
A Mac app with Full Disk Access can see far more than the file a user asked it to open. It may reach mail, messages, browser history and other material spread across the computer. Apple now says it will make that sweeping permission harder to grant, explicitly pointing to the growing power of AI agents as one reason.
In a developer notice published on October 2, Apple said future controls will require “very explicit user action” before an app receives Full Disk Access. The company did not give a rollout date or describe the exact approval flow. That distinction matters: this is a planned change, not a new safeguard already on every Mac.
Full Disk Access has legitimate uses. Backup software, for example, needs to reach files across a system to make a complete copy. But the permission is unusually broad. Apple says some developers use it in ways that could expose everything on a person’s Mac without that person fully understanding the scope. When an app can read communications, the privacy of other people in those conversations is also at stake.
AI agents sharpen the problem because they do not simply display a folder and wait. An agent may search, summarise and act across applications on a user’s behalf. Giving it unrestricted disk access could turn a convenient assistant into a single route to an enormous amount of personal or business information. Apple is not saying every agent is unsafe. It is saying the consequences of a poorly understood permission are becoming larger.
The practical question is whether Apple can preserve useful automation while making the risk unmistakable. A clearer prompt might reduce casual approvals, but people can still approve access they do not need if an app presents it as necessary for a simple task. Developers, meanwhile, will want to know whether the new controls allow more narrowly scoped alternatives for common workflows.
This is part of a broader change in what a personal computer must defend against. As AI agents move onto users’ own machines, operating-system permissions become an everyday editorial question as much as a technical one: what should an assistant be allowed to know simply because it is trying to help?







