disk Access, and see what's already been approved.
What Full Disk Access permissions expose, and why AI agents raise the risk
Full Disk Access was built for backup software. Apple's own developer notice describes the permission bluntly, saying it "largely sidesteps" the privacy controls built into the rest of macOS so backup tools can function properly (Macworld, two days ago).
Any app that receives FDA gets the same broad reach, whether it's the kind of tool the permission was designed for or not. Apple's notice spells out what that access covers: files, mail, messages, and browsing history (Computerworld). That's one reason this isn't purely a story about AI. On one Macworld writer's Mac, the Adobe Creative Cloud updater, Logitech's keyboard-and-mouse management software, and Microsoft OneDrive had all requested the same permission (Macworld, two days ago).
What's changed is which apps are asking and what they can do with the answer. Macworld described hearing "horror stories" about AI agents surfacing information they weren't supposed to have, or deleting and modifying files, and traced the pattern back to this one over-permissive setting. That's the outlet's own framing of anecdotal reports, not a documented incident count, but it tracks with the concern driving Apple's notice (Macworld, two days ago).
Apple ties the urgency directly to how capable and independent these agents are becoming. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," the company wrote, adding it's "committed to ensuring users clearly understand these risks before granting such access" (Computerworld). Apple singled out communication apps specifically, warning that granting FDA to a messaging or email client can expose the privacy of everyone that user talks to, not just the account holder (Computerworld).
The timing lines up with a dispute that's been circulating. Meta's Muse AI agent was accused of reading a journalist's private messages without permission, a claim Meta denies, and Apple hasn't confirmed that any single incident triggered this policy change (Computerworld). Whether or not that specific dispute is the cause, Apple's wording makes clear the concern isn't tied to one vendor. Any AI tool asking for FDA, regardless of brand, falls under the same reasoning.
Apple macOS Full Disk Access changes: what remains unknown
Two things are locked in. Apple will keep FDA available to grant, and doing so will require "very explicit user action" instead of the current single prompt (Computerworld).
Everything about the mechanism is still open. Apple hasn't described what the new flow will actually look like beyond acknowledging the current single-prompt approach needs to change (Macworld, two days ago). Macworld floated the idea that Apple might start with sterner in-app wording spelling out how much of the drive, down to the caches and buffers holding data from online services, an approved app can see. That's the outlet's own guess, not a confirmed detail, and it's worth treating it that way until Apple says otherwise (Macworld, two days ago).
Developers are already arguing about the fallout. Those distributing software outside the Mac App Store worry the added friction will create more barriers for legitimate tools, a concern Computerworld reported alongside the announcement. Security researchers sound less sympathetic to that complaint. Objective-See co-founder Patrick Wardle wrote on X that the real issue is "poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that," a dynamic Apple's notice appears to be responding to directly (Computerworld).
Where Apple's AI agent tools fit into this
Apple's push on Full Disk Access is separate from another track the company has been running: building out the software developers use to create AI agents in the first place. At WWDC26, Apple detailed updates to its Foundation Models framework, including a new DynamicProfile API that lets developers switch between models mid-session and configure agent-like behavior with specific goals and capabilities (Apple Developer, earlier this year).
That same update open-sourced the framework, added a companion Python SDK, and introduced a new Evaluations framework for measuring how AI features perform before shipping them (Apple Developer, earlier this year).
None of that is explicitly tied to the stricter Full Disk Access requirements Apple described this week. Those are app-building APIs for developers, not privacy controls for end users, and Apple hasn't said whether agents built with them will face different FDA requirements than any other app requesting the permission. Developers shouldn't assume the agent-building tools they're using now already include whatever disclosure flow Apple eventually ships.
What Mac users should do now
Apple hasn't published a review checklist for existing FDA grants, and no new control is available to enable today. The one concrete action available is checking what's already approved: open System Settings, go to Privacy & Security, then Full Disk Access, and look through the list of apps currently holding that permission.
For each one, weigh its stated purpose against what it's actually requesting. Apple's own description of FDA covers files, mail, messages, and browsing history, not just a single folder or document, so an AI assistant asking for that level of access to complete a narrow task deserves more scrutiny than the task itself would suggest. A backup tool or endpoint-security app asking for the same permission is a different calculation entirely, since scanning the full drive is the point of those tools.
Until Apple details the timeline, the macOS version, and the actual wording of the new approval flow, every app already listed under Full Disk Access remains governed by the current rules, not the ones described so far only in a developer notice. The practical move is watching Apple's developer site for implementation details and giving any AI tool that currently requests Full Disk Access the same scrutiny Apple itself is now building into the system, regardless of which company built it.
Comments
Be the first, drop a comment!