Apple Plans Stricter Mac Permissions for AI Agent Risks
Apple will add further safeguards around macOS Full Disk Access, warning that more autonomous AI agents raise the stakes for personal data.

What you need to know
- Apple plans additional controls for macOS Full Disk Access permissions.
- The permission can expose files, messages, emails, browser data and backup information.
- Apple has not confirmed a release date, macOS version or final design.
Apple plans extra safeguards
Apple said on 2 October that it will introduce additional controls for macOS Full Disk Access, a powerful privacy permission that can allow an app to read all files on a Mac, including data held by Mail, Messages and Safari.
The company said users will only be able to grant the permission with “very explicit user action”. Apple has not confirmed the final interface, which macOS versions will receive the change, or when it will arrive.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
What Full Disk Access can reveal
Full Disk Access already exists as a user-controlled setting under System Settings > Privacy & Security > Full Disk Access. Apple says it was created largely to help backup applications work properly, but warned that some developers use it in ways that could expose files, emails, messages and browsing history without users fully understanding the consequences.
The permission can also cover Time Machine backup data and certain administrative settings. Apple said: “Some developers are using Full Disk Access in ways that could put users at risk.”
AI security concerns add pressure
The announcement follows recent scrutiny of AI software on Macs. Inc columnist Jason Aten reported in September that Meta’s Muse agent appeared to have used information from his Messages database. Meta disputed the account, with vice-president of communications Andy Stone saying the Messages integration is “entirely opt-in” and requires both Full Disk Access and the Messages connector. The dispute has not been independently resolved in the reviewed sources.
Separately, WIRED reported on 2 October that a recently patched vulnerability in OpenAI’s ChatGPT Mac app could have allowed an attacker who already had malware on a Mac to access ChatGPT conversation data and issue commands to other sensitive applications. Apple did not say that either incident directly prompted its decision.
What happens next
For now, Mac owners can review which apps have Full Disk Access in macOS settings and remove access from software they no longer trust or use. Apple has not announced changes to Mac prices, hardware, UK availability or any requirement to purchase a new device.
Why it matters
Full Disk Access can be necessary for legitimate backup tools, but it also gives an app an unusually broad view of a Mac’s private data. For UK Mac owners trying AI assistants, Apple’s move should make the implications of approving that permission harder to miss. There is no reason to buy a new Mac: this is a planned macOS privacy-control change, with timing still unconfirmed.
Sources and evidence (7)
- developer.apple.com (other)
- support.apple.com (other)
- inc.com (other)
- techcrunch.com (other)
- wired.com (other)
- support.apple.com (other)
- techcrunch.com (other)
