Build1 publisher2 min readPublished
Apple tightens macOS Full Disk Access over the risk AI agents bring to a backup-era permission
Apple announced on October 2 that macOS Full Disk Access can be granted only through very explicit user action, citing the added risk from AI agents. Agent builders can scope to user-selected folders now.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Apple says Full Disk Access was originally built so that backup software works properly.
- Inc. columnist Jason Aten reported that Meta's Muse app knew the contents of his private messages, a claim Meta disputed on September 30.
- Wired reported a flaw in ChatGPT's Mac app that could have let hackers reach sensitive data.
- A dev.to guide to the change urges agent developers to scope access, log it and confirm before sharing, and says those steps are best practice, not Apple requirements.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Agent teams now have to justify a whole-disk request product by product, because an agent that touches a handful of folders can usually do its job from user-selected folders.
- cost Products built around whole-disk access take on a harder consent step at onboarding and will lose some users there.
- exposure The scope of the grant sets how far a prompt injection can go: an agent with Full Disk Access that obeys a hidden instruction can reach messages, mail and browsing history.
Apple's concern, as a dev.to post on the announcement relays it, is that AI agents have raised the risks of that access [4]. The post's author puts the risk in what agents read. Files, emails and web pages can all carry hidden instructions [6]. OWASP ranks prompt injection first on its 2025 list of LLM application risks [7]. If an agent holding Full Disk Access follows one of those instructions, it could reach messages, mail and browsing history [8].
Users who genuinely want to grant the permission still can, but only through very explicit action [5]. Apple also published a developer blog post explaining its concern [2]. The dev.to account does not say which macOS release carries the change, when it takes effect, or what the explicit action looks like on screen.
That leaves the adoption question open. The author expects stricter permission prompts and writes that if onboarding adds friction, some users will drop off [9]. That is a forecast.
The case for scoping holds whatever the prompt turns out to look like. In many cases an agent needs only a handful of folders, and scoped permissions or user-selected folders cover the real job, the author argues [10]. The same post applies least privilege to timing. A user who grants access for one task understands the trade; a user who clicks through onboarding rarely does [11]. OWASP's guidance on the "Excessive Agency" risk recommends least privilege and human review of sensitive actions [12].
In my view that is the right order for an agent that works inside a project directory or a mail folder. Build it to run with less access first. Then let users opt in to more, deliberately and knowingly [13]. A backup tool has no smaller scope to retreat to, and Apple has left the full grant available for that case [3][5].
The rest of the author's list is aimed at disputes like the one over Muse [17][18]. The post recommends telling users what the agent reads, and why, in plain language at the moment the permission is requested [14]. It recommends a log or activity view showing which files, mail or messages the agent touched. The post says that record also gives the team evidence if someone challenges the product's behavior [15]. It advises keeping sensitive data local where possible, sending off-device only what the task requires, and asking for confirmation before the agent shares anything sensitive [16].
What to watch
- Apple's developer post or macOS release notes naming the release that carries the change and showing the exact consent step users must take.
- Agent developers publishing onboarding drop-off figures once the stricter Full Disk Access prompt ships, the first evidence for or against the friction forecast.
- Any resolution of Meta's dispute with Jason Aten's report on what the Muse app could read.