Apple said on Friday it will tighten one of the most powerful permissions on the Mac — Full Disk Access — because AI agents are changing what that permission actually means. In a post aimed at developers, the company said some apps are using Full Disk Access "in ways that could put users at risk," and that future versions of macOS will require "very explicit user action" before an app can obtain what Apple calls an "extraordinary level of access."
Full Disk Access exists for a narrow set of software, like cloud backup services, that genuinely needs to see everything on a machine. It largely sidesteps the sandboxing rules that keep ordinary Mac apps contained — on iPhones and iPads, no app can reach inside another app's data by default, but the Mac has always been more flexible. With the permission granted, an app can read files, mail, messages and even browsing history. For a backup tool, that's the point. For an autonomous agent, Apple now argues, it is a different category of risk.
"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple wrote, adding that it wants users to "clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy." The company did not say exactly what the new controls will look like or when they will ship.
The backdrop is a very public fight over Meta's Muse, the shopping-and-email agent that has passed 5 million downloads and, unlike OpenAI's more work-oriented Dots, leans heavily on deep access to a user's machine. Earlier this month, Inc columnist Jason Aten wrote that Muse appeared to have synced his entire local Messages database and was using the contents as context, despite his belief that he had never granted permission. Meta spokesperson Andy Stone pushed back firmly: "You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content... It can't read your Messages unless you do this. And it can be revoked at any time."
The dispute hit an awkward moment for Meta: days before the open-source release of Muse gadget code, reporting surfaced that Muse's filesystem access had exposed details of the chatbot's internal files. Meta has not fully detailed what that exposure included. Apple's language on Friday stops short of naming any company, but the timing and the specifics — communication apps, message content, agent autonomy — track the Muse controversy closely.
The deeper tension is architectural. Desktop AI agents are most useful precisely when they can see everything: your calendar, your inbox, your downloads folder, the terms of the subscription you want them to cancel. Apple's answer is to keep the capability but raise the friction, forcing a deliberate, informed hand-off rather than a permission dialog clicked through on the way to the app. It is a notable stance for a company that has so far declined to ship a general-purpose agent of its own — and a signal that the next front in the agent wars is not features, but permissions.
Comments (0)
Log in to join the discussion
Log InNo comments yet