Apple is planning additional controls for Full Disk Access on Mac as AI agents become more capable of accessing sensitive user information. The permission allows apps to bypass certain macOS privacy protections, potentially giving them access to files, emails, messages and browsing history.
The move comes as AI applications increasingly operate across a user’s computer rather than simply responding to prompts. Apple says some developers are using Full Disk Access in ways that could expose information without users fully understanding how much data an app can access.
Full Disk Access was primarily designed to support applications such as backup tools that need broad access to data stored on a Mac. However, the permission can also give apps access to information well beyond what a user may have intended to share, including content from other applications.
The concern also extends to people who communicate with Mac users. Apple noted that communication apps with this level of access could potentially expose private information belonging to other people whose messages or data are stored on the device.
Apple says it will introduce additional controls that require more explicit user action before an app can receive Full Disk Access. The aim is to make the scope and risks of the permission clearer before users approve it.
The change comes as AI agents gain the ability to perform tasks on a user’s behalf across different applications. Unlike conventional apps that may perform a specific function, these agents can potentially work with files, messages and other information to complete tasks, making broad system access more consequential.
Recent incidents involving AI agents have highlighted those risks. The text also points to a bug in OpenAI’s Mac app that was fixed after it was found that the agent could potentially become corrupted and execute malicious commands on behalf of an attacker.
Apple’s developer statement links the issue directly to the growing capabilities of AI agents, warning that the risks associated with broad system-level access will increase as these systems become more autonomous. The company therefore wants users to have a clearer understanding of what they are granting before giving an app this level of access.






