Apple is moving to rein in one of the most powerful permissions on the Mac, and it is naming AI agents as the reason. In a post on its developer news site on October 2, the company said it will introduce additional controls for Full Disk Access on macOS, warning that autonomous agents dramatically raise the stakes of giving any app the ability to read everything on a computer.
The announcement lands days after a high-profile dispute over whether Meta's Muse agent read a journalist's private messages, and it marks one of the clearest signals yet that platform owners intend to set the rules for how agents touch personal data.
What Apple Is Changing
Full Disk Access was originally designed for a narrow purpose: letting backup utilities and similar tools see the whole file system so they can do their job. Apple now says some developers are using it in ways that could put users at risk, exposing files, mail, messages and even browsing history without people fully understanding what they have agreed to.
Under the new approach, users who genuinely want to hand an app that level of reach will only be able to do so through "very explicit user action," in Apple's words. Reporting from Startup Fortune suggests apps will have to request the permission again through that explicit step, rather than relying on a toggle a user may have flipped once and forgotten.
"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple wrote in its developer notice.
Apple has not said which macOS release will carry the new controls or when they take effect, and none of the coverage so far provides a timeline.
The Meta Muse Flashpoint
The timing is hard to separate from the controversy around Muse, the always-on personal agent Meta launched on September 8. Inc. columnist Jason Aten reported that after installing Muse on his iPhone and Mac, and declining to give it access to Messages or his calendar, the agent nonetheless appeared to know the contents of his private messages. Aten also claimed Muse synced roughly 187,000 of his iMessages, a figure Meta disputes.
Meta's response came from David Singleton of Meta Superintelligence Labs, who said the Messages integration in the Muse Mac app is opt-in. According to Singleton, Muse can only read Messages content if macOS-level Full Disk Access has been granted and the Messages connector is enabled, a chain he described as requiring three separate application-level permission steps on top of macOS protections.
That explanation, in effect, puts Full Disk Access at the centre of the debate. If a single system permission is the gate between an agent and a user's entire digital life, Apple's decision to make that gate harder to open is a direct answer.
A Broader Pattern of Agent Privacy Worries
Muse is not the only trigger. TechCrunch noted that Apple's move also follows a Wired report describing a flaw in the ChatGPT Mac application that could have exposed sensitive information to attackers. MacRumors framed the change against the wider rise of always-on assistants such as Muse and OpenAI's Dots, products designed to run continuously and act across many apps on a user's behalf.
The common thread is that desktop agents need broad access to be useful, but that same access turns any bug, misconfiguration or misunderstood consent screen into a serious privacy event. Key concerns include:
- Consent drift, where a permission granted for one purpose is later used by an agent for another
- Silent bulk access, where an agent can read entire mail or message stores without a visible prompt
- Persistence, where old grants survive app updates that add new agent capabilities
Why It Matters
For the agentic AI industry, Apple's announcement is a reminder that the operating system vendor holds the keys. Agent makers have raced to ship assistants that read inboxes, chats and documents to provide context, and many rely on the broadest permissions available on a Mac. Raising the bar for Full Disk Access could force developers to adopt narrower, purpose-specific integrations and clearer consent flows.
It also strengthens the argument, voiced this week by figures such as Airbnb's Brian Chesky, that agents need platform-level infrastructure designed for them rather than bolted onto systems built for human users. Apple appears to be taking the opposite tack for now: rather than building new doors for agents, it is reinforcing the existing ones.
For enterprises deploying agents on employee Macs, the change is likely welcome. Security teams have struggled to see what desktop agents can reach, and a more explicit grant process gives administrators and users a clearer moment to decide.
What to Watch
The key questions now are how "very explicit" the new process will be, whether existing grants will be reset when the controls ship, and how agent developers such as Meta and OpenAI adjust their Mac apps. Developers who depend on system-wide access for legitimate tools, from backup software to security scanners, will also be watching for any carve-outs.
Whatever the details, the direction is clear: as AI agents become more autonomous, the platforms they run on are starting to treat broad data access as an exception that must be earned, not a default.
