Apple moves to tighten Mac access as AI agents reach deeper into private files
New consent controls would address sweeping permissions that can expose messages and browsing history. Apple has not announced a rollout date.
Apple is moving to tighten one of the Mac’s broadest permissions as increasingly autonomous AI agents gain the ability to work across personal computers, raising the stakes of a single decision to grant access.
In an October 2 notice to developers, the company said it would introduce additional controls around Full Disk Access. The permission was designed to help backup applications do their jobs, but Apple warned that some developers were using it in ways users might not fully understand. Files, email, messages and browsing history can all be exposed.
Apple has not specified when the changes will arrive or described the precise approval steps. Its announcement commits to more explicit user action, rather than prohibiting every application that needs extensive access. The distinction matters for legitimate utilities as well as developers building assistants that organize information across multiple apps.
The privacy model already distinguishes broad access from narrower permissions. Apple’s platform security documentation says macOS requires consent for protected locations including Documents, Downloads, Desktop and iCloud Drive. Access to all storage is treated separately, making Full Disk Access an exceptional permission rather than the routine price of installing software.
Apple’s developer documentation also describes less expansive routes for applications. Software can work with files selected by users and request access to standard locations such as Music, Movies or Photos. Those mechanisms illustrate why the scope of a permission matters: permission to complete one task need not automatically mean permission to examine everything the account can reach.
The practical concern goes beyond the person who installs an app. A message archive contains information supplied by other people, who may never have agreed to share it with an assistant. Apple explicitly identified that risk in communication applications. More capable agents can magnify it by combining information and taking actions across services.
The announcement leaves important questions for the eventual implementation. Will existing approvals require renewed consent? How will the interface explain the difference between access needed for a specific task and access that persists afterward? Apple’s notice does not answer those questions, so a stronger permission prompt should not yet be treated as a completed security fix.
Apple’s notice asks developers to prepare for tighter controls on broad disk access. The existing privacy settings already let Mac users review which applications have access to protected locations; the announced changes concern how that permission is requested and governed.