Apple Tightens macOS 'Full Disk Access' Controls as AI Agents

Apple Responds to Growing AI Privacy Concerns

Apple has announced it is introducing additional controls around a macOS setting called "Full Disk Access," citing new risks posed by AI agents. The feature was originally designed to allow backups to function properly, but according to Apple, AI agents have now increased "the risks associated with this level of access."

The announcement follows a series of high-profile incidents that have raised questions about how much access desktop-based AI tools have to users' personal data. Days earlier, journalist Jason Aten reported that Meta's Muse app on Mac appeared to read his private messages β€” a claim Meta has disputed. Aten, an Inc. columnist, said Muse knew the content of his private messages even though he claimed he never granted the AI agent permission to access them.

Separately, a Wired report cited a flaw in ChatGPT's Mac app that could have allowed hackers to access sensitive user data. Together, these incidents have intensified scrutiny of desktop AI agents, which can control system functions and read files, messages, and browsing history.

What Is Full Disk Access β€” and Why Does It Matter for AI?

AI agents running on the desktop gain access to files, messages, and other personal content by adjusting macOS settings. Full Disk Access is one of the most powerful of these permissions, granting an app the ability to read files, mail, messages, and even browsing history.

In Muse's case, the AI optionally allows users to enable Full Disk Access. While the setting was traditionally intended for backup and utility software, some AI developers have been using it in ways that could expose far more user data than customers realize.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users' full knowledge and understanding."

β€” Apple, in a developer blog post

New Controls Require 'Very Explicit User Action'

In a post aimed at developers, Apple said it will introduce new controls to ensure that users who "genuinely wish to grant an app this extraordinary level of access" can do so only through "very explicit user action."

The company framed the change as a necessary response to the evolving capabilities of AI systems.

"Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

β€” Apple

Apple did not respond to TechCrunch's request for comment on the specific feature changes or a timeline for their rollout.

Why This Matters in 2026

The move reflects a broader shift in the tech industry as AI agents move from chat windows into the operating system itself. In 2026, agentic AI tools are increasingly capable of autonomously performing multi-step tasks β€” reading email, summarizing documents, managing calendars, and interacting with local files. That autonomy, while convenient, dramatically expands the attack surface for both malicious actors and overreaching app developers.

Apple's decision to tighten Full Disk Access controls signals that platform vendors are beginning to treat AI agents less like ordinary apps and more like privileged system processes that require explicit, informed consent. For developers building desktop AI, the message is clear: broad access will need to be justified, and users will be given more control over what their AI can see.

via TechCrunch AI

Related