Skip to content

Product3 publishers3 min readPublished

Apple will make Full Disk Access harder to grant as AI agents ask Mac users for it

Apple says it will add macOS controls so users can give an app Full Disk Access only through "very explicit user action." Teams building Mac AI agents that ask for that access during setup will feel the change first.

The Product Desk · Product desk

What happened

  • Apple's developer post says some developers use the setting in ways that expose files, mail, messages and browsing history without users' full knowledge.
  • Apple tied the change to AI agents, writing that the risks of that level of access will grow substantially as agents become more capable and autonomous.
  • Days earlier, Inc. columnist Jason Aten reported that Meta's Muse knew the content of his private messages though he said he had not given it permission, a claim Meta disputed.
  • Apple has not shared any details about the new controls or the other changes it plans to make to macOS.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • cost Each deliberate extra step in an agent's setup is a place where users stop, and a user who stops there never reaches the agent's first useful task.
  • constraint A team whose agent depends on broad access cannot yet plan for whether users who already granted it will be asked again once the controls arrive.
  • exposure People who message a user of a broad-access agent are exposed too, by Apple's account of communication apps, and they never saw or answered the permission prompt.

A Muse user who wants Meta's agent to see more of their Mac is offered an optional extra, TechCrunch reported: switch on Full Disk Access [10]. Desktop agents get that kind of reach through macOS settings the user changes, opening up files, messages and other personal content [13]. Apple says it built this particular switch for one kind of software. "Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac," the company wrote in its developer post [1].

The controls in that sentence are the ones that come with Apple's developer APIs, which the company describes as "designed to protect users' private data" [2]. As 9to5Mac describes them, Muse and OpenAI's Dots are always-on agents that request substantial access to personal data [12]. In permission terms, what they ask for is the exemption Apple made for backup tools. An agent holding it reads the Mac without going through the checks other apps pass [1][2].

Teams tend to count a flipped switch as consent from someone who read the prompt and understood it. Apple is describing a different user. The company wrote that it wants people to "clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy" [8]. Apple would not be redesigning the step if a flipped switch reliably meant an informed user.

Bugs add a second risk. TechCrunch cited a Wired report that a flaw in ChatGPT's Mac app could have allowed hackers to access sensitive data [11]. An attacker who exploits a flaw in an app can reach whatever that app can read. With Full Disk Access, the app can read what a backup tool reads [1].

In my view, teams shipping agents on the Mac should move every task they can onto the scoped permissions that come with Apple's APIs [2]. Full Disk Access should stay only where the product breaks without it. The cost is more prompts and an agent that does less on its first day, and some users will quit setup at each prompt. Staying on Full Disk Access swaps those prompts for one harder step whose design Apple controls. Judge either path by setup completion and by how many users are still handing the agent real tasks a month later. A count of daily opens of an always-on app says little about whether anyone wanted it reading their mail.

A 2x2 sorts most cases. One axis asks whether the agent's core task fails without Full Disk Access. The other asks whether a user would still grant it after reading Apple's description of what it exposes. If the task fails and the user would grant it, keep the request and budget for a longer onboarding step. If the task fails and the user would refuse, the product depends on access its own users do not want to give, and no prompt design fixes that. Where the task survives without it and users would grant it anyway, drop the request, because the harder step becomes a cost with nothing behind it. Where the task survives and users would refuse, the request should be gone before Apple's change ships.

What to watch

  • What Apple's new consent step looks like on screen, and which macOS release ships it.
  • How the controls apply on company-managed Macs, since that decides whether IT teams or individual users absorb the extra step.
  • Whether Meta or OpenAI drop the Full Disk Access request from Muse and Dots before Apple's change lands.
Loading claim ledger
Loading source directory links
Loading share composer